Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
rPO_CW00402902400415.exe

Overview

General Information

Sample name:rPO_CW00402902400415.exe
Analysis ID:1518169
MD5:0e509caf00f17b291c24a27e87e9cacc
SHA1:fa90e2eb0ce15a16ebacb5acac99fda9ef977827
SHA256:c6f3ede5e924420f0b933fee1beb94cf12fcd3eb1a4a390cbcd6041c19a6fe50
Tags:exeuser-Porcupine
Infos:

Detection

AgentTesla
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected AgentTesla
Yara detected AntiVM3
Yara detected UAC Bypass using CMSTP
.NET source code references suspicious native API functions
AI detected suspicious sample
Allocates memory in foreign processes
Contains functionality to log keystrokes (.Net Source)
Contains functionality to register a low level keyboard hook
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Installs a global keyboard hook
Machine Learning detection for sample
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a window with clipboard capturing capabilities
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
PE file does not import any functions
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Suspicious Outbound SMTP Connections
Uses SMTP (mail sending)
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • rPO_CW00402902400415.exe (PID: 6860 cmdline: "C:\Users\user\Desktop\rPO_CW00402902400415.exe" MD5: 0E509CAF00F17B291C24A27E87E9CACC)
    • AddInProcess32.exe (PID: 1344 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" MD5: 9827FF3CDF4B83F9C86354606736CA9C)
    • AddInProcess32.exe (PID: 3096 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" MD5: 9827FF3CDF4B83F9C86354606736CA9C)
    • WerFault.exe (PID: 5000 cmdline: C:\Windows\system32\WerFault.exe -u -p 6860 -s 1040 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Agent Tesla, AgentTeslaA .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
  • SWEED
https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
{"Exfil Mode": "SMTP", "Port": "587", "Host": "mail.alhoneycomb.com", "Username": "blog@alhoneycomb.com", "Password": "          WORTHwill3611!           "}
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
    SourceRuleDescriptionAuthorStrings
    00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_UACBypassusingCMSTPYara detected UAC Bypass using CMSTPJoe Security
      00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
          00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
              Click to see the 8 entries
              SourceRuleDescriptionAuthorStrings
              0.2.rPO_CW00402902400415.exe.19319f83b50.0.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                0.2.rPO_CW00402902400415.exe.19319f83b50.0.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                  0.2.rPO_CW00402902400415.exe.19319f83b50.0.unpackINDICATOR_SUSPICIOUS_EXE_VaultSchemaGUIDDetects executables referencing Windows vault credential objects. Observed in infostealersditekSHen
                  • 0x339aa:$s1: 2F1A6504-0641-44CF-8BB5-3612D865F2E5
                  • 0x33a1c:$s2: 3CCD5499-87A8-4B10-A215-608888DD3B55
                  • 0x33aa6:$s3: 154E23D0-C644-4E6F-8CE6-5069272F999F
                  • 0x33b38:$s4: 4BF4C442-9B8A-41A0-B380-DD4A704DDB28
                  • 0x33ba2:$s5: 77BC582B-F0A6-4E15-4E80-61736B6F3B29
                  • 0x33c14:$s6: E69D7838-91B5-4FC9-89D5-230D4D4CC2BC
                  • 0x33caa:$s7: 3E0E35BE-1B77-43E7-B873-AED901B6275B
                  • 0x33d3a:$s8: 3C886FF3-2669-4AA2-A8FB-3F6759A77548
                  0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                    0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                      Click to see the 10 entries

                      System Summary

                      barindex
                      Source: Network ConnectionAuthor: frack113: Data: DestinationIp: 74.119.238.7, DestinationIsIpv6: false, DestinationPort: 587, EventID: 3, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe, Initiated: true, ProcessId: 1344, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49735
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-25T13:47:01.460408+020020301711A Network Trojan was detected192.168.2.44973574.119.238.7587TCP
                      2024-09-25T13:47:09.424925+020020301711A Network Trojan was detected192.168.2.44973874.119.238.7587TCP
                      2024-09-25T13:48:43.590012+020020301711A Network Trojan was detected192.168.2.44974574.119.238.7587TCP
                      2024-09-25T13:49:07.670179+020020301711A Network Trojan was detected192.168.2.44974674.119.238.7587TCP
                      2024-09-25T13:49:23.297545+020020301711A Network Trojan was detected192.168.2.44974774.119.238.7587TCP
                      2024-09-25T13:49:31.532720+020020301711A Network Trojan was detected192.168.2.44974874.119.238.7587TCP
                      2024-09-25T13:49:47.914945+020020301711A Network Trojan was detected192.168.2.44974974.119.238.7587TCP
                      2024-09-25T13:50:00.396305+020020301711A Network Trojan was detected192.168.2.44975174.119.238.7587TCP
                      2024-09-25T13:50:00.403942+020020301711A Network Trojan was detected192.168.2.44975074.119.238.7587TCP
                      2024-09-25T13:50:08.939842+020020301711A Network Trojan was detected192.168.2.44975374.119.238.7587TCP
                      2024-09-25T13:50:25.237826+020020301711A Network Trojan was detected192.168.2.44975474.119.238.7587TCP
                      2024-09-25T13:50:37.665189+020020301711A Network Trojan was detected192.168.2.44975574.119.238.7587TCP
                      2024-09-25T13:50:39.578772+020020301711A Network Trojan was detected192.168.2.44975674.119.238.7587TCP
                      2024-09-25T13:50:46.404575+020020301711A Network Trojan was detected192.168.2.44975774.119.238.7587TCP
                      2024-09-25T13:50:55.302341+020020301711A Network Trojan was detected192.168.2.44975874.119.238.7587TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-25T13:47:06.967082+020028555421A Network Trojan was detected192.168.2.44973574.119.238.7587TCP
                      2024-09-25T13:47:09.213303+020028555421A Network Trojan was detected192.168.2.44973874.119.238.7587TCP
                      2024-09-25T13:48:43.573976+020028555421A Network Trojan was detected192.168.2.44974574.119.238.7587TCP
                      2024-09-25T13:49:07.660343+020028555421A Network Trojan was detected192.168.2.44974674.119.238.7587TCP
                      2024-09-25T13:49:23.290985+020028555421A Network Trojan was detected192.168.2.44974774.119.238.7587TCP
                      2024-09-25T13:49:31.524220+020028555421A Network Trojan was detected192.168.2.44974874.119.238.7587TCP
                      2024-09-25T13:49:47.907211+020028555421A Network Trojan was detected192.168.2.44974974.119.238.7587TCP
                      2024-09-25T13:50:00.389766+020028555421A Network Trojan was detected192.168.2.44975174.119.238.7587TCP
                      2024-09-25T13:50:00.393270+020028555421A Network Trojan was detected192.168.2.44975074.119.238.7587TCP
                      2024-09-25T13:50:08.929717+020028555421A Network Trojan was detected192.168.2.44975374.119.238.7587TCP
                      2024-09-25T13:50:25.226860+020028555421A Network Trojan was detected192.168.2.44975474.119.238.7587TCP
                      2024-09-25T13:50:37.656934+020028555421A Network Trojan was detected192.168.2.44975574.119.238.7587TCP
                      2024-09-25T13:50:39.572077+020028555421A Network Trojan was detected192.168.2.44975674.119.238.7587TCP
                      2024-09-25T13:50:46.397475+020028555421A Network Trojan was detected192.168.2.44975774.119.238.7587TCP
                      2024-09-25T13:50:55.295564+020028555421A Network Trojan was detected192.168.2.44975874.119.238.7587TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-25T13:47:06.967082+020028552451A Network Trojan was detected192.168.2.44973574.119.238.7587TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-25T13:47:01.460408+020028397231Malware Command and Control Activity Detected192.168.2.44973574.119.238.7587TCP
                      2024-09-25T13:47:09.424925+020028397231Malware Command and Control Activity Detected192.168.2.44973874.119.238.7587TCP
                      2024-09-25T13:48:43.590012+020028397231Malware Command and Control Activity Detected192.168.2.44974574.119.238.7587TCP
                      2024-09-25T13:49:07.670179+020028397231Malware Command and Control Activity Detected192.168.2.44974674.119.238.7587TCP
                      2024-09-25T13:49:23.297545+020028397231Malware Command and Control Activity Detected192.168.2.44974774.119.238.7587TCP
                      2024-09-25T13:49:31.532720+020028397231Malware Command and Control Activity Detected192.168.2.44974874.119.238.7587TCP
                      2024-09-25T13:49:47.914945+020028397231Malware Command and Control Activity Detected192.168.2.44974974.119.238.7587TCP
                      2024-09-25T13:50:00.396305+020028397231Malware Command and Control Activity Detected192.168.2.44975174.119.238.7587TCP
                      2024-09-25T13:50:00.403942+020028397231Malware Command and Control Activity Detected192.168.2.44975074.119.238.7587TCP
                      2024-09-25T13:50:08.939842+020028397231Malware Command and Control Activity Detected192.168.2.44975374.119.238.7587TCP
                      2024-09-25T13:50:25.237826+020028397231Malware Command and Control Activity Detected192.168.2.44975474.119.238.7587TCP
                      2024-09-25T13:50:37.665189+020028397231Malware Command and Control Activity Detected192.168.2.44975574.119.238.7587TCP
                      2024-09-25T13:50:39.578772+020028397231Malware Command and Control Activity Detected192.168.2.44975674.119.238.7587TCP
                      2024-09-25T13:50:46.404575+020028397231Malware Command and Control Activity Detected192.168.2.44975774.119.238.7587TCP
                      2024-09-25T13:50:55.302341+020028397231Malware Command and Control Activity Detected192.168.2.44975874.119.238.7587TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-25T13:47:01.460408+020028400321A Network Trojan was detected192.168.2.44973574.119.238.7587TCP
                      2024-09-25T13:47:09.424925+020028400321A Network Trojan was detected192.168.2.44973874.119.238.7587TCP
                      2024-09-25T13:48:43.590012+020028400321A Network Trojan was detected192.168.2.44974574.119.238.7587TCP
                      2024-09-25T13:49:07.670179+020028400321A Network Trojan was detected192.168.2.44974674.119.238.7587TCP
                      2024-09-25T13:49:23.297545+020028400321A Network Trojan was detected192.168.2.44974774.119.238.7587TCP
                      2024-09-25T13:49:31.532720+020028400321A Network Trojan was detected192.168.2.44974874.119.238.7587TCP
                      2024-09-25T13:49:47.914945+020028400321A Network Trojan was detected192.168.2.44974974.119.238.7587TCP
                      2024-09-25T13:50:00.396305+020028400321A Network Trojan was detected192.168.2.44975174.119.238.7587TCP
                      2024-09-25T13:50:00.403942+020028400321A Network Trojan was detected192.168.2.44975074.119.238.7587TCP
                      2024-09-25T13:50:08.939842+020028400321A Network Trojan was detected192.168.2.44975374.119.238.7587TCP
                      2024-09-25T13:50:25.237826+020028400321A Network Trojan was detected192.168.2.44975474.119.238.7587TCP
                      2024-09-25T13:50:37.665189+020028400321A Network Trojan was detected192.168.2.44975574.119.238.7587TCP
                      2024-09-25T13:50:39.578772+020028400321A Network Trojan was detected192.168.2.44975674.119.238.7587TCP
                      2024-09-25T13:50:46.404575+020028400321A Network Trojan was detected192.168.2.44975774.119.238.7587TCP
                      2024-09-25T13:50:55.302341+020028400321A Network Trojan was detected192.168.2.44975874.119.238.7587TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpackMalware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Port": "587", "Host": "mail.alhoneycomb.com", "Username": "blog@alhoneycomb.com", "Password": " WORTHwill3611! "}
                      Source: rPO_CW00402902400415.exeReversingLabs: Detection: 52%
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: rPO_CW00402902400415.exeJoe Sandbox ML: detected

                      Exploits

                      barindex
                      Source: Yara matchFile source: 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: rPO_CW00402902400415.exe PID: 6860, type: MEMORYSTR
                      Source: rPO_CW00402902400415.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Source: Binary string: Microsoft.VisualBasic.ni.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: mscorlib.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.ni.pdbRSDS source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: mscorlib.ni.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.Core.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: mscorlib.ni.pdbRSDS7^3l source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: mscorlib.pdbpH{ source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.ni.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.Core.ni.pdbRSDS source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.Core.ni.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: Microsoft.VisualBasic.pdb source: WER8D6B.tmp.dmp.5.dr

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 2855245 - Severity 1 - ETPRO MALWARE Agent Tesla Exfil via SMTP : 192.168.2.4:49735 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49735 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49745 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49747 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49746 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49738 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49749 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49738 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49738 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49738 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49747 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49747 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49750 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49749 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49749 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49749 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49747 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49745 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49745 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49745 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49746 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49751 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49746 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49746 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49748 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49750 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49750 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49750 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49751 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49751 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49751 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49754 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49754 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49754 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49754 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49755 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49748 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49748 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49748 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49756 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49756 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49756 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49756 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49758 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49755 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49755 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49755 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49758 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49758 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49758 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49757 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49757 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49757 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49757 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2855542 - Severity 1 - ETPRO MALWARE Agent Tesla CnC Exfil Activity : 192.168.2.4:49753 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49753 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49753 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49753 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2030171 - Severity 1 - ET MALWARE AgentTesla Exfil Via SMTP : 192.168.2.4:49735 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2839723 - Severity 1 - ETPRO MALWARE Win32/Agent Tesla SMTP Activity : 192.168.2.4:49735 -> 74.119.238.7:587
                      Source: Network trafficSuricata IDS: 2840032 - Severity 1 - ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 : 192.168.2.4:49735 -> 74.119.238.7:587
                      Source: global trafficTCP traffic: 192.168.2.4:49735 -> 74.119.238.7:587
                      Source: Joe Sandbox ViewASN Name: VPLSNETUS VPLSNETUS
                      Source: global trafficTCP traffic: 192.168.2.4:49735 -> 74.119.238.7:587
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: global trafficDNS traffic detected: DNS query: mail.alhoneycomb.com
                      Source: AddInProcess32.exe, 00000001.00000002.4139321179.0000000002856000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.00000000027CC000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.00000000026BB000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.0000000002421000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.0000000002734000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.00000000025FD000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.0000000002560000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://mail.alhoneycomb.com
                      Source: Amcache.hve.5.drString found in binary or memory: http://upx.sf.net
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://account.dyn.com/

                      Key, Mouse, Clipboard, Microphone and Screen Capturing

                      barindex
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, SKTzxzsJw.cs.Net Code: GhwkGV1Ll50
                      Source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.raw.unpack, SKTzxzsJw.cs.Net Code: GhwkGV1Ll50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_059ADBC8 SetWindowsHookExA 0000000D,00000000,?,?,?,?,?,?,?,?,?,059AEA70,00000000,000000001_2_059ADBC8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWindows user hook set: 0 keyboard low level C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWindow created: window name: CLIPBRDWNDCLASSJump to behavior

                      System Summary

                      barindex
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                      Source: 1.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                      Source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                      Source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                      Source: initial sampleStatic PE information: Filename: rPO_CW00402902400415.exe
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BAC43C50_2_00007FFD9BAC43C5
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BABF3C90_2_00007FFD9BABF3C9
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BAB93A80_2_00007FFD9BAB93A8
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BACA0690_2_00007FFD9BACA069
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BAB4D5D0_2_00007FFD9BAB4D5D
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BB800000_2_00007FFD9BB80000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_022943301_2_02294330
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_02294C001_2_02294C00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_02293FE81_2_02293FE8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_02291B411_2_02291B41
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_0229BF201_2_0229BF20
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_0229BF101_2_0229BF10
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_059A47001_2_059A4700
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_059A9CAC1_2_059A9CAC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_059AB5301_2_059AB530
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_059A26F01_2_059A26F0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_059A7CD01_2_059A7CD0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_059A79001_2_059A7900
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_05E69B891_2_05E69B89
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 1_2_05E64BA01_2_05E64BA0
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 6860 -s 1040
                      Source: rPO_CW00402902400415.exeStatic PE information: No import functions for PE file found
                      Source: rPO_CW00402902400415.exe, 00000000.00000000.1670596569.00000193081B8000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameTransponer.exe6 vs rPO_CW00402902400415.exe
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameb17b300f-3107-4f0e-bd36-73672dc506a5.exe4 vs rPO_CW00402902400415.exe
                      Source: rPO_CW00402902400415.exeBinary or memory string: OriginalFilenameTransponer.exe6 vs rPO_CW00402902400415.exe
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                      Source: 1.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                      Source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                      Source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, 4JJG6X.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, 4JJG6X.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, 8C78isHTVco.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, 8C78isHTVco.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, 8C78isHTVco.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, 8C78isHTVco.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, CqSP68Ir.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, CqSP68Ir.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: classification engineClassification label: mal100.troj.spyw.expl.evad.winEXE@6/5@1/1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMutant created: NULL
                      Source: C:\Windows\System32\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6860
                      Source: C:\Windows\System32\WerFault.exeFile created: C:\ProgramData\Microsoft\Windows\WER\Temp\38d3f890-3016-41b0-a1ab-aaa6e4cce410Jump to behavior
                      Source: rPO_CW00402902400415.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: rPO_CW00402902400415.exeStatic file information: TRID: Win64 Executable GUI Net Framework (217006/5) 49.88%
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile read: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: rPO_CW00402902400415.exeReversingLabs: Detection: 52%
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeFile read: C:\Users\user\Desktop\rPO_CW00402902400415.exeJump to behavior
                      Source: unknownProcess created: C:\Users\user\Desktop\rPO_CW00402902400415.exe "C:\Users\user\Desktop\rPO_CW00402902400415.exe"
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 6860 -s 1040
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: textshaping.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: textinputframework.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: coreuicomponents.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: coremessaging.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: ntmarta.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: vaultcli.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: dhcpcsvc6.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: dhcpcsvc.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: winnsi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: dpapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: edputil.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: windowscodecs.dllJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                      Source: Window RecorderWindow detected: More than 3 window changes detected
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Outlook\ProfilesJump to behavior
                      Source: rPO_CW00402902400415.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                      Source: rPO_CW00402902400415.exeStatic file information: File size 1849494 > 1048576
                      Source: rPO_CW00402902400415.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Source: Binary string: Microsoft.VisualBasic.ni.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: mscorlib.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.ni.pdbRSDS source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: mscorlib.ni.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.Core.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: mscorlib.ni.pdbRSDS7^3l source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: mscorlib.pdbpH{ source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.ni.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.Core.ni.pdbRSDS source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: System.Core.ni.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: Binary string: Microsoft.VisualBasic.pdb source: WER8D6B.tmp.dmp.5.dr
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BAB8167 push ebx; ret 0_2_00007FFD9BAB816A
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BAC58BF push ecx; ret 0_2_00007FFD9BAC58C2
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeCode function: 0_2_00007FFD9BB80000 push esp; retf 4810h0_2_00007FFD9BB80312
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                      Malware Analysis System Evasion

                      barindex
                      Source: Yara matchFile source: Process Memory Space: rPO_CW00402902400415.exe PID: 6860, type: MEMORYSTR
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: WINE_GET_UNIX_FILE_NAME
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory allocated: 193084F0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory allocated: 19321F00000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMemory allocated: 21B0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMemory allocated: 2420000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMemory allocated: 21B0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199891Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199765Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199643Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199422Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199289Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199172Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199062Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1198953Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWindow / User API: threadDelayed 3472Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWindow / User API: threadDelayed 6331Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -36893488147419080s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -100000s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99890s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99781s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99671s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99562s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99452s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99343s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99234s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99124s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99015s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98906s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98796s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98687s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98578s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98468s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98357s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98238s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -196218s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -97970s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -97843s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -97722s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -97582s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -97453s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99780s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99672s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99561s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99442s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99312s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99199s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -99093s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98984s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98874s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98765s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98656s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98546s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98437s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98328s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -98218s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -97999s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -97890s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -1199891s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -1199765s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -1199643s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -1199422s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -1199289s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -1199172s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -1199062s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 6888Thread sleep time: -1198953s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 100000Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99890Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99781Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99671Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99562Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99452Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99343Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99234Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99124Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99015Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98906Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98796Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98687Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98578Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98468Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98357Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98238Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98109Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 97970Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 97843Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 97722Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 97582Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 97453Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99780Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99672Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99561Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99442Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99312Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99199Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 99093Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98984Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98874Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98765Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98656Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98546Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98437Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98328Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 98218Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 97999Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 97890Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199891Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199765Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199643Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199422Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199289Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199172Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1199062Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeThread delayed: delay time: 1198953Jump to behavior
                      Source: Amcache.hve.5.drBinary or memory string: VMware
                      Source: Amcache.hve.5.drBinary or memory string: VMware Virtual USB Mouse
                      Source: Amcache.hve.5.drBinary or memory string: vmci.syshbin
                      Source: Amcache.hve.5.drBinary or memory string: VMware, Inc.
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
                      Source: Amcache.hve.5.drBinary or memory string: VMware20,1hbin@
                      Source: Amcache.hve.5.drBinary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563
                      Source: Amcache.hve.5.drBinary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
                      Source: Amcache.hve.5.drBinary or memory string: .Z$c:/windows/system32/drivers/vmci.sys
                      Source: Amcache.hve.5.drBinary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWARE
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\'C:\WINDOWS\system32\drivers\vmmouse.sys&C:\WINDOWS\system32\drivers\vmhgfs.sys
                      Source: Amcache.hve.5.drBinary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware SVGA II
                      Source: Amcache.hve.5.drBinary or memory string: c:/windows/system32/drivers/vmci.sys
                      Source: Amcache.hve.5.drBinary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
                      Source: AddInProcess32.exe, 00000001.00000002.4144764045.0000000005759000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: Amcache.hve.5.drBinary or memory string: vmci.sys
                      Source: Amcache.hve.5.drBinary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\WINDOWS\system32\drivers\vmmouse.sys
                      Source: Amcache.hve.5.drBinary or memory string: vmci.syshbin`
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmware
                      Source: Amcache.hve.5.drBinary or memory string: \driver\vmci,\driver\pci
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\WINDOWS\system32\drivers\vmhgfs.sys
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SOFTWARE\VMware, Inc.\VMware Tools
                      Source: Amcache.hve.5.drBinary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
                      Source: Amcache.hve.5.drBinary or memory string: VMware20,1
                      Source: Amcache.hve.5.drBinary or memory string: Microsoft Hyper-V Generation Counter
                      Source: Amcache.hve.5.drBinary or memory string: NECVMWar VMware SATA CD00
                      Source: Amcache.hve.5.drBinary or memory string: VMware Virtual disk SCSI Disk Device
                      Source: Amcache.hve.5.drBinary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
                      Source: Amcache.hve.5.drBinary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
                      Source: Amcache.hve.5.drBinary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver
                      Source: Amcache.hve.5.drBinary or memory string: VMware PCI VMCI Bus Device
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: noValueButYesKey)C:\WINDOWS\system32\drivers\VBoxMouse.sys
                      Source: rPO_CW00402902400415.exe, 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\WINDOWS\system32\drivers\VBoxMouse.sys
                      Source: Amcache.hve.5.drBinary or memory string: VMware VMCI Bus Device
                      Source: Amcache.hve.5.drBinary or memory string: VMware Virtual RAM
                      Source: Amcache.hve.5.drBinary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
                      Source: Amcache.hve.5.drBinary or memory string: vmci.inf_amd64_68ed49469341f563
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory allocated: page read and write | page guardJump to behavior

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: rPO_CW00402902400415.exe, --.csReference to suspicious API methods: LoadLibrary(_321A(_3196_3227_A97F_322F._318F_319D_31D7_A9BC_A9B3_D7C9))
                      Source: rPO_CW00402902400415.exe, --.csReference to suspicious API methods: GetProcAddress(intPtr, _321A(_3196_3227_A97F_322F._3190_3212_D7FC))
                      Source: rPO_CW00402902400415.exe, --.csReference to suspicious API methods: VirtualProtect(procAddress, (uint)enumerable.ToArray().Length, 64u, out var _31C8)
                      Source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, zOS.csReference to suspicious API methods: _120HqGy.OpenProcess(_2pIt.DuplicateHandle, bInheritHandle: true, (uint)iVE.ProcessID)
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 400000 protect: page execute and read and writeJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 400000 value starts with: 4D5AJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 400000Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 402000Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 440000Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 442000Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 3E5008Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeQueries volume information: C:\Users\user\Desktop\rPO_CW00402902400415.exe VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\rPO_CW00402902400415.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                      Source: Amcache.hve.5.drBinary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23080.2006-0\msmpeng.exe
                      Source: Amcache.hve.5.drBinary or memory string: msmpeng.exe
                      Source: Amcache.hve.5.drBinary or memory string: c:\program files\windows defender\msmpeng.exe
                      Source: Amcache.hve.5.drBinary or memory string: MsMpEng.exe

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: dump.pcap, type: PCAP
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.4139321179.0000000002421000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: rPO_CW00402902400415.exe PID: 6860, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: AddInProcess32.exe PID: 1344, type: MEMORYSTR
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\SessionsJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqliteJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.iniJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.iniJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\FTP Navigator\Ftplist.txtJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\ProfilesJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\IdentitiesJump to behavior
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.4139321179.0000000002421000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: rPO_CW00402902400415.exe PID: 6860, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: AddInProcess32.exe PID: 1344, type: MEMORYSTR

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: dump.pcap, type: PCAP
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f83b50.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.rPO_CW00402902400415.exe.19319f46b08.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.4139321179.0000000002421000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: rPO_CW00402902400415.exe PID: 6860, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: AddInProcess32.exe PID: 1344, type: MEMORYSTR
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid Accounts121
                      Windows Management Instrumentation
                      1
                      DLL Side-Loading
                      311
                      Process Injection
                      1
                      Disable or Modify Tools
                      2
                      OS Credential Dumping
                      231
                      Security Software Discovery
                      Remote Services1
                      Email Collection
                      1
                      Encrypted Channel
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault Accounts1
                      Native API
                      Boot or Logon Initialization Scripts1
                      DLL Side-Loading
                      151
                      Virtualization/Sandbox Evasion
                      31
                      Input Capture
                      1
                      Process Discovery
                      Remote Desktop Protocol31
                      Input Capture
                      1
                      Non-Standard Port
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)311
                      Process Injection
                      1
                      Credentials in Registry
                      151
                      Virtualization/Sandbox Evasion
                      SMB/Windows Admin Shares11
                      Archive Collected Data
                      1
                      Non-Application Layer Protocol
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                      Deobfuscate/Decode Files or Information
                      NTDS1
                      Application Window Discovery
                      Distributed Component Object Model2
                      Data from Local System
                      11
                      Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                      Obfuscated Files or Information
                      LSA Secrets1
                      File and Directory Discovery
                      SSH1
                      Clipboard Data
                      Fallback ChannelsScheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                      DLL Side-Loading
                      Cached Domain Credentials24
                      System Information Discovery
                      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      rPO_CW00402902400415.exe53%ReversingLabsWin64.Spyware.Negasteal
                      rPO_CW00402902400415.exe100%Joe Sandbox ML
                      No Antivirus matches
                      No Antivirus matches
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      http://upx.sf.net0%URL Reputationsafe
                      https://account.dyn.com/0%URL Reputationsafe
                      http://mail.alhoneycomb.com0%Avira URL Cloudsafe
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      mail.alhoneycomb.com
                      74.119.238.7
                      truetrue
                        unknown
                        NameSourceMaliciousAntivirus DetectionReputation
                        http://upx.sf.netAmcache.hve.5.drfalse
                        • URL Reputation: safe
                        unknown
                        https://account.dyn.com/rPO_CW00402902400415.exe, 00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://mail.alhoneycomb.comAddInProcess32.exe, 00000001.00000002.4139321179.0000000002856000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.00000000027CC000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.00000000026BB000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.0000000002421000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.0000000002734000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.00000000025FD000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000001.00000002.4139321179.0000000002560000.00000004.00000800.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        74.119.238.7
                        mail.alhoneycomb.comUnited States
                        35908VPLSNETUStrue
                        Joe Sandbox version:41.0.0 Charoite
                        Analysis ID:1518169
                        Start date and time:2024-09-25 13:46:06 +02:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 7m 27s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:default.jbs
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:10
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Sample name:rPO_CW00402902400415.exe
                        Detection:MAL
                        Classification:mal100.troj.spyw.expl.evad.winEXE@6/5@1/1
                        EGA Information:
                        • Successful, ratio: 100%
                        HCA Information:
                        • Successful, ratio: 95%
                        • Number of executed functions: 45
                        • Number of non-executed functions: 3
                        Cookbook Comments:
                        • Found application associated with file extension: .exe
                        • Override analysis time to 240000 for current running targets taking high CPU consumption
                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                        • Excluded IPs from analysis (whitelisted): 20.42.65.92
                        • Excluded domains from analysis (whitelisted): onedsblobprdeus17.eastus.cloudapp.azure.com, ocsp.digicert.com, login.live.com, slscr.update.microsoft.com, blobcollector.events.data.trafficmanager.net, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size exceeded maximum capacity and may have missing behavior information.
                        • Report size getting too big, too many NtOpenKeyEx calls found.
                        • Report size getting too big, too many NtQueryValueKey calls found.
                        • Report size getting too big, too many NtReadVirtualMemory calls found.
                        • Report size getting too big, too many NtSetInformationFile calls found.
                        • VT rate limit hit for: rPO_CW00402902400415.exe
                        TimeTypeDescription
                        07:47:03API Interceptor9605495x Sleep call for process: AddInProcess32.exe modified
                        07:47:10API Interceptor1x Sleep call for process: WerFault.exe modified
                        12:46:48Task SchedulerRun new task: {8A5B439B-D615-4531-9F05-A57B712A52DA} path:
                        No context
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        VPLSNETUSLisectAVT_2403002B_466.exeGet hashmaliciousFormBookBrowse
                        • 67.198.129.29
                        SecuriteInfo.com.FileRepMalware.25505.20211.exeGet hashmaliciousUnknownBrowse
                        • 66.186.50.50
                        arm.elfGet hashmaliciousMiraiBrowse
                        • 67.229.74.119
                        bolonetwork.x86.elfGet hashmaliciousMirai, OkiruBrowse
                        • 184.164.217.225
                        95DVgihS4k.elfGet hashmaliciousUnknownBrowse
                        • 67.229.75.73
                        hesaphareketi-01.exeGet hashmaliciousAgentTeslaBrowse
                        • 74.119.238.38
                        RFQ_372842754579.pdf.exeGet hashmaliciousAgentTeslaBrowse
                        • 74.119.238.38
                        BEddZjSb7A.elfGet hashmaliciousUnknownBrowse
                        • 174.139.231.30
                        wNJM6XQwaZ.elfGet hashmaliciousUnknownBrowse
                        • 98.126.6.63
                        czEunnbk7b.elfGet hashmaliciousMiraiBrowse
                        • 98.126.6.34
                        No context
                        No context
                        Process:C:\Windows\System32\WerFault.exe
                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):0.9883881010331115
                        Encrypted:false
                        SSDEEP:192:smdbi2FK50UnUlaWB9fCzuiFGZ24lO86:hM2FnUnUlam9azuiFGY4lO86
                        MD5:94F38BC6503573F1C23DE0BC4FA6AD3D
                        SHA1:D53AB5BC3FE1F1220AF58258B6780CD4718DEBD9
                        SHA-256:54A3024B1298DD79085CA7D68A8CD710F90AD37A05CA9A77F0BBC3BAA4D7C2CA
                        SHA-512:109F872F6B7D07EA2ABC412288A210DDF5D029CE444999CF628A61A0F2C40014331FCA55ACFB985A6B626556688D386F9264E37608AAA1E5C065B4642E522255
                        Malicious:false
                        Reputation:low
                        Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.7.1.7.3.8.4.1.8.4.3.6.7.1.3.4.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.7.1.7.3.8.4.2.0.3.2.7.3.5.8.3.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.c.1.c.7.6.9.2.c.-.f.1.a.b.-.4.8.e.b.-.a.0.3.e.-.d.a.e.1.a.5.2.2.c.1.a.4.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.f.c.0.8.9.4.e.5.-.6.0.5.7.-.4.4.0.4.-.a.9.e.5.-.5.f.3.7.f.9.9.d.9.7.e.8.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....N.s.A.p.p.N.a.m.e.=.r.P.O._.C.W.0.0.4.0.2.9.0.2.4.0.0.4.1.5...e.x.e.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.T.r.a.n.s.p.o.n.e.r...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.a.c.c.-.0.0.0.1.-.0.0.1.4.-.a.6.4.e.-.c.8.9.f.4.0.0.f.d.b.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.6.9.8.7.8.5.3.e.9.0.f.6.0.5.6.a.0.6.1.c.8.9.8.f.b.9.d.3.d.a.1.c.a.0.0.0.0.0.0.0.0.!.0.0.0.0.f.a.9.0.e.2.e.b.0.c.e.1.5.a.1.6.e.b.a.c.b.5.a.c.a.c.9.9.f.d.a.9.e.f.9.7.7.8.2.
                        Process:C:\Windows\System32\WerFault.exe
                        File Type:Mini DuMP crash report, 16 streams, Wed Sep 25 11:46:59 2024, 0x1205a4 type
                        Category:dropped
                        Size (bytes):387776
                        Entropy (8bit):3.2532903907701263
                        Encrypted:false
                        SSDEEP:3072:u4KIIuf8zUztj4blgagcSdoB1CCqOW03+vTo3brEIJ:uCMSFIqb03QTo88
                        MD5:CDB31EB7AA5F9CC04C1335103D1BB4A2
                        SHA1:088A1018ECFAF4945852D18A9D7C283FD0356FA4
                        SHA-256:68E45B67E61B52138A416E71286B66E566E6EE646D0350F1AC81AA74C38016F0
                        SHA-512:5299844FFC832416B66F01CA9B25B266918D1E4B5FB46E6C3BE1C0230762582343EE7FE1ECA50BE3B59D4B19D612DB8D78B4512DA890BC03D14A0AA6D9A60D5B
                        Malicious:false
                        Reputation:low
                        Preview:MDMP..a..... .......3..f....................................$...........`...........tE..,t..........l.......8...........T............(...............7...........9..............................................................................eJ.......9......Lw......................T...........1..f.............................0..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\WerFault.exe
                        File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):8638
                        Entropy (8bit):3.702482003755678
                        Encrypted:false
                        SSDEEP:192:R6l7wVeJWhYy2f6Y9b+OVigmfoO6Jlprj89br88fBZm:R6lXJoYdf6YhhVigmfvisr/fu
                        MD5:BD1B730E7E8A22ED13271BC915E17648
                        SHA1:766CB57BD0B058FD2A375A1F19DC1D19A5A85B56
                        SHA-256:3C881C7AA4F05038BBB845EEDAB00E7C696389534A517DB9425E51367ACB5BDC
                        SHA-512:B4946DCD3AD3FF26D484F51C3281928BAD5192AD035CB196EE9AD9AAF9460D447261E6A2F519EF0BC09C4FDB3F90893DD66DC148B0C292E62083D63CFB25D66D
                        Malicious:false
                        Reputation:low
                        Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.9.0.4.5.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.9.0.4.1...2.0.0.6...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.2.0.0.6.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.2.0.5.7.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.6.8.6.0.<./.P.i.
                        Process:C:\Windows\System32\WerFault.exe
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4808
                        Entropy (8bit):4.520253134841157
                        Encrypted:false
                        SSDEEP:48:cvIwWl8zsp+Jg771I9ClWpW8VYjNPYm8M4J5kXAFOIyq85VEWz7WSeWvd:uIjfp0I7dU7VxJ302Svvd
                        MD5:C6E9FBEE00352549D2651BA40A7F9B35
                        SHA1:C107B87C81C4D171526C12714D031D5AA858210E
                        SHA-256:4D9AE970F621F7066DF8719DB0BEC81C7561CD94A0152D4E00AA0AF22CF4B731
                        SHA-512:0B2634DDADD4B614A6A01150CC11C87D88402DA9FE4A54A400E545F0E8E80522563BCA5621BF58A6936EA641926616D9516D354085ABB243C81F72145633F440
                        Malicious:false
                        Reputation:low
                        Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="19045" />.. <arg nm="vercsdbld" val="2006" />.. <arg nm="verqfe" val="2006" />.. <arg nm="csdbld" val="2006" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="2057" />.. <arg nm="geoid" val="223" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="515689" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.789.19041.0-11.0.1000" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="409
                        Process:C:\Windows\System32\WerFault.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):1835008
                        Entropy (8bit):4.465734888271991
                        Encrypted:false
                        SSDEEP:6144:uIXfpi67eLPU9skLmb0b4mWSPKaJG8nAgejZMMhA2gX4WABl0uNIdwBCswSbgy:jXD94mWlLZMM6YFH++gy
                        MD5:948B4EF3E1E790EC54AE7DAF7A01C99C
                        SHA1:0B92EA550D0CF2E99E70A6F89538193DB70CE565
                        SHA-256:53BD01760ACD60B08C3109C6CE037E9F6A4FFAD90886FA1840281A8BD5FEC687
                        SHA-512:41D867BFAE045934D6E94FA294405B3830B4A5CDE228C8E33A34B2B8BBAF1EC1025F2D3837B5808C0F6FA1E9BC28E4723AF1B42F572F9FD61E5B404601A3C7E3
                        Malicious:false
                        Reputation:low
                        Preview:regf6...6....\.Z.................... ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e....c...b...#.......c...b...#...........c...b...#......rmtm*.@................................................................................................................................................................................................................................................................................................................................................a..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        File type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                        Entropy (8bit):5.3336408452956645
                        TrID:
                        • Win64 Executable GUI Net Framework (217006/5) 49.88%
                        • Win64 Executable GUI (202006/5) 46.43%
                        • Win64 Executable (generic) (12005/4) 2.76%
                        • Generic Win/DOS Executable (2004/3) 0.46%
                        • DOS Executable Generic (2002/1) 0.46%
                        File name:rPO_CW00402902400415.exe
                        File size:1'849'494 bytes
                        MD5:0e509caf00f17b291c24a27e87e9cacc
                        SHA1:fa90e2eb0ce15a16ebacb5acac99fda9ef977827
                        SHA256:c6f3ede5e924420f0b933fee1beb94cf12fcd3eb1a4a390cbcd6041c19a6fe50
                        SHA512:23d2b6b222f571a339c5385a8bdc2be3eeee37fc047b8c2ccb18a53cbcfc044736ac37744e557fb23730d4c1ef494b42cc24c26f5587169fcbcdd093cbd7bb51
                        SSDEEP:12288:PDo56nVCOiH4p6rJDYq0adTWyiFOI/jAlI11Krtkv2+dH/4g1pc+4/AVP0+saK9V:b46rncr1LavsI112kvHdRpNH7eV
                        TLSH:068522A6B2575D47FE008972D2E275F440FCAD8376F2A08FEF90AE3225905BD8501DB6
                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f.........."...0..A............... ....@...... ....................................`................................
                        Icon Hash:90cececece8e8eb0
                        Entrypoint:0x400000
                        Entrypoint Section:
                        Digitally signed:false
                        Imagebase:0x400000
                        Subsystem:windows gui
                        Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                        DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                        Time Stamp:0x66F19604 [Mon Sep 23 16:23:32 2024 UTC]
                        TLS Callbacks:
                        CLR (.Net) Version:
                        OS Version Major:4
                        OS Version Minor:0
                        File Version Major:4
                        File Version Minor:0
                        Subsystem Version Major:4
                        Subsystem Version Minor:0
                        Import Hash:
                        Instruction
                        dec ebp
                        pop edx
                        nop
                        add byte ptr [ebx], al
                        add byte ptr [eax], al
                        add byte ptr [eax+eax], al
                        add byte ptr [eax], al
                        NameVirtual AddressVirtual Size Is in Section
                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x80000x5ea.rsrc
                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20000x48.text
                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                        .text0x20000x41c40x4200ba77e0d6963330031ff5b64061006513False0.6039891098484849data6.35621370856705IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                        .rsrc0x80000x5ea0x6006607d61143a669c71136267a0b616d6cFalse0.421875data4.148329262417721IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        NameRVASizeTypeLanguageCountryZLIB Complexity
                        RT_VERSION0x80a00x360data0.41087962962962965
                        RT_MANIFEST0x84000x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-09-25T13:47:01.460408+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44973574.119.238.7587TCP
                        2024-09-25T13:47:01.460408+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44973574.119.238.7587TCP
                        2024-09-25T13:47:01.460408+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44973574.119.238.7587TCP
                        2024-09-25T13:47:06.967082+02002855245ETPRO MALWARE Agent Tesla Exfil via SMTP1192.168.2.44973574.119.238.7587TCP
                        2024-09-25T13:47:06.967082+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44973574.119.238.7587TCP
                        2024-09-25T13:47:09.213303+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44973874.119.238.7587TCP
                        2024-09-25T13:47:09.424925+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44973874.119.238.7587TCP
                        2024-09-25T13:47:09.424925+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44973874.119.238.7587TCP
                        2024-09-25T13:47:09.424925+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44973874.119.238.7587TCP
                        2024-09-25T13:48:43.573976+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44974574.119.238.7587TCP
                        2024-09-25T13:48:43.590012+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44974574.119.238.7587TCP
                        2024-09-25T13:48:43.590012+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44974574.119.238.7587TCP
                        2024-09-25T13:48:43.590012+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44974574.119.238.7587TCP
                        2024-09-25T13:49:07.660343+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44974674.119.238.7587TCP
                        2024-09-25T13:49:07.670179+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44974674.119.238.7587TCP
                        2024-09-25T13:49:07.670179+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44974674.119.238.7587TCP
                        2024-09-25T13:49:07.670179+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44974674.119.238.7587TCP
                        2024-09-25T13:49:23.290985+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44974774.119.238.7587TCP
                        2024-09-25T13:49:23.297545+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44974774.119.238.7587TCP
                        2024-09-25T13:49:23.297545+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44974774.119.238.7587TCP
                        2024-09-25T13:49:23.297545+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44974774.119.238.7587TCP
                        2024-09-25T13:49:31.524220+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44974874.119.238.7587TCP
                        2024-09-25T13:49:31.532720+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44974874.119.238.7587TCP
                        2024-09-25T13:49:31.532720+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44974874.119.238.7587TCP
                        2024-09-25T13:49:31.532720+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44974874.119.238.7587TCP
                        2024-09-25T13:49:47.907211+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44974974.119.238.7587TCP
                        2024-09-25T13:49:47.914945+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44974974.119.238.7587TCP
                        2024-09-25T13:49:47.914945+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44974974.119.238.7587TCP
                        2024-09-25T13:49:47.914945+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44974974.119.238.7587TCP
                        2024-09-25T13:50:00.389766+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44975174.119.238.7587TCP
                        2024-09-25T13:50:00.393270+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44975074.119.238.7587TCP
                        2024-09-25T13:50:00.396305+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44975174.119.238.7587TCP
                        2024-09-25T13:50:00.396305+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44975174.119.238.7587TCP
                        2024-09-25T13:50:00.396305+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44975174.119.238.7587TCP
                        2024-09-25T13:50:00.403942+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44975074.119.238.7587TCP
                        2024-09-25T13:50:00.403942+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44975074.119.238.7587TCP
                        2024-09-25T13:50:00.403942+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44975074.119.238.7587TCP
                        2024-09-25T13:50:08.929717+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44975374.119.238.7587TCP
                        2024-09-25T13:50:08.939842+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44975374.119.238.7587TCP
                        2024-09-25T13:50:08.939842+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44975374.119.238.7587TCP
                        2024-09-25T13:50:08.939842+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44975374.119.238.7587TCP
                        2024-09-25T13:50:25.226860+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44975474.119.238.7587TCP
                        2024-09-25T13:50:25.237826+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44975474.119.238.7587TCP
                        2024-09-25T13:50:25.237826+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44975474.119.238.7587TCP
                        2024-09-25T13:50:25.237826+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44975474.119.238.7587TCP
                        2024-09-25T13:50:37.656934+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44975574.119.238.7587TCP
                        2024-09-25T13:50:37.665189+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44975574.119.238.7587TCP
                        2024-09-25T13:50:37.665189+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44975574.119.238.7587TCP
                        2024-09-25T13:50:37.665189+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44975574.119.238.7587TCP
                        2024-09-25T13:50:39.572077+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44975674.119.238.7587TCP
                        2024-09-25T13:50:39.578772+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44975674.119.238.7587TCP
                        2024-09-25T13:50:39.578772+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44975674.119.238.7587TCP
                        2024-09-25T13:50:39.578772+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44975674.119.238.7587TCP
                        2024-09-25T13:50:46.397475+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44975774.119.238.7587TCP
                        2024-09-25T13:50:46.404575+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44975774.119.238.7587TCP
                        2024-09-25T13:50:46.404575+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44975774.119.238.7587TCP
                        2024-09-25T13:50:46.404575+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44975774.119.238.7587TCP
                        2024-09-25T13:50:55.295564+02002855542ETPRO MALWARE Agent Tesla CnC Exfil Activity1192.168.2.44975874.119.238.7587TCP
                        2024-09-25T13:50:55.302341+02002030171ET MALWARE AgentTesla Exfil Via SMTP1192.168.2.44975874.119.238.7587TCP
                        2024-09-25T13:50:55.302341+02002839723ETPRO MALWARE Win32/Agent Tesla SMTP Activity1192.168.2.44975874.119.238.7587TCP
                        2024-09-25T13:50:55.302341+02002840032ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M21192.168.2.44975874.119.238.7587TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Sep 25, 2024 13:47:04.941143036 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:04.947170973 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:04.947247028 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:05.638761997 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:05.641513109 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:05.647032976 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:05.804575920 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:05.805526972 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:05.810698986 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.182398081 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.182692051 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.183689117 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.183737040 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.188745975 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.460321903 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.468729973 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.474056959 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.627687931 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.631253958 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.636177063 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.803392887 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.803546906 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.808424950 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.962250948 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.966983080 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.967082024 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.967082024 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.967082977 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:06.971940994 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.971976042 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.972003937 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:06.972014904 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:07.232748032 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:07.276155949 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:07.281500101 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:07.636418104 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:07.636528015 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:07.636596918 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:07.636596918 CEST49735587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:07.637392044 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:07.644391060 CEST5874973574.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:07.644407034 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:07.644489050 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:08.248948097 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.249205112 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:08.254487991 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.405469894 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.405621052 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:08.411079884 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.562674046 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.562902927 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:08.568892002 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.722192049 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.722336054 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:08.728849888 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.885415077 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:08.885658979 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:08.892091036 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.055907965 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.056024075 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.060971022 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.211589098 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.213254929 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.213254929 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.213303089 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.213303089 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.213402033 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.213444948 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.213444948 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.213465929 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.213574886 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:47:09.217986107 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.218029976 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.218040943 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.218190908 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.218235016 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.218388081 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.218436003 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.378366947 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:47:09.424925089 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:41.413129091 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:41.418138981 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:41.770004988 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:41.770095110 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:41.770109892 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:41.770143986 CEST49738587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:41.773382902 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:41.775302887 CEST5874973874.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:41.778518915 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:41.778580904 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:42.429656029 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:42.429876089 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:42.434732914 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:42.588143110 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:42.591605902 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:42.597374916 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:42.753504992 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:42.754079103 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:42.759125948 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.041888952 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.045347929 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.050334930 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.210947990 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.217628002 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.222508907 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.397593975 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.398029089 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.402879953 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.556334019 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.573771000 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.573878050 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.573976040 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.574147940 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.578815937 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.578830957 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.578855991 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.579092026 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.584904909 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.589942932 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.589961052 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.589982033 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.589993000 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.590003967 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.590012074 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.590017080 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.590080976 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.590080976 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.590161085 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.590286016 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.590385914 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.594899893 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.594981909 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.594994068 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.595038891 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.595068932 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.595101118 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.595164061 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.595221996 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.595305920 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.595334053 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.595400095 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.599903107 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600006104 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.600009918 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600024939 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600095034 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.600110054 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600128889 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600192070 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.600238085 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600249052 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600284100 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600295067 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600344896 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600357056 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600368977 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600378990 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600398064 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600544930 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600557089 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600568056 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600578070 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600588083 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600596905 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600606918 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600616932 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600626945 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600637913 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600647926 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600657940 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.600667953 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.604872942 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.604906082 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.604917049 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.604926109 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.604939938 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.604988098 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605003119 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605041027 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605051041 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605062008 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605072021 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605092049 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605103970 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605144978 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605154991 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605175018 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.605185032 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.632170916 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.632217884 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:48:43.637087107 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:43.976730108 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:48:44.018790960 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:05.575747013 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:05.580760002 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:05.938637018 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:05.938741922 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:05.938780069 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:05.938813925 CEST49745587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:05.939769983 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:05.943615913 CEST5874974574.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:05.944550991 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:05.944614887 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:06.551584959 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:06.552933931 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:06.557744980 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:06.707174063 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:06.707376957 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:06.713840008 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:06.866311073 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:06.866539001 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:06.871463060 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.027324915 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.027512074 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.032411098 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.181534052 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.181715012 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.186533928 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.501878977 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.503649950 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.509244919 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.659615040 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.659961939 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.660307884 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.660342932 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.660429955 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.663245916 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.666346073 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.666654110 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.666810036 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.666824102 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.666858912 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.670124054 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670140028 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670152903 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670167923 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670178890 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.670181990 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670221090 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.670242071 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670245886 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.670255899 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670270920 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670286894 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.670299053 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.670311928 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.670319080 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.670337915 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.672003031 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.672544003 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.678136110 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.678165913 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.678179979 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.678193092 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.678206921 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.678220987 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.678224087 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.678364992 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.679250002 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.679303885 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.684400082 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.684493065 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.685157061 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685172081 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685184002 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685197115 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685210943 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685214996 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.685224056 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685237885 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685250044 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:07.685254097 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685297966 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685311079 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685323000 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685642004 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685656071 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685668945 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.685813904 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.686281919 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.686295033 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.686306953 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.686414003 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691148996 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691164970 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691294909 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691308022 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691703081 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691715956 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691844940 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691858053 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691869020 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691881895 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691894054 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691905975 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691916943 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691983938 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:07.691996098 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:08.032486916 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:08.254695892 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:08.254781961 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:21.234174967 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:21.241043091 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:21.593621016 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:21.593802929 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:21.593820095 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:21.593904972 CEST49746587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:21.594926119 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:21.598743916 CEST5874974674.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:21.600220919 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:21.600909948 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:22.205683947 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.205909014 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:22.211136103 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.366255045 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.366671085 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:22.371615887 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.526968002 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.527296066 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:22.532105923 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.701180935 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.727858067 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:22.732644081 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.889359951 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:22.890943050 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:22.895781994 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.065275908 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.130258083 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.135190010 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.290498018 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.290745020 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.290936947 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.290985107 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.291100025 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.292448044 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.295610905 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.295819998 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.295876026 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.295905113 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.295933962 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.297370911 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297436953 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.297482014 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297514915 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297544956 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.297570944 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.297588110 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297616959 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297643900 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.297646046 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297669888 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.297697067 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.297707081 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297735929 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297764063 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.297791958 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.297818899 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.300753117 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.300816059 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.302557945 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.302649975 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.302675962 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.302705050 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.302736998 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.302752972 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.302778006 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.302803040 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.302944899 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.303004026 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.303014994 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.303034067 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.303061962 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.305772066 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.305902958 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.307574987 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.307627916 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.307679892 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.307698965 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.307732105 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.307784081 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.307790995 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.307887077 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.307954073 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:23.307964087 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.307991028 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308020115 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308072090 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308101892 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308154106 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308182955 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308209896 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308238029 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308264971 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308294058 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308345079 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308372974 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308401108 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308429003 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308455944 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308489084 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.308516026 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.310862064 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.310909986 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.310995102 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.311023951 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.312552929 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.312660933 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.312720060 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313333035 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313366890 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313448906 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313518047 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313546896 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313580990 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313632011 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313661098 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313688993 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313716888 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313744068 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313796043 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313824892 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.313853025 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.685333967 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:23.810970068 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:29.596510887 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:29.601624966 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:29.959502935 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:29.959583044 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:29.959614038 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:29.959702969 CEST49747587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:29.960841894 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:29.964437008 CEST5874974774.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:29.965696096 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:29.965761900 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:30.576704979 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:30.576945066 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:30.581801891 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:30.733571053 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:30.733803034 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:30.738758087 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:30.889780045 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:30.889980078 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:30.894763947 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.045902967 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.046174049 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.050986052 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.202318907 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.202510118 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.208841085 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.368489027 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.368673086 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.373548031 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.523530960 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.524116993 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.524116993 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.524219990 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.524272919 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.526911020 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.529982090 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.530010939 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.530025005 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.530095100 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.530158997 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.532635927 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.532720089 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.532876015 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.533065081 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.535655022 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.535738945 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.537611961 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.537714005 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.537792921 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.537895918 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.537966013 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.538009882 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.538072109 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.538084984 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.538093090 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.538120031 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.538161993 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.540632963 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.540661097 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.540710926 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.542851925 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543090105 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.543093920 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543108940 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543185949 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.543288946 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543303013 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543349981 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543416023 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:31.543422937 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543478012 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543521881 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543561935 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543627977 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543732882 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543801069 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543813944 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543951035 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.543963909 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.545566082 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547348976 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547363043 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547399998 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547414064 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547439098 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547451973 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547465086 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547843933 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.547939062 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548011065 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548058987 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548077106 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548105001 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548163891 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548193932 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548209906 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548350096 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548363924 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548418999 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548433065 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548546076 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548558950 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548583031 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548625946 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548676014 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548688889 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548719883 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.548784971 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.895278931 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:31.940773964 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:45.752015114 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:45.759465933 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:46.110486984 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:46.110502005 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:46.110572100 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:46.110635996 CEST49748587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:46.111805916 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:46.117537022 CEST5874974874.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:46.118876934 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:46.118979931 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:46.750304937 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:46.753251076 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:46.758193016 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:46.909567118 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:46.913117886 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:46.919363976 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.071275949 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.074176073 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.079103947 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.424681902 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.425062895 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.431792021 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.580908060 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.581587076 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.586452961 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.751648903 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.752006054 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.756985903 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.906538963 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.907012939 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.907161951 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.907211065 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.907326937 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.909926891 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.909972906 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.911911964 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.912034988 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.912102938 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.912168980 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.912174940 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.914710045 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.914764881 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.914885044 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.914926052 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.914931059 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.914943933 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.914944887 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.914990902 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.915008068 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.915014029 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.915210962 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.916986942 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.917079926 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.919673920 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.919735909 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.919750929 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.919807911 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.919830084 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.919848919 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.919898033 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.919913054 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.919950008 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.919965982 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.920068979 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.920079947 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.920128107 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.920193911 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.920277119 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.922116041 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.922159910 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.922389030 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.922460079 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.924655914 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.924666882 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.924731016 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.924742937 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.924782038 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.924814939 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.924840927 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.925251961 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.925313950 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:47.925364971 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.927042961 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.927048922 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.927064896 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.927179098 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.927227020 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.927232027 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.927283049 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.927289009 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929543018 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929548979 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929585934 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929610968 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929617882 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929630041 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929656982 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929675102 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929785967 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929790974 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929837942 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929845095 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929857969 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929868937 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929881096 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.929886103 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.930046082 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.930147886 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.930282116 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:47.930288076 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:48.290328026 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:48.378370047 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:58.181993008 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:58.231596947 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:58.582319975 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:58.582456112 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:58.582478046 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:58.582524061 CEST49749587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:58.583367109 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:58.587297916 CEST5874974974.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:58.588150978 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:58.588239908 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:58.595824003 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:58.600630045 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:58.600714922 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.241594076 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.242506027 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.247370005 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.252166033 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.252357960 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.257186890 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.402936935 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.405088902 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.409955978 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.410754919 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.411117077 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.415894985 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.565506935 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.565967083 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.570787907 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.573605061 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.573916912 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.578773975 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.737960100 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.738229990 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.742007971 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.742249012 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:49:59.743063927 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:49:59.747060061 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.053877115 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.053893089 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.054053068 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.054117918 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.058837891 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.058845997 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.227026939 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.227157116 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.231909037 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.232218981 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.232332945 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.237134933 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.389353991 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.389750957 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.389750957 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.389765978 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.389822960 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.391439915 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.392995119 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.393172979 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.393234968 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.393270016 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.393313885 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.394495010 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.394556999 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.394567966 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.394613981 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.394803047 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.396251917 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.396262884 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.396305084 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.396323919 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.396326065 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.396332979 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.396342039 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.396369934 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.396378040 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.396397114 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.396409035 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.398766041 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.399235010 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.399298906 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.399300098 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.399310112 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.399319887 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.399339914 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.399348974 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.399358034 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.399358034 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.399398088 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.399411917 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.401139975 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.401185989 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.401210070 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.401221037 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.401274920 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.401335955 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.401355982 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.401388884 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.401396036 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.401412010 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.401446104 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.403552055 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.403597116 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.403902054 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.403942108 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.404012918 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.404028893 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.404057980 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.404073000 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.404078960 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.404086113 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.404097080 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.404098034 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.404124975 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.404145002 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.405880928 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.405934095 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.405944109 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.405955076 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.405962944 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.405981064 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.405994892 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.406032085 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.406038046 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.406065941 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.406091928 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.406135082 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.406145096 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.406177998 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.406183958 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.406186104 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.406249046 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.408531904 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.408653975 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.408663988 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.408699036 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.408761024 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.408817053 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.408899069 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.408912897 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.409041882 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.409102917 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.410648108 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410731077 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.410742044 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410785913 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410797119 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410805941 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410823107 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410866976 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410891056 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410902023 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410912991 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410928011 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.410960913 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.410991907 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.411000967 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.411004066 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.411010027 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.411053896 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.413186073 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413197994 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413209915 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413219929 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413237095 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413338900 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413360119 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413369894 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413378954 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413388014 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413399935 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413408995 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413425922 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413466930 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413476944 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413496017 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413505077 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413513899 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413523912 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413533926 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413583994 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.413604021 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.414036036 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.414096117 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.414227962 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.414278984 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.414401054 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.414449930 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.415620089 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.415699959 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.415935040 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.415992975 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.416188955 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416198969 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416208029 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416218996 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416300058 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416310072 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416318893 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416429043 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416438103 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416564941 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416639090 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416693926 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416778088 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416786909 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.416795969 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.418637991 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.418981075 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.418991089 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419001102 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419009924 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419148922 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419157028 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419186115 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419193983 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419397116 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419459105 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419466972 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.419473886 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.420552969 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.420562029 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.420599937 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.420608997 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.420823097 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.420898914 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.420989037 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.425702095 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.778933048 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.792026997 CEST5874975074.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:00.832926989 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:00.880932093 CEST49750587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:05.027139902 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:05.031888008 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:05.386956930 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:05.387082100 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:05.387130022 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:05.387197018 CEST49751587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:05.388113976 CEST49752587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:05.393732071 CEST5874975174.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:05.394720078 CEST5874975274.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:05.394802094 CEST49752587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:05.973901033 CEST5874975274.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:05.974323034 CEST49752587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:05.979195118 CEST5874975274.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:06.132379055 CEST5874975274.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:06.132653952 CEST49752587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:06.137473106 CEST5874975274.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:06.293986082 CEST5874975274.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:06.294264078 CEST49752587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:06.299154997 CEST5874975274.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:06.409703016 CEST49752587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:06.414729118 CEST5874975274.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:06.414823055 CEST49752587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:06.463974953 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:06.468796968 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:06.469096899 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:07.018098116 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.018239975 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:07.023318052 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.174287081 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.174484015 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:07.182461023 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.333709955 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.333957911 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:07.338860035 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.496124029 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.496342897 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:07.504725933 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.651818037 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:07.653286934 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:07.658775091 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.762449026 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.762592077 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.764682055 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.764812946 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.764875889 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.764920950 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.764940023 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.764982939 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.772217035 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.929207087 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.929596901 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.929647923 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.929717064 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.929760933 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.932602882 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.939563036 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939636946 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939646006 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939692974 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.939762115 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939771891 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939779043 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939841986 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.939851999 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939860106 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939868927 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939879894 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.939894915 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.939927101 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.940309048 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.940318108 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.940325975 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.940351963 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.940373898 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.944577932 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.944632053 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.944665909 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.944710016 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.944763899 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.944772005 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.944825888 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.944827080 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.944855928 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.944885969 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.944895029 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.944919109 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.944927931 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.945255041 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.945308924 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.945334911 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.945378065 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.945779085 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.945856094 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.950248957 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.950304985 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.950310946 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.950362921 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.950623989 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.950664997 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:08.950666904 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.950675011 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.950768948 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.950794935 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.950803995 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.950814962 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951030970 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951071978 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951078892 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951162100 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951170921 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951179028 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951416016 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951426029 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951435089 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951443911 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951459885 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951467991 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.951473951 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955394983 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955404043 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955419064 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955430031 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955461979 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955471039 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955480099 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955518961 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955528021 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955638885 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955647945 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955655098 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955662966 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955672026 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955679893 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955688000 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955846071 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955854893 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:08.955863953 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:09.313504934 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:09.362756968 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:23.019412994 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:23.024591923 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:23.383440971 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:23.383744955 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:23.383835077 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:23.384032965 CEST49753587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:23.385293007 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:23.391105890 CEST5874975374.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:23.391591072 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:23.391664028 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:23.998385906 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:23.998862028 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:24.004646063 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:24.164786100 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:24.164992094 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:24.169970989 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:24.460604906 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:24.460874081 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:24.474308014 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:24.747060061 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:24.747394085 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:24.752368927 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:24.901597023 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:24.901721954 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:24.907450914 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.070724964 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.070873022 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.075985909 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.225476980 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.225938082 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.226756096 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.226860046 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.226860046 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.231966019 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.232980967 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.232991934 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.232995987 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.233005047 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.233057022 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.237771034 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.237821102 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.237826109 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.237873077 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.237883091 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.237886906 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.237895012 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.237898111 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.237936974 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.238010883 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.238014936 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.238076925 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.242738962 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.242835999 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.242854118 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.242916107 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.242965937 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.243040085 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.243191957 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.243196964 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.243206024 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.243269920 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.243504047 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.243509054 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.243516922 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.243580103 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.243643045 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.243741989 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.247678995 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.247729063 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.247796059 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.247826099 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.247879982 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.247973919 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.247978926 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.247988939 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248030901 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.248117924 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248177052 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248303890 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248308897 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248317957 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248370886 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248486042 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248490095 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248500109 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248503923 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248514891 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248569965 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248574972 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248616934 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248725891 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248730898 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248739958 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248859882 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248864889 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248878956 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.248883009 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.252739906 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.252744913 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.252891064 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.252895117 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.252898932 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.252907991 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253036976 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253041029 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253050089 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253175974 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253180981 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253184080 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253187895 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253196955 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253223896 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.253304958 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:25.270606041 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.603751898 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:25.644023895 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:35.649914980 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:35.654870033 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.006119967 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.006263018 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:36.006318092 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.006581068 CEST49754587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:36.007138014 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:36.011138916 CEST5874975474.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.011921883 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.012372017 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:36.649435043 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.649646997 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:36.654627085 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.812257051 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.812500954 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:36.817867994 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.977385044 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:36.977621078 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:36.982462883 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.160439014 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.160615921 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.165463924 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.319883108 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.320086002 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.324924946 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.493993998 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.494132996 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.500015020 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.656573057 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.656842947 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.656904936 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.656934023 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.656982899 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.658235073 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.663114071 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.663219929 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.663259983 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.663310051 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.664093971 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.665128946 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.665189028 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.665292025 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.665330887 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.665338993 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.665385962 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.668137074 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.668185949 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.670069933 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.670119047 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.670169115 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.670177937 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.670233965 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.670268059 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.670312881 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.670331001 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.670377970 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.670444012 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.670485973 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.670526028 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.670574903 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.673079014 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.673127890 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.673130989 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.673176050 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.674972057 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675018072 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.675057888 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675101042 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675107002 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.675143957 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.675225019 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675251961 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675283909 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.675302982 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675328016 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675421953 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675456047 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675523996 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675563097 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675929070 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675937891 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.675991058 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.676000118 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.676008940 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.676023960 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.679430008 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.679439068 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.679445028 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.679461002 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.679532051 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.679539919 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.679577112 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.679972887 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681168079 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681175947 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681231976 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681240082 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681288004 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681296110 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681349039 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681358099 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681432009 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681440115 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681497097 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681505919 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681560040 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681569099 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681653023 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681709051 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.681809902 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.956645966 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:37.961968899 CEST5874975574.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:37.962091923 CEST49755587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:38.029000998 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:38.033986092 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:38.034132957 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:38.620735884 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:38.621220112 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:38.626091003 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:38.778038025 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:38.778238058 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:38.783032894 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:38.932553053 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:38.932806969 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:38.937674046 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.091675997 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.091835976 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.096636057 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.248099089 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.248241901 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.253062963 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.416466951 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.416601896 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.421758890 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.571702957 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.571942091 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.572077036 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.572077036 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.572077036 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.573286057 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.578668118 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.578679085 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.578685999 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.578696966 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.578768015 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.578772068 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.578810930 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.579566956 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.579579115 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.579586983 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.579632044 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.586067915 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.586076975 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.586085081 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.586093903 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.586102009 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.586114883 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.586124897 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.586132050 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.586133003 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.586194992 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.591237068 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591283083 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.591326952 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591367006 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.591406107 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591453075 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.591494083 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591514111 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591531992 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.591552973 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.591577053 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591588020 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591624975 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591629028 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.591645002 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591655970 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591669083 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591702938 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591732025 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591741085 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591763973 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591773033 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591833115 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591841936 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591850996 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591861010 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591878891 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.591887951 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596190929 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596199989 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596220970 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596230030 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596236944 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596292973 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596302032 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596333027 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596342087 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596357107 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596365929 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596417904 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596426964 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596481085 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596488953 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596498966 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596575975 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596637011 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596646070 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596667051 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596676111 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596692085 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.596699953 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.597026110 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:39.603168964 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:39.954680920 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:40.007222891 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:44.476958990 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:44.482016087 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:44.833487034 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:44.833585978 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:44.833677053 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:44.833724976 CEST49756587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:44.835038900 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:44.838390112 CEST5874975674.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:44.839852095 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:44.839934111 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:45.431463003 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:45.431663036 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:45.436624050 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:45.587785006 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:45.587929010 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:45.592967033 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:45.742717981 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:45.749026060 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:45.753880024 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:45.905823946 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:45.909248114 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:45.914274931 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.076251030 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.076435089 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.081231117 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.242641926 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.242796898 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.247657061 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.397072077 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.397414923 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.397475004 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.397475004 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.399493933 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.399494886 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.402358055 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.402369022 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.402378082 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.402709961 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.404339075 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.404433012 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.404536963 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.404575109 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.404620886 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.404762030 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.407109976 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.409141064 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.409456968 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.409532070 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.409565926 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.409583092 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.409610987 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.409616947 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.409620047 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.409636021 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.409720898 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.409784079 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.414074898 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414163113 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414457083 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414525032 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414532900 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.414634943 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414681911 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.414711952 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414738894 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414778948 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:46.414871931 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414984941 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.414994955 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415045023 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415081024 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415091991 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415127993 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415164948 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415234089 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415244102 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415252924 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.415285110 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419339895 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419352055 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419393063 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419445038 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419456005 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419529915 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419538975 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419548988 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419552088 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419555902 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419733047 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419743061 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419754028 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419764042 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419771910 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419781923 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419795036 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419804096 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419895887 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419905901 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419986010 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.419996977 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.420006037 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.420026064 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.420037985 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.420047998 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.420527935 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.769469023 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:46.815928936 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:53.363420963 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:53.368350029 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:53.721290112 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:53.721318007 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:53.721381903 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:53.721468925 CEST49757587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:53.722533941 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:53.728471994 CEST5874975774.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:53.731021881 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:53.731103897 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:54.321702957 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.321829081 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:54.326699972 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.479259014 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.479471922 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:54.486901045 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.634932995 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.635214090 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:54.640644073 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.808525085 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.811163902 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:54.815896988 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.970104933 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:54.971170902 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:54.976516008 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.138227940 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.138401985 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.143718958 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.294939041 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.295418978 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.295494080 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.295563936 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.295691967 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.297202110 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.300311089 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.300524950 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.300586939 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.300808907 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.301021099 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.302186012 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.302288055 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.302292109 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.302299976 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.302340984 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.302428961 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.306006908 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.306081057 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.307651043 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.311131954 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.311319113 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.311378956 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.311625957 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.318816900 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.318866968 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.318923950 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.318944931 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.319020033 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319060087 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.319094896 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319188118 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319190979 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.319248915 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.319408894 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:50:55.319488049 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319544077 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319628000 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319632053 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319683075 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319816113 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319819927 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319833040 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319835901 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.319844961 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.320111990 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.320194006 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.320203066 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.320205927 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327465057 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327470064 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327538967 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327543020 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327550888 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327584028 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327670097 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327855110 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327927113 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327930927 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327939987 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327943087 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327982903 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.327987909 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.328128099 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.328131914 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.328171015 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.328265905 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.328871965 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.328898907 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.328902006 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.329005957 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.329010010 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.679059982 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:50:55.815956116 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:06.196638107 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:06.201678991 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:06.552942991 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:06.553153992 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:06.553189039 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:06.553354979 CEST49758587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:06.554009914 CEST49759587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:06.558132887 CEST5874975874.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:06.559103966 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:06.559262037 CEST49759587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:07.175956964 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.178899050 CEST49759587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:07.185142040 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.338933945 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.339180946 CEST49759587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:07.345643044 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.498276949 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.500010967 CEST49759587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:07.504838943 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.657423019 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.659315109 CEST49759587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:07.664289951 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.928787947 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:07.928975105 CEST49759587192.168.2.474.119.238.7
                        Sep 25, 2024 13:51:07.940243006 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:08.096441984 CEST5874975974.119.238.7192.168.2.4
                        Sep 25, 2024 13:51:08.144228935 CEST49759587192.168.2.474.119.238.7
                        TimestampSource PortDest PortSource IPDest IP
                        Sep 25, 2024 13:47:04.618244886 CEST5175253192.168.2.41.1.1.1
                        Sep 25, 2024 13:47:04.933150053 CEST53517521.1.1.1192.168.2.4
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Sep 25, 2024 13:47:04.618244886 CEST192.168.2.41.1.1.10xcaadStandard query (0)mail.alhoneycomb.comA (IP address)IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Sep 25, 2024 13:47:04.933150053 CEST1.1.1.1192.168.2.40xcaadNo error (0)mail.alhoneycomb.com74.119.238.7A (IP address)IN (0x0001)false
                        TimestampSource PortDest PortSource IPDest IPCommands
                        Sep 25, 2024 13:47:05.638761997 CEST5874973574.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:17:05 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:47:05.641513109 CEST49735587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:47:05.804575920 CEST5874973574.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:47:05.805526972 CEST49735587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:47:06.182398081 CEST5874973574.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:47:06.183689117 CEST5874973574.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:47:06.460321903 CEST5874973574.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:47:06.468729973 CEST49735587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:47:06.627687931 CEST5874973574.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:47:06.631253958 CEST49735587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:47:06.803392887 CEST5874973574.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:47:06.803546906 CEST49735587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:47:06.962250948 CEST5874973574.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:47:06.967082977 CEST49735587192.168.2.474.119.238.7.
                        Sep 25, 2024 13:47:07.232748032 CEST5874973574.119.238.7192.168.2.4250 OK id=1stQU6-003nie-2o
                        Sep 25, 2024 13:47:07.276155949 CEST49735587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:47:07.636418104 CEST5874973574.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:47:08.248948097 CEST5874973874.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:17:08 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:47:08.249205112 CEST49738587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:47:08.405469894 CEST5874973874.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:47:08.405621052 CEST49738587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:47:08.562674046 CEST5874973874.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:47:08.722192049 CEST5874973874.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:47:08.722336054 CEST49738587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:47:08.885415077 CEST5874973874.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:47:08.885658979 CEST49738587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:47:09.055907965 CEST5874973874.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:47:09.056024075 CEST49738587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:47:09.211589098 CEST5874973874.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:47:09.213574886 CEST49738587192.168.2.474.119.238.7.
                        Sep 25, 2024 13:47:09.378366947 CEST5874973874.119.238.7192.168.2.4250 OK id=1stQU9-003nk4-0P
                        Sep 25, 2024 13:48:41.413129091 CEST49738587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:48:41.770004988 CEST5874973874.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:48:42.429656029 CEST5874974574.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:18:42 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:48:42.429876089 CEST49745587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:48:42.588143110 CEST5874974574.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:48:42.591605902 CEST49745587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:48:42.753504992 CEST5874974574.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:48:43.041888952 CEST5874974574.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:48:43.045347929 CEST49745587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:48:43.210947990 CEST5874974574.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:48:43.217628002 CEST49745587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:48:43.397593975 CEST5874974574.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:48:43.398029089 CEST49745587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:48:43.556334019 CEST5874974574.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:48:43.632217884 CEST49745587192.168.2.474.119.238.7.
                        Sep 25, 2024 13:48:43.976730108 CEST5874974574.119.238.7192.168.2.4250 OK id=1stQVf-003p9u-1V
                        Sep 25, 2024 13:49:05.575747013 CEST49745587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:49:05.938637018 CEST5874974574.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:49:06.551584959 CEST5874974674.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:19:06 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:49:06.552933931 CEST49746587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:49:06.707174063 CEST5874974674.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:49:06.707376957 CEST49746587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:49:06.866311073 CEST5874974674.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:49:07.027324915 CEST5874974674.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:49:07.027512074 CEST49746587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:07.181534052 CEST5874974674.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:49:07.181715012 CEST49746587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:07.501878977 CEST5874974674.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:49:07.503649950 CEST49746587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:49:07.659615040 CEST5874974674.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:49:08.032486916 CEST5874974674.119.238.7192.168.2.4250 OK id=1stQW3-003pTR-1q
                        Sep 25, 2024 13:49:08.254695892 CEST5874974674.119.238.7192.168.2.4250 OK id=1stQW3-003pTR-1q
                        Sep 25, 2024 13:49:21.234174967 CEST49746587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:49:21.593621016 CEST5874974674.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:49:22.205683947 CEST5874974774.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:19:22 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:49:22.205909014 CEST49747587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:49:22.366255045 CEST5874974774.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:49:22.366671085 CEST49747587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:49:22.526968002 CEST5874974774.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:49:22.701180935 CEST5874974774.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:49:22.727858067 CEST49747587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:22.889359951 CEST5874974774.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:49:22.890943050 CEST49747587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:23.065275908 CEST5874974774.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:49:23.130258083 CEST49747587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:49:23.290498018 CEST5874974774.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:49:23.685333967 CEST5874974774.119.238.7192.168.2.4250 OK id=1stQWJ-003peB-0e
                        Sep 25, 2024 13:49:29.596510887 CEST49747587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:49:29.959502935 CEST5874974774.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:49:30.576704979 CEST5874974874.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:19:30 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:49:30.576945066 CEST49748587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:49:30.733571053 CEST5874974874.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:49:30.733803034 CEST49748587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:49:30.889780045 CEST5874974874.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:49:31.045902967 CEST5874974874.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:49:31.046174049 CEST49748587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:31.202318907 CEST5874974874.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:49:31.202510118 CEST49748587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:31.368489027 CEST5874974874.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:49:31.368673086 CEST49748587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:49:31.523530960 CEST5874974874.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:49:31.895278931 CEST5874974874.119.238.7192.168.2.4250 OK id=1stQWR-003pqD-1Q
                        Sep 25, 2024 13:49:45.752015114 CEST49748587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:49:46.110486984 CEST5874974874.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:49:46.750304937 CEST5874974974.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:19:46 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:49:46.753251076 CEST49749587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:49:46.909567118 CEST5874974974.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:49:46.913117886 CEST49749587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:49:47.071275949 CEST5874974974.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:49:47.424681902 CEST5874974974.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:49:47.425062895 CEST49749587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:47.580908060 CEST5874974974.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:49:47.581587076 CEST49749587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:47.751648903 CEST5874974974.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:49:47.752006054 CEST49749587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:49:47.906538963 CEST5874974974.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:49:48.290328026 CEST5874974974.119.238.7192.168.2.4250 OK id=1stQWh-003q0C-2e
                        Sep 25, 2024 13:49:58.181993008 CEST49749587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:49:58.582319975 CEST5874974974.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:49:59.241594076 CEST5874975074.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:19:59 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:49:59.242506027 CEST49750587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:49:59.252166033 CEST5874975174.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:19:59 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:49:59.252357960 CEST49751587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:49:59.402936935 CEST5874975074.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:49:59.405088902 CEST49750587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:49:59.410754919 CEST5874975174.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:49:59.411117077 CEST49751587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:49:59.565506935 CEST5874975074.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:49:59.573605061 CEST5874975174.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:49:59.737960100 CEST5874975074.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:49:59.738229990 CEST49750587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:49:59.742007971 CEST5874975174.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:49:59.742249012 CEST49751587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:00.053877115 CEST5874975074.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:50:00.053893089 CEST5874975174.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:50:00.054053068 CEST49750587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:00.054117918 CEST49751587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:00.227026939 CEST5874975174.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:00.227157116 CEST49751587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:50:00.232218981 CEST5874975074.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:00.232332945 CEST49750587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:50:00.389353991 CEST5874975174.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:50:00.392995119 CEST5874975074.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:50:00.413604021 CEST49751587192.168.2.474.119.238.7.
                        Sep 25, 2024 13:50:00.420898914 CEST49750587192.168.2.474.119.238.7.
                        Sep 25, 2024 13:50:00.778933048 CEST5874975174.119.238.7192.168.2.4250 OK id=1stQWu-003q7n-0y
                        Sep 25, 2024 13:50:00.792026997 CEST5874975074.119.238.7192.168.2.4250 OK id=1stQWu-003q7m-0y
                        Sep 25, 2024 13:50:05.027139902 CEST49751587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:50:05.386956930 CEST5874975174.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:50:05.973901033 CEST5874975274.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:20:05 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:50:05.974323034 CEST49752587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:50:06.132379055 CEST5874975274.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:50:06.132653952 CEST49752587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:50:06.293986082 CEST5874975274.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:50:07.018098116 CEST5874975374.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:20:06 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:50:07.018239975 CEST49753587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:50:07.174287081 CEST5874975374.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:50:07.174484015 CEST49753587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:50:07.333709955 CEST5874975374.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:50:07.496124029 CEST5874975374.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:50:07.496342897 CEST49753587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:07.651818037 CEST5874975374.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:50:07.653286934 CEST49753587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:08.762449026 CEST5874975374.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:08.762592077 CEST49753587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:50:08.764682055 CEST5874975374.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:08.764875889 CEST5874975374.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:08.764920950 CEST5874975374.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:08.929207087 CEST5874975374.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:50:09.313504934 CEST5874975374.119.238.7192.168.2.4250 OK id=1stQX2-003qEU-2i
                        Sep 25, 2024 13:50:23.019412994 CEST49753587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:50:23.383440971 CEST5874975374.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:50:23.998385906 CEST5874975474.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:20:23 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:50:23.998862028 CEST49754587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:50:24.164786100 CEST5874975474.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:50:24.164992094 CEST49754587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:50:24.460604906 CEST5874975474.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:50:24.747060061 CEST5874975474.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:50:24.747394085 CEST49754587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:24.901597023 CEST5874975474.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:50:24.901721954 CEST49754587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:25.070724964 CEST5874975474.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:25.070873022 CEST49754587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:50:25.225476980 CEST5874975474.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:50:25.253304958 CEST49754587192.168.2.474.119.238.7.
                        Sep 25, 2024 13:50:25.603751898 CEST5874975474.119.238.7192.168.2.4250 OK id=1stQXJ-003qd0-0S
                        Sep 25, 2024 13:50:35.649914980 CEST49754587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:50:36.006119967 CEST5874975474.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:50:36.649435043 CEST5874975574.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:20:36 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:50:36.649646997 CEST49755587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:50:36.812257051 CEST5874975574.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:50:36.812500954 CEST49755587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:50:36.977385044 CEST5874975574.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:50:37.160439014 CEST5874975574.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:50:37.160615921 CEST49755587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:37.319883108 CEST5874975574.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:50:37.320086002 CEST49755587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:37.493993998 CEST5874975574.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:37.494132996 CEST49755587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:50:37.656573057 CEST5874975574.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:50:38.620735884 CEST5874975674.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:20:38 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:50:38.621220112 CEST49756587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:50:38.778038025 CEST5874975674.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:50:38.778238058 CEST49756587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:50:38.932553053 CEST5874975674.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:50:39.091675997 CEST5874975674.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:50:39.091835976 CEST49756587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:39.248099089 CEST5874975674.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:50:39.248241901 CEST49756587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:39.416466951 CEST5874975674.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:39.416601896 CEST49756587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:50:39.571702957 CEST5874975674.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:50:39.597026110 CEST49756587192.168.2.474.119.238.7.
                        Sep 25, 2024 13:50:39.954680920 CEST5874975674.119.238.7192.168.2.4250 OK id=1stQXX-003qs3-1Z
                        Sep 25, 2024 13:50:44.476958990 CEST49756587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:50:44.833487034 CEST5874975674.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:50:45.431463003 CEST5874975774.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:20:45 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:50:45.431663036 CEST49757587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:50:45.587785006 CEST5874975774.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:50:45.587929010 CEST49757587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:50:45.742717981 CEST5874975774.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:50:45.905823946 CEST5874975774.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:50:45.909248114 CEST49757587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:46.076251030 CEST5874975774.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:50:46.076435089 CEST49757587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:46.242641926 CEST5874975774.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:46.242796898 CEST49757587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:50:46.397072077 CEST5874975774.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:50:46.769469023 CEST5874975774.119.238.7192.168.2.4250 OK id=1stQXe-003qxS-10
                        Sep 25, 2024 13:50:53.363420963 CEST49757587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:50:53.721290112 CEST5874975774.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:50:54.321702957 CEST5874975874.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:20:54 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:50:54.321829081 CEST49758587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:50:54.479259014 CEST5874975874.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:50:54.479471922 CEST49758587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:50:54.634932995 CEST5874975874.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:50:54.808525085 CEST5874975874.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:50:54.811163902 CEST49758587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:54.970104933 CEST5874975874.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:50:54.971170902 CEST49758587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:50:55.138227940 CEST5874975874.119.238.7192.168.2.4250 Accepted
                        Sep 25, 2024 13:50:55.138401985 CEST49758587192.168.2.474.119.238.7DATA
                        Sep 25, 2024 13:50:55.294939041 CEST5874975874.119.238.7192.168.2.4354 Enter message, ending with "." on a line by itself
                        Sep 25, 2024 13:50:55.679059982 CEST5874975874.119.238.7192.168.2.4250 OK id=1stQXn-003r3Z-0f
                        Sep 25, 2024 13:51:06.196638107 CEST49758587192.168.2.474.119.238.7QUIT
                        Sep 25, 2024 13:51:06.552942991 CEST5874975874.119.238.7192.168.2.4221 md-la-5.webhostbox.net closing connection
                        Sep 25, 2024 13:51:07.175956964 CEST5874975974.119.238.7192.168.2.4220-md-la-5.webhostbox.net ESMTP Exim 4.96.2 #2 Wed, 25 Sep 2024 17:21:07 +0530
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 25, 2024 13:51:07.178899050 CEST49759587192.168.2.474.119.238.7EHLO 051829
                        Sep 25, 2024 13:51:07.338933945 CEST5874975974.119.238.7192.168.2.4250-md-la-5.webhostbox.net Hello 051829 [8.46.123.33]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPECONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 25, 2024 13:51:07.339180946 CEST49759587192.168.2.474.119.238.7AUTH login YmxvZ0BhbGhvbmV5Y29tYi5jb20=
                        Sep 25, 2024 13:51:07.498276949 CEST5874975974.119.238.7192.168.2.4334 UGFzc3dvcmQ6
                        Sep 25, 2024 13:51:07.657423019 CEST5874975974.119.238.7192.168.2.4235 Authentication succeeded
                        Sep 25, 2024 13:51:07.659315109 CEST49759587192.168.2.474.119.238.7MAIL FROM:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:51:07.928787947 CEST5874975974.119.238.7192.168.2.4250 OK
                        Sep 25, 2024 13:51:07.928975105 CEST49759587192.168.2.474.119.238.7RCPT TO:<blog@alhoneycomb.com>
                        Sep 25, 2024 13:51:08.096441984 CEST5874975974.119.238.7192.168.2.4250 Accepted

                        Click to jump to process

                        Click to jump to process

                        Click to dive into process behavior distribution

                        Click to jump to process

                        Target ID:0
                        Start time:07:46:57
                        Start date:25/09/2024
                        Path:C:\Users\user\Desktop\rPO_CW00402902400415.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Users\user\Desktop\rPO_CW00402902400415.exe"
                        Imagebase:0x193081b0000
                        File size:1'849'494 bytes
                        MD5 hash:0E509CAF00F17B291C24A27E87E9CACC
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000000.00000002.1811254005.000001930A253000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000000.00000002.1811970397.0000019319F07000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                        Reputation:low
                        Has exited:true

                        Target ID:1
                        Start time:07:46:58
                        Start date:25/09/2024
                        Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                        Imagebase:0x20000
                        File size:43'008 bytes
                        MD5 hash:9827FF3CDF4B83F9C86354606736CA9C
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000001.00000002.4137755318.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000001.00000002.4139321179.0000000002421000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000001.00000002.4139321179.0000000002421000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                        Reputation:moderate
                        Has exited:false

                        Target ID:2
                        Start time:07:46:58
                        Start date:25/09/2024
                        Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                        Imagebase:0x980000
                        File size:43'008 bytes
                        MD5 hash:9827FF3CDF4B83F9C86354606736CA9C
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:moderate
                        Has exited:true

                        Target ID:5
                        Start time:07:46:58
                        Start date:25/09/2024
                        Path:C:\Windows\System32\WerFault.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\WerFault.exe -u -p 6860 -s 1040
                        Imagebase:0x7ff6afcf0000
                        File size:570'736 bytes
                        MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Reset < >

                          Execution Graph

                          Execution Coverage:12.1%
                          Dynamic/Decrypted Code Coverage:100%
                          Signature Coverage:0%
                          Total number of Nodes:21
                          Total number of Limit Nodes:0
                          execution_graph 15235 7ffd9bac8bf9 15236 7ffd9bac8c0f VirtualProtect 15235->15236 15238 7ffd9bac8cb1 15236->15238 15239 7ffd9bab0ab5 15240 7ffd9bab0ac4 15239->15240 15253 7ffd9bab0618 15240->15253 15242 7ffd9bab0b73 15257 7ffd9bab0628 15242->15257 15244 7ffd9bab0b94 15245 7ffd9bab0628 VirtualProtect 15244->15245 15246 7ffd9bab0bd7 15245->15246 15247 7ffd9bab0618 VirtualProtect 15246->15247 15248 7ffd9bab0bef 15247->15248 15249 7ffd9bab0628 VirtualProtect 15248->15249 15250 7ffd9bab0c10 15249->15250 15251 7ffd9bab0628 VirtualProtect 15250->15251 15252 7ffd9bab0c53 15251->15252 15254 7ffd9bab0621 VirtualProtect 15253->15254 15256 7ffd9bab3a51 15254->15256 15256->15242 15258 7ffd9bab0631 VirtualProtect 15257->15258 15260 7ffd9bab3a51 15258->15260 15260->15244

                          Control-flow Graph

                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID:
                          • String ID: ^$fish
                          • API String ID: 0-2906118863
                          • Opcode ID: 22d1648a0442f8cbed123aa592ccb4a61f1432c450161f1a73e164c0c4e798bb
                          • Instruction ID: dd0e0c93045edf041614eab799cad894a834775f50cc7499ca4527b0b952df44
                          • Opcode Fuzzy Hash: 22d1648a0442f8cbed123aa592ccb4a61f1432c450161f1a73e164c0c4e798bb
                          • Instruction Fuzzy Hash: 02D16C3171DB4E0FE76DAB6898754B977E1EF96310F05027EE49BC71E2DD28A8028781
                          Memory Dump Source
                          • Source File: 00000000.00000002.1821156603.00007FFD9BB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BB80000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bb80000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: a9cdd91f66de84422370782edd9698b45c1874cb1fab80d4bfc3472f6f8b4fea
                          • Instruction ID: 01694197a01c56166d8cc79f3cf894002b722b27766aa63b9ee291d15a8bfa63
                          • Opcode Fuzzy Hash: a9cdd91f66de84422370782edd9698b45c1874cb1fab80d4bfc3472f6f8b4fea
                          • Instruction Fuzzy Hash: D3D23732A0FBC94FD766DB6888655A47FE0FF56304F4A01FAD089CB1E2DA786906C741

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 741 7ffd9babf3c9-7ffd9babf43e 746 7ffd9babf440-7ffd9babf445 741->746 747 7ffd9babf4af-7ffd9babf4c5 call 7ffd9babb920 741->747 748 7ffd9babf447-7ffd9babf461 call 7ffd9bab7bb0 746->748 749 7ffd9babf4c6-7ffd9babf4da 746->749 758 7ffd9babf4c7-7ffd9babf4da 747->758 759 7ffd9babf4df-7ffd9babf4ea 747->759 751 7ffd9babf578-7ffd9babf57a 749->751 756 7ffd9babf57c-7ffd9babf581 751->756 757 7ffd9babf5eb-7ffd9babf5f0 751->757 760 7ffd9babf583-7ffd9babf59f 756->760 761 7ffd9babf602 756->761 757->761 758->751 762 7ffd9babf4ec-7ffd9babf4ff 759->762 763 7ffd9babf501-7ffd9babf50c 759->763 764 7ffd9babf608-7ffd9babf656 call 7ffd9babb920 * 2 call 7ffd9bab7810 761->764 765 7ffd9babf604-7ffd9babf605 761->765 762->751 767 7ffd9babf50e-7ffd9babf520 763->767 768 7ffd9babf522-7ffd9babf541 763->768 780 7ffd9babf65c-7ffd9babf67a 764->780 781 7ffd9babf7d9-7ffd9babf833 764->781 765->764 767->751 768->751 773 7ffd9babf543-7ffd9babf574 768->773 773->751 780->781 782 7ffd9babf680-7ffd9babf69a 780->782 792 7ffd9babf966-7ffd9babf9c3 781->792 793 7ffd9babf839-7ffd9babf894 call 7ffd9babb920 * 2 call 7ffd9bab7810 781->793 784 7ffd9babf69c-7ffd9babf69f 782->784 785 7ffd9babf6f3-7ffd9babf718 782->785 786 7ffd9babf720-7ffd9babf72a 784->786 787 7ffd9babf6a1-7ffd9babf6c0 784->787 789 7ffd9babf71a-7ffd9babf71f 785->789 790 7ffd9babf731-7ffd9babf746 785->790 794 7ffd9babf72c-7ffd9babf72f 786->794 795 7ffd9babf75e-7ffd9babf7af call 7ffd9babc2f0 786->795 787->790 791 7ffd9babf6c2-7ffd9babf6c7 787->791 789->786 796 7ffd9babf748-7ffd9babf759 790->796 791->796 797 7ffd9babf6c9-7ffd9babf6f2 call 7ffd9bab7bb0 791->797 809 7ffd9babf9c9-7ffd9babfa1e call 7ffd9babb920 * 2 call 7ffd9bab7810 792->809 810 7ffd9babfa7e-7ffd9babfa89 792->810 793->792 820 7ffd9babf89a-7ffd9babf8f0 793->820 794->795 795->781 808 7ffd9babf7b1-7ffd9babf7d8 795->808 796->795 799 7ffd9babf75b-7ffd9babf75c 796->799 797->785 799->795 809->810 835 7ffd9babfa20-7ffd9babfa44 809->835 817 7ffd9babfa8b-7ffd9babfa8d 810->817 818 7ffd9babfa8e-7ffd9babfaaa 810->818 817->818 821 7ffd9babfaac-7ffd9babfad7 818->821 822 7ffd9babfaf4-7ffd9babfb36 call 7ffd9babb920 * 2 call 7ffd9bab7810 818->822 820->792 824 7ffd9babf8f2-7ffd9babf93d call 7ffd9babc2f0 820->824 825 7ffd9babfc6b-7ffd9babfc9a 821->825 826 7ffd9babfadd-7ffd9babfaf3 821->826 822->825 850 7ffd9babfb3c-7ffd9babfb5a 822->850 824->792 836 7ffd9babf93f-7ffd9babf965 824->836 844 7ffd9babfc9c-7ffd9babfcc7 825->844 845 7ffd9babfce4-7ffd9babfd23 call 7ffd9babb920 * 2 call 7ffd9bab7810 825->845 826->822 839 7ffd9babfa46-7ffd9babfa56 835->839 840 7ffd9babfa72-7ffd9babfa7d 835->840 839->810 843 7ffd9babfa58-7ffd9babfa6f 839->843 843->840 847 7ffd9babfe27-7ffd9babfe59 844->847 848 7ffd9babfccd-7ffd9babfce3 844->848 845->847 880 7ffd9babfd29-7ffd9babfd44 845->880 865 7ffd9babfe5b-7ffd9babfe86 847->865 866 7ffd9babfea3-7ffd9babfebd call 7ffd9babb920 847->866 848->845 850->825 852 7ffd9babfb60-7ffd9babfb7a 850->852 855 7ffd9babfb7c-7ffd9babfb7f 852->855 856 7ffd9babfbd3-7ffd9babfbd7 852->856 857 7ffd9babfc00-7ffd9babfc3f call 7ffd9babc2f0 855->857 858 7ffd9babfb81-7ffd9babfb9a 855->858 860 7ffd9babfc58-7ffd9babfc6a 856->860 861 7ffd9babfbd9-7ffd9babfbff call 7ffd9bab7bb0 856->861 877 7ffd9babfc41 857->877 863 7ffd9babfb9c-7ffd9babfbb1 858->863 864 7ffd9babfbb3-7ffd9babfbc4 858->864 861->857 869 7ffd9babfbc8-7ffd9babfbd0 863->869 864->869 870 7ffd9babff55-7ffd9babff67 865->870 871 7ffd9babfe8c-7ffd9babfe9f 865->871 876 7ffd9babfbd2 869->876 869->877 890 7ffd9babffa9-7ffd9babffb7 870->890 891 7ffd9babff69-7ffd9babff8a 870->891 871->866 876->856 877->825 886 7ffd9babfc43-7ffd9babfc56 877->886 881 7ffd9babfd46-7ffd9babfd49 880->881 882 7ffd9babfd9d-7ffd9babfda4 880->882 887 7ffd9babfd4b-7ffd9babfd69 881->887 888 7ffd9babfdca-7ffd9babfdd9 881->888 882->847 889 7ffd9babfdaa-7ffd9babfdc7 882->889 886->860 892 7ffd9babfd6b-7ffd9babfd70 887->892 893 7ffd9babfdda-7ffd9babfdee call 7ffd9babc2f0 887->893 888->893 889->888 896 7ffd9babffbd-7ffd9babffd1 890->896 897 7ffd9bac0113-7ffd9bac0129 890->897 894 7ffd9babff8c-7ffd9babffa6 891->894 895 7ffd9babffd4-7ffd9bac000f call 7ffd9babb920 * 2 call 7ffd9babd5a0 891->895 899 7ffd9babfd72-7ffd9babfd96 call 7ffd9bab7bb0 892->899 900 7ffd9babfdf1-7ffd9babfdfd 892->900 893->900 894->890 918 7ffd9bac0029-7ffd9bac0034 895->918 919 7ffd9bac0011-7ffd9bac0027 895->919 896->895 908 7ffd9bac012b-7ffd9bac013f 897->908 909 7ffd9bac012a 897->909 899->882 900->847 906 7ffd9babfdff-7ffd9babfe26 900->906 914 7ffd9bac0141-7ffd9bac0179 908->914 909->908 916 7ffd9bac017b-7ffd9bac018d call 7ffd9bab0278 914->916 917 7ffd9bac018f 914->917 921 7ffd9bac0194-7ffd9bac0221 916->921 917->921 927 7ffd9bac0046 918->927 928 7ffd9bac0036-7ffd9bac0044 918->928 919->918 950 7ffd9bac0308-7ffd9bac030f 921->950 951 7ffd9bac0227-7ffd9bac029f 921->951 930 7ffd9bac0048-7ffd9bac004d 927->930 928->930 932 7ffd9bac0070-7ffd9bac0086 930->932 933 7ffd9bac004f-7ffd9bac006e call 7ffd9bab3bd0 930->933 940 7ffd9bac0088-7ffd9bac0099 932->940 941 7ffd9bac009a-7ffd9bac00af call 7ffd9babdf90 932->941 938 7ffd9bac00b3-7ffd9bac00b9 933->938 938->909 943 7ffd9bac00bb-7ffd9bac00c0 938->943 940->941 941->938 943->914 946 7ffd9bac00c2-7ffd9bac00f0 call 7ffd9bab7bb0 call 7ffd9bab7810 943->946 946->897 958 7ffd9bac00f2-7ffd9bac0112 946->958 954 7ffd9bac032c-7ffd9bac033c 950->954 955 7ffd9bac0311-7ffd9bac031e 950->955 966 7ffd9bac02ff-7ffd9bac0307 call 7ffd9bac0354 951->966 967 7ffd9bac02a1-7ffd9bac02a7 call 7ffd9bab9178 951->967 960 7ffd9bac0342-7ffd9bac0353 954->960 955->954 959 7ffd9bac0320-7ffd9bac032a 955->959 959->954 966->950 970 7ffd9bac02ac-7ffd9bac02bb 967->970 973 7ffd9bac02df-7ffd9bac02fe 970->973 974 7ffd9bac02bd-7ffd9bac02de 970->974 973->966 974->973
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 40d47e0ead6c1be30da7014b4a6bd6468523b7f98f4a3e00475d9fc510861384
                          • Instruction ID: 91dddad0a46fd9c8d1bf0c98fd9aadd811b2980ea27135ecf07c44ae70682c7f
                          • Opcode Fuzzy Hash: 40d47e0ead6c1be30da7014b4a6bd6468523b7f98f4a3e00475d9fc510861384
                          • Instruction Fuzzy Hash: E3B28A30A0DB594FD329DB28C4A04B5B7E1FF85301F0546BEE49AC72A6DE35E946CB81
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 1370afc66226891567537ffd09a093c395214a256459b685706d2325207e6426
                          • Instruction ID: 229c6095a40afa7d2544b60a675ce40e065174fe11d001c42c1f3d903e1b34ca
                          • Opcode Fuzzy Hash: 1370afc66226891567537ffd09a093c395214a256459b685706d2325207e6426
                          • Instruction Fuzzy Hash: 83521830B0DA1D4FEB68DF68C46567977E1EF59301F1501BEE09EC72A2CE64AD428B81
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 848b09a41bbc1b365f49c88d8c6da2492a5dac166c0c71b972a0584873858897
                          • Instruction ID: f7c91b14ce992e6ba23eeef2f199f9cf14b2e90b04dd0933dafbf6342d88fecb
                          • Opcode Fuzzy Hash: 848b09a41bbc1b365f49c88d8c6da2492a5dac166c0c71b972a0584873858897
                          • Instruction Fuzzy Hash: F252CB30A0EA4E4FE768EB28C4615B577E1FF81300B1445BEE09BC71E6DE79A946C780
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 8f162e5e6db02d6ca186129b29fa98c9a7e91b7b7959ec275653c805a250e87f
                          • Instruction ID: bde9657388368feda3d79cc50e394ec07d213154166a3e514a85138d1d3b0d0e
                          • Opcode Fuzzy Hash: 8f162e5e6db02d6ca186129b29fa98c9a7e91b7b7959ec275653c805a250e87f
                          • Instruction Fuzzy Hash: 47124A31B1E94D4FE378EBAC88261B477D1EF85320B1602BDD44DC71B6DEA86D068785

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 554 7ffd9bab396a-7ffd9bab3977 555 7ffd9bab3979-7ffd9bab3981 554->555 556 7ffd9bab3982-7ffd9bab3993 554->556 555->556 557 7ffd9bab3995-7ffd9bab399d 556->557 558 7ffd9bab399e-7ffd9bab3a4f VirtualProtect 556->558 557->558 562 7ffd9bab3a57-7ffd9bab3a7f 558->562 563 7ffd9bab3a51 558->563 563->562
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID: ProtectVirtual
                          • String ID:
                          • API String ID: 544645111-0
                          • Opcode ID: 892f6ef2613fc30e0e6c81ed7c4e9621643ea502c991c1e9d01125b511769d9c
                          • Instruction ID: 0af3b1deb9f235e21d40a8f623d7aa17ceb527e7a7eb7642b070de77e86ca010
                          • Opcode Fuzzy Hash: 892f6ef2613fc30e0e6c81ed7c4e9621643ea502c991c1e9d01125b511769d9c
                          • Instruction Fuzzy Hash: 5D414A3190DB884FDB19DBA898166E9BFF0EF56321F0402AFD059C31A3CF646856CB91

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 564 7ffd9bab0618-7ffd9bab062a 566 7ffd9bab0698-7ffd9bab06a6 564->566 567 7ffd9bab062c-7ffd9bab0633 564->567 570 7ffd9bab39b0-7ffd9bab3a4f VirtualProtect 566->570 567->570 574 7ffd9bab3a57-7ffd9bab3a7f 570->574 575 7ffd9bab3a51 570->575 575->574
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID: ProtectVirtual
                          • String ID:
                          • API String ID: 544645111-0
                          • Opcode ID: 71d0670a7a7a1626e8c08a0f652097853165bafa8278cd9ce94ff6d3f5000545
                          • Instruction ID: 844eaaf0e242c685996d2a82fdc116adbcefe1ea307ab26d4e5287608bc36155
                          • Opcode Fuzzy Hash: 71d0670a7a7a1626e8c08a0f652097853165bafa8278cd9ce94ff6d3f5000545
                          • Instruction Fuzzy Hash: F5312531A0CA1C8FDB18EB9898556F97BE1EF99325F04427FE059C31A2DF746846CB81

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 667 7ffd9bac8bf9-7ffd9bac8caf VirtualProtect 671 7ffd9bac8cb7-7ffd9bac8cdf 667->671 672 7ffd9bac8cb1 667->672 672->671
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID: ProtectVirtual
                          • String ID:
                          • API String ID: 544645111-0
                          • Opcode ID: 17be76b67f3a646a5d4c3e72f923f5dcfb93286874cb1942a2f51dc4d5eb4557
                          • Instruction ID: d0c8f63d4098124f7e9bc111dd98a85ddee10ce06fd053185277defed58b1e74
                          • Opcode Fuzzy Hash: 17be76b67f3a646a5d4c3e72f923f5dcfb93286874cb1942a2f51dc4d5eb4557
                          • Instruction Fuzzy Hash: 1431E631A0CB5C8FDB18EFA898466F97BF1FB65321F04426FD049D3192DB606856CB81

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 734 7ffd9baba034-7ffd9bac8caf VirtualProtect 739 7ffd9bac8cb7-7ffd9bac8cdf 734->739 740 7ffd9bac8cb1 734->740 740->739
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.1819919168.00007FFD9BAB0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BAB0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bab0000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID: ProtectVirtual
                          • String ID:
                          • API String ID: 544645111-0
                          • Opcode ID: 5884c8ee9a5e59a246e101e2f760a6420d899b070fbc45f0275585ec53ff99ce
                          • Instruction ID: 8a4c78ae8139737f021cf4eb326e7217da41cd1e0f469d0d3d3424c2dabf1fd2
                          • Opcode Fuzzy Hash: 5884c8ee9a5e59a246e101e2f760a6420d899b070fbc45f0275585ec53ff99ce
                          • Instruction Fuzzy Hash: 3F31C731A0CA1C8FDB1CEF9898456F9B7E5FBA5321F00422FD049D3292DB646852CB81
                          Memory Dump Source
                          • Source File: 00000000.00000002.1821156603.00007FFD9BB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BB80000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bb80000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: b1c16a83e10448fac341a4bd96f83a5fdaa18954622c924cfa8ecbd1d165841f
                          • Instruction ID: 090ce363c12f27f244780d760ca9a99555b8afd526576d7a974989b3b5858d69
                          • Opcode Fuzzy Hash: b1c16a83e10448fac341a4bd96f83a5fdaa18954622c924cfa8ecbd1d165841f
                          • Instruction Fuzzy Hash: A6412631A0EA8D4FDB56DF64C8644E87BF0FF59304B0A01EAD04ACB5A2DA74A841C740
                          Memory Dump Source
                          • Source File: 00000000.00000002.1821156603.00007FFD9BB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BB80000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_7ffd9bb80000_rPO_CW00402902400415.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 7aa2157dfb828b43575427f113c3ffc1dbaa2325fe8fa9719eb07841c3bb74e5
                          • Instruction ID: a3bee0d768627d7bccc74331d36cecdbf316a2784dcafc36112750c0fe87e149
                          • Opcode Fuzzy Hash: 7aa2157dfb828b43575427f113c3ffc1dbaa2325fe8fa9719eb07841c3bb74e5
                          • Instruction Fuzzy Hash: EFF09A72B0995C8FDF50DA9CD896AACB7F0FB9A744F4000B6D09ED7152CE30B90A8B41

                          Execution Graph

                          Execution Coverage:10.2%
                          Dynamic/Decrypted Code Coverage:100%
                          Signature Coverage:0.7%
                          Total number of Nodes:418
                          Total number of Limit Nodes:39
                          execution_graph 43005 2290848 43007 229084e 43005->43007 43006 229091b 43007->43006 43012 22915f0 43007->43012 43030 22914d7 43007->43030 43043 59af298 43007->43043 43047 59af287 43007->43047 43013 229157e 43012->43013 43015 22914ee 43013->43015 43016 22915fb 43013->43016 43027 229d968 3 API calls 43013->43027 43029 229da90 3 API calls 43013->43029 43094 229d978 43013->43094 43014 22915e8 43014->43007 43015->43014 43020 229d978 3 API calls 43015->43020 43022 22915f0 9 API calls 43015->43022 43051 59ae990 43015->43051 43057 59ae9a0 43015->43057 43063 2297043 43015->43063 43067 22970e0 43015->43067 43071 59a8fa0 43015->43071 43077 59a8f92 43015->43077 43083 229da90 43015->43083 43090 229d968 43015->43090 43016->43007 43020->43015 43022->43015 43027->43015 43029->43015 43032 22914ee 43030->43032 43031 22915e8 43031->43007 43032->43031 43033 22970e0 2 API calls 43032->43033 43034 2297043 2 API calls 43032->43034 43035 229d968 3 API calls 43032->43035 43036 229d978 3 API calls 43032->43036 43037 229da90 3 API calls 43032->43037 43038 22915f0 9 API calls 43032->43038 43039 59a8f92 3 API calls 43032->43039 43040 59a8fa0 3 API calls 43032->43040 43041 59ae990 SetWindowsHookExA 43032->43041 43042 59ae9a0 SetWindowsHookExA 43032->43042 43033->43032 43034->43032 43035->43032 43036->43032 43037->43032 43038->43032 43039->43032 43040->43032 43041->43032 43042->43032 43044 59af2a7 43043->43044 43202 59add68 43044->43202 43048 59af298 43047->43048 43049 59add68 4 API calls 43048->43049 43050 59af2c7 43049->43050 43050->43007 43052 59ae9a8 43051->43052 43053 59ae9ed 43052->43053 43098 59aea00 43052->43098 43102 59ae9f0 43052->43102 43106 59aea82 43052->43106 43053->43015 43058 59ae9a8 43057->43058 43059 59ae9ed 43058->43059 43060 59aea82 SetWindowsHookExA 43058->43060 43061 59ae9f0 SetWindowsHookExA 43058->43061 43062 59aea00 SetWindowsHookExA 43058->43062 43059->43015 43060->43058 43061->43058 43062->43058 43064 2297068 43063->43064 43065 22970ac 43064->43065 43114 2299d9a 43064->43114 43065->43015 43068 22970ea 43067->43068 43069 229717f 43068->43069 43070 2299d9a 2 API calls 43068->43070 43069->43015 43070->43068 43072 59a8fb2 43071->43072 43075 59a9063 43072->43075 43144 59a8c34 43072->43144 43074 59a9029 43149 59a8c54 43074->43149 43075->43015 43078 59a8f28 43077->43078 43078->43077 43079 59a8c34 2 API calls 43078->43079 43081 59a9063 43078->43081 43080 59a9029 43079->43080 43082 59a8c54 KiUserCallbackDispatcher 43080->43082 43081->43015 43082->43081 43084 229da9a 43083->43084 43085 229dab4 43084->43085 43188 59a3978 43084->43188 43193 59a3968 43084->43193 43088 229dafa 43085->43088 43198 59a5437 43085->43198 43088->43015 43092 229d98e 43090->43092 43091 229dafa 43091->43015 43092->43091 43093 59a5437 3 API calls 43092->43093 43093->43091 43096 229d98e 43094->43096 43095 229dafa 43095->43015 43096->43095 43097 59a5437 3 API calls 43096->43097 43097->43095 43100 59aea1d 43098->43100 43099 59aea80 43099->43052 43100->43099 43110 59adbc8 43100->43110 43103 59aea00 43102->43103 43104 59adbc8 SetWindowsHookExA 43103->43104 43105 59aea80 43103->43105 43104->43103 43105->43052 43107 59aea3d 43106->43107 43108 59adbc8 SetWindowsHookExA 43107->43108 43109 59aea80 43107->43109 43108->43107 43109->43052 43113 59aec08 SetWindowsHookExA 43110->43113 43112 59aec92 43112->43100 43113->43112 43115 2299e03 43114->43115 43116 2299f17 GetActiveWindow 43115->43116 43117 2299f45 43115->43117 43118 2299fb7 43115->43118 43116->43117 43117->43118 43121 229a7c0 43117->43121 43125 229a7b0 43117->43125 43118->43064 43122 229a7c9 43121->43122 43129 2299cb8 43122->43129 43126 229a7c9 43125->43126 43127 2299cb8 OleInitialize 43126->43127 43128 229a7d4 43127->43128 43128->43118 43130 2299cc3 43129->43130 43133 229b81c 43130->43133 43132 229ba32 43134 229b827 43133->43134 43136 229bb11 43134->43136 43137 229b904 43134->43137 43136->43132 43139 229b90f 43137->43139 43138 229be4b 43138->43136 43139->43138 43141 229b920 43139->43141 43142 229be80 OleInitialize 43141->43142 43143 229bee4 43142->43143 43143->43138 43145 59a8c3f 43144->43145 43153 59aa15b 43145->43153 43159 59aa170 43145->43159 43151 59a8c5f 43149->43151 43152 59ac68b 43151->43152 43184 59a9df4 43151->43184 43152->43075 43154 59a9202 43153->43154 43155 59aa167 43153->43155 43154->43074 43164 59aa680 43155->43164 43169 59aa671 43155->43169 43156 59aa21e 43160 59aa19b 43159->43160 43162 59aa680 2 API calls 43160->43162 43163 59aa671 2 API calls 43160->43163 43161 59aa21e 43162->43161 43163->43161 43165 59aa6ad 43164->43165 43166 59aa72e 43165->43166 43174 59aa7e0 43165->43174 43179 59aa7f0 43165->43179 43170 59aa680 43169->43170 43171 59aa72e 43170->43171 43172 59aa7f0 GetModuleHandleW 43170->43172 43173 59aa7e0 GetModuleHandleW 43170->43173 43172->43171 43173->43171 43178 59aa805 43174->43178 43175 59aaa40 43175->43166 43176 59aab68 GetModuleHandleW 43177 59aab95 43176->43177 43177->43166 43178->43175 43178->43176 43183 59aa805 43179->43183 43180 59aaa40 43180->43166 43181 59aab68 GetModuleHandleW 43182 59aab95 43181->43182 43182->43166 43183->43180 43183->43181 43185 59ac6a0 KiUserCallbackDispatcher 43184->43185 43187 59ac70e 43185->43187 43187->43151 43190 59a398d 43188->43190 43189 59a3ba2 43189->43085 43190->43189 43191 59a3fd0 GlobalMemoryStatusEx GlobalMemoryStatusEx GlobalMemoryStatusEx 43190->43191 43192 59a3f91 GlobalMemoryStatusEx GlobalMemoryStatusEx GlobalMemoryStatusEx 43190->43192 43191->43190 43192->43190 43195 59a398d 43193->43195 43194 59a3ba2 43194->43085 43195->43194 43196 59a3fd0 GlobalMemoryStatusEx GlobalMemoryStatusEx GlobalMemoryStatusEx 43195->43196 43197 59a3f91 GlobalMemoryStatusEx GlobalMemoryStatusEx GlobalMemoryStatusEx 43195->43197 43196->43195 43197->43195 43199 59a5442 43198->43199 43200 59a3978 3 API calls 43199->43200 43201 59a5449 43200->43201 43201->43088 43204 59add73 43202->43204 43206 59af2e0 43204->43206 43205 59af78d 43205->43205 43208 59af2eb 43206->43208 43207 59af9d8 43209 59afa33 43207->43209 43223 5e69b89 43207->43223 43208->43207 43208->43209 43213 5e60db2 43208->43213 43218 5e60dc0 43208->43218 43209->43205 43215 5e60dbd 43213->43215 43214 5e60e05 43214->43207 43215->43214 43227 5e60f70 43215->43227 43232 5e60f6a 43215->43232 43219 5e60de1 43218->43219 43220 5e60e05 43219->43220 43221 5e60f70 3 API calls 43219->43221 43222 5e60f6a 3 API calls 43219->43222 43220->43207 43221->43220 43222->43220 43225 5e69bb9 43223->43225 43224 5e69f98 WaitMessage 43224->43225 43225->43224 43226 5e69c44 43225->43226 43229 5e60f7d 43227->43229 43228 5e60fb6 43228->43214 43229->43228 43237 5e60fc8 43229->43237 43243 5e60fd8 43229->43243 43233 5e60f70 43232->43233 43234 5e60fb6 43233->43234 43235 5e60fc8 3 API calls 43233->43235 43236 5e60fd8 3 API calls 43233->43236 43234->43214 43235->43234 43236->43234 43238 5e61000 43237->43238 43239 5e61028 43238->43239 43249 5e610d4 43238->43249 43260 5e61088 43238->43260 43270 5e61070 43238->43270 43239->43239 43244 5e61000 43243->43244 43245 5e61028 43244->43245 43246 5e610d4 3 API calls 43244->43246 43247 5e61070 3 API calls 43244->43247 43248 5e61088 3 API calls 43244->43248 43245->43245 43246->43245 43247->43245 43248->43245 43250 5e61092 43249->43250 43251 5e610e2 43249->43251 43280 5e61e0f 43250->43280 43284 5e61e1c 43250->43284 43288 5e61e78 43250->43288 43292 5e61e88 43250->43292 43252 5e61097 43296 5e65a58 43252->43296 43305 5e65a70 43252->43305 43253 5e610d1 43253->43239 43261 5e61092 43260->43261 43266 5e61e0f 3 API calls 43261->43266 43267 5e61e1c 3 API calls 43261->43267 43268 5e61e88 3 API calls 43261->43268 43269 5e61e78 3 API calls 43261->43269 43262 5e61097 43264 5e65a70 3 API calls 43262->43264 43265 5e65a58 3 API calls 43262->43265 43263 5e610d1 43263->43239 43264->43263 43265->43263 43266->43262 43267->43262 43268->43262 43269->43262 43271 5e61088 43270->43271 43274 5e61e0f 3 API calls 43271->43274 43275 5e61e1c 3 API calls 43271->43275 43276 5e61e88 3 API calls 43271->43276 43277 5e61e78 3 API calls 43271->43277 43272 5e61097 43278 5e65a70 3 API calls 43272->43278 43279 5e65a58 3 API calls 43272->43279 43273 5e610d1 43273->43239 43274->43272 43275->43272 43276->43272 43277->43272 43278->43273 43279->43273 43283 5e61e10 43280->43283 43281 5e61db3 43281->43252 43282 5e60dc0 3 API calls 43282->43281 43283->43281 43283->43282 43287 5e61e10 43284->43287 43285 5e61db3 43285->43252 43286 5e60dc0 3 API calls 43286->43285 43287->43285 43287->43286 43291 5e61e10 43288->43291 43289 5e61db3 43289->43252 43290 5e60dc0 3 API calls 43290->43289 43291->43288 43291->43289 43291->43290 43295 5e61eb8 43292->43295 43293 5e62190 43293->43252 43294 5e60dc0 3 API calls 43294->43293 43295->43293 43295->43294 43298 5e65aa1 43296->43298 43300 5e65ba1 43296->43300 43297 5e65aad 43297->43253 43298->43297 43314 5e65ce8 43298->43314 43318 5e65cd8 43298->43318 43299 5e65aed 43303 59aa15b 2 API calls 43299->43303 43304 59aa170 2 API calls 43299->43304 43300->43253 43303->43300 43304->43300 43307 5e65aa1 43305->43307 43309 5e65ba1 43305->43309 43306 5e65aad 43306->43253 43307->43306 43310 5e65ce8 3 API calls 43307->43310 43311 5e65cd8 3 API calls 43307->43311 43308 5e65aed 43312 59aa15b 2 API calls 43308->43312 43313 59aa170 2 API calls 43308->43313 43309->43253 43310->43308 43311->43308 43312->43309 43313->43309 43323 5e65d28 43314->43323 43332 5e65d19 43314->43332 43315 5e65cf2 43315->43299 43319 5e65ce8 43318->43319 43321 5e65d28 3 API calls 43319->43321 43322 5e65d19 3 API calls 43319->43322 43320 5e65cf2 43320->43299 43321->43320 43322->43320 43324 5e65d39 43323->43324 43326 5e65d54 43323->43326 43327 59aab18 GetModuleHandleW 43324->43327 43328 59aa7f0 GetModuleHandleW 43324->43328 43329 59aa7e0 GetModuleHandleW 43324->43329 43325 5e65d44 43325->43326 43330 5e65d28 GetModuleHandleW GetModuleHandleW GetModuleHandleW 43325->43330 43331 5e65d19 GetModuleHandleW GetModuleHandleW GetModuleHandleW 43325->43331 43326->43315 43327->43325 43328->43325 43329->43325 43330->43326 43331->43326 43333 5e65d28 43332->43333 43335 5e65d54 43333->43335 43338 59aab18 GetModuleHandleW 43333->43338 43339 59aa7f0 GetModuleHandleW 43333->43339 43340 59aa7e0 GetModuleHandleW 43333->43340 43334 5e65d44 43334->43335 43336 5e65d28 GetModuleHandleW GetModuleHandleW GetModuleHandleW 43334->43336 43337 5e65d19 GetModuleHandleW GetModuleHandleW GetModuleHandleW 43334->43337 43335->43315 43336->43335 43337->43335 43338->43334 43339->43334 43340->43334 43341 212d0f0 43342 212d108 43341->43342 43343 212d162 43342->43343 43348 59ab408 43342->43348 43352 59a9c84 43342->43352 43363 59ab3f7 43342->43363 43367 59ac0b0 43342->43367 43349 59ab42e 43348->43349 43350 59a9c84 3 API calls 43349->43350 43351 59ab44f 43350->43351 43351->43343 43353 59a9c8f 43352->43353 43354 59ac141 43353->43354 43356 59ac131 43353->43356 43357 59ac13f 43354->43357 43406 59a9d9c 43354->43406 43378 5e665a4 43356->43378 43384 59ac268 43356->43384 43390 59ac258 43356->43390 43396 5e664d8 43356->43396 43401 5e664c9 43356->43401 43364 59ab42e 43363->43364 43365 59a9c84 3 API calls 43364->43365 43366 59ab44f 43365->43366 43366->43343 43370 59ac10d 43367->43370 43368 59ac141 43369 59a9d9c 3 API calls 43368->43369 43372 59ac13f 43368->43372 43369->43372 43370->43368 43371 59ac131 43370->43371 43373 59ac258 3 API calls 43371->43373 43374 59ac268 3 API calls 43371->43374 43375 5e665a4 3 API calls 43371->43375 43376 5e664d8 3 API calls 43371->43376 43377 5e664c9 3 API calls 43371->43377 43373->43372 43374->43372 43375->43372 43376->43372 43377->43372 43379 5e66562 43378->43379 43380 5e665b2 43378->43380 43413 5e66590 43379->43413 43416 5e6657f 43379->43416 43381 5e66578 43381->43357 43386 59ac276 43384->43386 43385 59a9d9c 3 API calls 43385->43386 43386->43385 43387 59ac34e 43386->43387 43431 59acb40 43386->43431 43436 59acb30 43386->43436 43387->43357 43392 59ac268 43390->43392 43391 59a9d9c 3 API calls 43391->43392 43392->43391 43393 59ac34e 43392->43393 43394 59acb30 OleGetClipboard 43392->43394 43395 59acb40 OleGetClipboard 43392->43395 43393->43357 43394->43392 43395->43392 43398 5e664ec 43396->43398 43397 5e66578 43397->43357 43399 5e66590 3 API calls 43398->43399 43400 5e6657f 3 API calls 43398->43400 43399->43397 43400->43397 43403 5e664ec 43401->43403 43402 5e66578 43402->43357 43404 5e66590 3 API calls 43403->43404 43405 5e6657f 3 API calls 43403->43405 43404->43402 43405->43402 43407 59a9da7 43406->43407 43408 59ac3aa 43407->43408 43409 59ac454 43407->43409 43410 59ac402 CallWindowProcW 43408->43410 43412 59ac3b1 43408->43412 43411 59a9c84 2 API calls 43409->43411 43410->43412 43411->43412 43412->43357 43414 5e665a1 43413->43414 43420 5e679c0 43413->43420 43414->43381 43417 5e6658a 43416->43417 43418 5e665a1 43417->43418 43419 5e679c0 3 API calls 43417->43419 43418->43381 43419->43418 43423 59a9d9c 3 API calls 43420->43423 43424 59ac358 43420->43424 43421 5e679da 43421->43414 43423->43421 43425 59ac365 43424->43425 43426 59ac3aa 43425->43426 43427 59ac454 43425->43427 43428 59ac402 CallWindowProcW 43426->43428 43430 59ac3b1 43426->43430 43429 59a9c84 2 API calls 43427->43429 43428->43430 43429->43430 43430->43421 43432 59acb5f 43431->43432 43433 59acc07 43432->43433 43441 59accf8 43432->43441 43447 59acce8 43432->43447 43433->43386 43437 59acb5f 43436->43437 43438 59acc07 43437->43438 43439 59accf8 OleGetClipboard 43437->43439 43440 59acce8 OleGetClipboard 43437->43440 43438->43386 43439->43437 43440->43437 43443 59acd00 43441->43443 43442 59acd14 43442->43432 43443->43442 43453 59acd30 43443->43453 43464 59acd40 43443->43464 43444 59acd29 43444->43432 43449 59accf8 43447->43449 43448 59acd14 43448->43432 43449->43448 43451 59acd30 OleGetClipboard 43449->43451 43452 59acd40 OleGetClipboard 43449->43452 43450 59acd29 43450->43432 43451->43450 43452->43450 43454 59acd40 43453->43454 43455 59acd6d 43454->43455 43457 59acdb1 43454->43457 43460 59acd30 OleGetClipboard 43455->43460 43461 59acd40 OleGetClipboard 43455->43461 43456 59acd73 43456->43444 43459 59ace31 43457->43459 43475 59acf18 43457->43475 43479 59acf08 43457->43479 43458 59ace4f 43458->43444 43459->43444 43460->43456 43461->43456 43465 59acd52 43464->43465 43466 59acd6d 43465->43466 43468 59acdb1 43465->43468 43471 59acd30 OleGetClipboard 43466->43471 43472 59acd40 OleGetClipboard 43466->43472 43467 59acd73 43467->43444 43470 59ace31 43468->43470 43473 59acf18 OleGetClipboard 43468->43473 43474 59acf08 OleGetClipboard 43468->43474 43469 59ace4f 43469->43444 43470->43444 43471->43467 43472->43467 43473->43469 43474->43469 43477 59acf2d 43475->43477 43478 59acf53 43477->43478 43483 59ac9ac 43477->43483 43478->43458 43480 59acf18 43479->43480 43481 59ac9ac OleGetClipboard 43480->43481 43482 59acf53 43480->43482 43481->43480 43482->43458 43484 59acfc0 OleGetClipboard 43483->43484 43486 59ad05a 43484->43486 43487 229ba6f 43490 229b82c 43487->43490 43491 229b837 43490->43491 43495 229cc3b 43491->43495 43499 229cc40 43491->43499 43492 229ba7c 43496 229cc40 43495->43496 43503 229b98c 43496->43503 43500 229cc8f 43499->43500 43501 229b98c EnumThreadWindows 43500->43501 43502 229cd10 43501->43502 43502->43492 43505 229cd30 EnumThreadWindows 43503->43505 43506 229cd10 43505->43506 43506->43492 43507 5e6a840 DispatchMessageW 43508 5e6a8ac 43507->43508 43509 229d4c0 43510 229d505 MessageBoxW 43509->43510 43512 229d54c 43510->43512 43517 229b050 DuplicateHandle 43518 229b0e6 43517->43518 43513 59ab250 43514 59ab2b8 CreateWindowExW 43513->43514 43516 59ab374 43514->43516
                          APIs
                          • SetWindowsHookExA.USER32(0000000D,00000000,?,?,?,?,?,?,?,?,?,059AEA70,00000000,00000000), ref: 059AEC83
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: HookWindows
                          • String ID: +ZR4
                          • API String ID: 2559412058-2657457958
                          • Opcode ID: 1601a9e0034c2c632ad11c9aa5b47aa289a0049ea9b90ad526d57c50e821d69e
                          • Instruction ID: 979956166daff80fffc3a1fc07beadf8f2250807345d8b3c371b72bd2abd47d6
                          • Opcode Fuzzy Hash: 1601a9e0034c2c632ad11c9aa5b47aa289a0049ea9b90ad526d57c50e821d69e
                          • Instruction Fuzzy Hash: 472115B2904209DFDB14DF99C944BEEFBF9FB88310F10842AE459A7250C775A944CFA5
                          Memory Dump Source
                          • Source File: 00000001.00000002.4146174511.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_5e60000_AddInProcess32.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 3d4e63ed513825f1335b9e7e47559b79de1aa59211ff6fd8dd1b53a5b73c72f2
                          • Instruction ID: 0216c2c41fc1aef87a3914cca53704c8daa2cbafe8385d531c235650e3130399
                          • Opcode Fuzzy Hash: 3d4e63ed513825f1335b9e7e47559b79de1aa59211ff6fd8dd1b53a5b73c72f2
                          • Instruction Fuzzy Hash: DAD15F30A40219CFEB14DFA5C848BADBBF2BF44388F159564E449EF2A6DB71E945CB40

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 0 2299d9a-2299e22 4 2299e28-2299e4d 0->4 5 229a066-229a099 0->5 10 229a0a0-229a0d5 4->10 11 2299e53-2299e78 4->11 5->10 18 229a0dc-229a111 10->18 11->18 19 2299e7e-2299e8e 11->19 24 229a118-229a144 18->24 19->24 25 2299e94-2299e98 19->25 30 229a14b-229a189 24->30 26 2299e9a-2299ea0 25->26 27 2299ea6-2299eab 25->27 26->27 26->30 31 2299eb9-2299ebf 27->31 32 2299ead-2299eb3 27->32 33 229a190-229a1ce 30->33 35 2299ec1-2299ec9 31->35 36 2299ed0-2299ee4 31->36 32->31 32->33 69 229a1d5-229a24a 33->69 35->36 47 2299eea 36->47 48 2299ee6-2299ee8 36->48 51 2299eef-2299f07 47->51 48->51 54 2299f09-2299f0f 51->54 55 2299f11-2299f15 51->55 54->55 56 2299f64-2299f71 54->56 57 2299f58-2299f61 55->57 58 2299f17-2299f43 GetActiveWindow 55->58 66 2299fb1 56->66 67 2299f73-2299f89 call 2299aa0 56->67 57->56 61 2299f4c-2299f56 58->61 62 2299f45-2299f4b 58->62 61->56 62->61 99 2299fb1 call 229a7e8 66->99 100 2299fb1 call 229a7b0 66->100 101 2299fb1 call 229a7c0 66->101 78 2299fa8-2299fae 67->78 79 2299f8b-2299fa2 67->79 95 229a24c-229a254 69->95 71 2299fb7-229a00b call 2299aac 91 229a014 71->91 78->66 79->69 79->78 91->5 95->95 96 229a256-229a273 95->96 99->71 100->71 101->71
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: ActiveWindow
                          • String ID: +ZR4$Hbq$Hbq
                          • API String ID: 2558294473-2430806922
                          • Opcode ID: c82e6933dd262bfc05acd5462a60adf450714ffb68cb0c9cd7abe42bd456bd63
                          • Instruction ID: 58d01b49d5be1d5156ded117031a0d0fc7e6a3783a777ef33a128434c9774e7c
                          • Opcode Fuzzy Hash: c82e6933dd262bfc05acd5462a60adf450714ffb68cb0c9cd7abe42bd456bd63
                          • Instruction Fuzzy Hash: 1CC19D30B102568FDB48AFB8941476E7AE7EF88310F148868D506EB398DF389D46CB51

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 102 59ab244-59ab2b6 103 59ab2b8-59ab2be 102->103 104 59ab2c1-59ab2c8 102->104 103->104 105 59ab2ca-59ab2d0 104->105 106 59ab2d3-59ab30b 104->106 105->106 107 59ab313-59ab372 CreateWindowExW 106->107 108 59ab37b-59ab3b3 107->108 109 59ab374-59ab37a 107->109 113 59ab3c0 108->113 114 59ab3b5-59ab3b8 108->114 109->108 115 59ab3c1 113->115 114->113 115->115
                          APIs
                          • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 059AB362
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: CreateWindow
                          • String ID: +ZR4$+ZR4
                          • API String ID: 716092398-2190121733
                          • Opcode ID: a5e984dcbf8a12c229312dfa7a7c3ec548e7b5c0b711b60910795d8acbdc4630
                          • Instruction ID: d7fdb74263bf61bcdbdc00b7175ebecd0790a8df2a6587758428e81c869474ad
                          • Opcode Fuzzy Hash: a5e984dcbf8a12c229312dfa7a7c3ec548e7b5c0b711b60910795d8acbdc4630
                          • Instruction Fuzzy Hash: 5751C2B1D013099FDB14CF99C884ADEBBB6FF48310F24812AE819AB250D7759885CF91

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 116 59ab250-59ab2b6 117 59ab2b8-59ab2be 116->117 118 59ab2c1-59ab2c8 116->118 117->118 119 59ab2ca-59ab2d0 118->119 120 59ab2d3-59ab372 CreateWindowExW 118->120 119->120 122 59ab37b-59ab3b3 120->122 123 59ab374-59ab37a 120->123 127 59ab3c0 122->127 128 59ab3b5-59ab3b8 122->128 123->122 129 59ab3c1 127->129 128->127 129->129
                          APIs
                          • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 059AB362
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: CreateWindow
                          • String ID: +ZR4$+ZR4
                          • API String ID: 716092398-2190121733
                          • Opcode ID: a2ff2f7dee62c0f6d6f912c5ec994ebee0a02bcec03dc39d1c4552448b7ff81f
                          • Instruction ID: 36518af5f3278990c838e68a48b306d28b51b93c66473363bd8e214d18bd1b39
                          • Opcode Fuzzy Hash: a2ff2f7dee62c0f6d6f912c5ec994ebee0a02bcec03dc39d1c4552448b7ff81f
                          • Instruction Fuzzy Hash: 3441B3B1D11349DFDB14CF99C884ADEBBB5FF48310F24812AE819AB250D7719845CF91

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 775 59aa7f0-59aa816 778 59aa818-59aa840 call 59a9bac 775->778 779 59aa846-59aa84e 775->779 778->779 789 59aaa4c-59aaa72 778->789 780 59aa850-59aa855 call 59a9bb8 779->780 781 59aa894-59aa8ce call 59a9bc4 779->781 786 59aa85a-59aa88f 780->786 799 59aaa79-59aaaab 781->799 800 59aa8d4-59aa91f 781->800 795 59aa922-59aa97b call 59a9bd0 786->795 789->799 821 59aa980-59aa984 795->821 814 59aaab2-59aab60 799->814 800->795 826 59aab68-59aab93 GetModuleHandleW 814->826 827 59aab62-59aab65 814->827 823 59aa98a-59aa997 821->823 824 59aaa40-59aaa4b 821->824 831 59aaa3c-59aaa3e 823->831 832 59aa99d-59aa9ca call 59a9bc4 823->832 829 59aab9c-59aabb0 826->829 830 59aab95-59aab9b 826->830 827->826 830->829 831->814 831->824 832->831 839 59aa9cc-59aa9d9 832->839 839->831 840 59aa9db-59aa9f2 call 59a9bdc 839->840 844 59aa9ff-59aaa2e call 59a9bd0 840->844 845 59aa9f4-59aa9fd call 59a9bd0 840->845 844->831 853 59aaa30-59aaa3a 844->853 845->831 853->831 853->844
                          APIs
                          • GetModuleHandleW.KERNELBASE(00000000), ref: 059AAB86
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: HandleModule
                          • String ID: +ZR4
                          • API String ID: 4139908857-2657457958
                          • Opcode ID: b7de821919c417205f71e5030fcaf6615a4b130f7b91cc413c427d017c96343b
                          • Instruction ID: 4688c210c4a79c21e180a90d709eb6cc965995f929b42cc5ab52079b5bbb472e
                          • Opcode Fuzzy Hash: b7de821919c417205f71e5030fcaf6615a4b130f7b91cc413c427d017c96343b
                          • Instruction Fuzzy Hash: 6EB17871A007059FCB14EF69C884A6EBBF6FF88310B00896AD44ADB755DB74E945CBA0

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 855 59a4b98-59a4ba3 856 59a4bcd-59a4bec call 59a3f7c 855->856 857 59a4ba5-59a4bcc call 59a3f70 855->857 863 59a4bee-59a4bf1 856->863 864 59a4bf2-59a4c51 856->864 871 59a4c53-59a4c56 864->871 872 59a4c57-59a4ce4 GlobalMemoryStatusEx 864->872 875 59a4ced-59a4d15 872->875 876 59a4ce6-59a4cec 872->876 876->875
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID:
                          • String ID: +ZR4
                          • API String ID: 0-2657457958
                          • Opcode ID: 8eff1c0a15593b6ec9b74218c12015180cf03d8ce324da924e3f2658d163eae0
                          • Instruction ID: 827b6f756499bcdc1f186bf708c32d978023df8fcd1bdc77d37dc1678001a33b
                          • Opcode Fuzzy Hash: 8eff1c0a15593b6ec9b74218c12015180cf03d8ce324da924e3f2658d163eae0
                          • Instruction Fuzzy Hash: 3D413272E043598FCB04CFB9D8447AEBBF4AF89210F14856AD408E7281DB74A884CBE0

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 879 59a9d9c-59ac3a4 882 59ac3aa-59ac3af 879->882 883 59ac454-59ac474 call 59a9c84 879->883 884 59ac402-59ac43a CallWindowProcW 882->884 885 59ac3b1-59ac3e8 882->885 891 59ac477-59ac484 883->891 887 59ac43c-59ac442 884->887 888 59ac443-59ac452 884->888 892 59ac3ea-59ac3f0 885->892 893 59ac3f1-59ac400 885->893 887->888 888->891 892->893 893->891
                          APIs
                          • CallWindowProcW.USER32(?,?,?,?,?), ref: 059AC429
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: CallProcWindow
                          • String ID: +ZR4
                          • API String ID: 2714655100-2657457958
                          • Opcode ID: 2c050d6fa6018f981b07a614ddfb55fe92ec6615e1ade2d108ddc91eccb15ff6
                          • Instruction ID: 81b7e88d4f1dfaa305f0e2a3e854db65275af613c3fdf09fc05a9387cc9f020e
                          • Opcode Fuzzy Hash: 2c050d6fa6018f981b07a614ddfb55fe92ec6615e1ade2d108ddc91eccb15ff6
                          • Instruction Fuzzy Hash: 83413DB5A00305CFDB14CF59C488AAABBF5FF88314F14C859E519AB321D774A845CFA0

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 896 59ac9ac-59ad058 OleGetClipboard 899 59ad05a-59ad060 896->899 900 59ad061-59ad0af 896->900 899->900 905 59ad0bf 900->905 906 59ad0b1-59ad0b5 900->906 908 59ad0c0 905->908 906->905 907 59ad0b7 906->907 907->905 908->908
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: Clipboard
                          • String ID: +ZR4
                          • API String ID: 220874293-2657457958
                          • Opcode ID: 3ebb0fcefdea12b81bbe36e4a359fd8fd8862ae169e72492425a41ef3ca60a56
                          • Instruction ID: e7233e435b74a716d100bcd0a5078201f89d0e967dbbdbcd4a42f8e32afc8fd4
                          • Opcode Fuzzy Hash: 3ebb0fcefdea12b81bbe36e4a359fd8fd8862ae169e72492425a41ef3ca60a56
                          • Instruction Fuzzy Hash: A73122B1D05318DFDB10DFA9C984B8EBBF5AF48304F208019E405BB294D7B5A985CBA5

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 909 59acfb4-59ad010 911 59ad01a-59ad058 OleGetClipboard 909->911 912 59ad05a-59ad060 911->912 913 59ad061-59ad0af 911->913 912->913 918 59ad0bf 913->918 919 59ad0b1-59ad0b5 913->919 921 59ad0c0 918->921 919->918 920 59ad0b7 919->920 920->918 921->921
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: Clipboard
                          • String ID: +ZR4
                          • API String ID: 220874293-2657457958
                          • Opcode ID: aa21aa8f0c6f0a3647569ace651387bf36be4449e601ba3d8ade03ed03937717
                          • Instruction ID: e2805301d7c748916418715a0ef23533d93cbf28797de727bb61fb24365764b8
                          • Opcode Fuzzy Hash: aa21aa8f0c6f0a3647569ace651387bf36be4449e601ba3d8ade03ed03937717
                          • Instruction Fuzzy Hash: 243101B1901318DFDB10DFA9C985BCDBBF5BF48314F608019E404AB294D7B56986CBA1
                          APIs
                          • EnumThreadWindows.USER32(?,00000000,?,?,?,?,00000E20,?,?,0229CD10,034260D8,02446194), ref: 0229CDA1
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: EnumThreadWindows
                          • String ID: +ZR4
                          • API String ID: 2941952884-2657457958
                          • Opcode ID: 9caf184222b43123ea9baabf038ebe053e7a9c2e36455234f56efce46b5b3f65
                          • Instruction ID: 54f127900f969601c0f5de7d3b88cda136f99e462cf2cd23e2c47c3c9b9f7b2f
                          • Opcode Fuzzy Hash: 9caf184222b43123ea9baabf038ebe053e7a9c2e36455234f56efce46b5b3f65
                          • Instruction Fuzzy Hash: D62159B1D102498FDB10CFAAC845BEEFBF4EB88324F04842AE454A7251C774A945CFA5
                          APIs
                          • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 0229B0D7
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: DuplicateHandle
                          • String ID: +ZR4
                          • API String ID: 3793708945-2657457958
                          • Opcode ID: ba175ebcb4871160a1d89ea32947614632c08d3d5d664b00a9ce7745dbce2289
                          • Instruction ID: 05e83c94b600ddbfa61244a4af0bfdb170beb0d13b9ad1262ed4f7e066a40509
                          • Opcode Fuzzy Hash: ba175ebcb4871160a1d89ea32947614632c08d3d5d664b00a9ce7745dbce2289
                          • Instruction Fuzzy Hash: 8921E3B59012499FDB10CFAAD584ADEBBF4FB48314F14801AE958A7250D375A941CFA1
                          APIs
                          • EnumThreadWindows.USER32(?,00000000,?,?,?,?,00000E20,?,?,0229CD10,034260D8,02446194), ref: 0229CDA1
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: EnumThreadWindows
                          • String ID: +ZR4
                          • API String ID: 2941952884-2657457958
                          • Opcode ID: b7dfe1478ddfaf421b203fa5c6f0e4fc9830f55caec234611ef5e780863c6678
                          • Instruction ID: dec4cb1bf842f88ee90df1351b286c3cd72922cf1b80b56f131ef9b43c469896
                          • Opcode Fuzzy Hash: b7dfe1478ddfaf421b203fa5c6f0e4fc9830f55caec234611ef5e780863c6678
                          • Instruction Fuzzy Hash: 1D215BB1D002098FDB10CFAAC845BEEFBF5EF88310F10842AD458A7250D778A945CFA1
                          APIs
                          • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 0229B0D7
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: DuplicateHandle
                          • String ID: +ZR4
                          • API String ID: 3793708945-2657457958
                          • Opcode ID: da1c8f42b163452dc372cd857fb259390464b0c831bdfc864bbdb4df2533606b
                          • Instruction ID: 23f41f068deb9b2a0baafb4b9429eef5bc09571d4a7b49457539b4c062044d45
                          • Opcode Fuzzy Hash: da1c8f42b163452dc372cd857fb259390464b0c831bdfc864bbdb4df2533606b
                          • Instruction Fuzzy Hash: 1621E4B59002089FDB10CFAAD584ADEFBF4FB48314F14801AE914A3350C375A940CFA5
                          APIs
                          • EnumThreadWindows.USER32(?,00000000,?,?,?,?,00000E20,?,?,0229CD10,034260D8,02446194), ref: 0229CDA1
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: EnumThreadWindows
                          • String ID: +ZR4
                          • API String ID: 2941952884-2657457958
                          • Opcode ID: ada1e66ae4c683d66075c7246c2c40d34f471827d50697ce5ce918bf99c0fd01
                          • Instruction ID: 0c96298062767d77e6e798203ae80568464c721d81c6c1e73d57b191df4bfd8c
                          • Opcode Fuzzy Hash: ada1e66ae4c683d66075c7246c2c40d34f471827d50697ce5ce918bf99c0fd01
                          • Instruction Fuzzy Hash: AE2158B1D102198FDB10DF9AC844BEEFBF4EB88324F10842AE458A7350D774A944CFA5
                          APIs
                          • MessageBoxW.USER32(?,00000000,00000000,?), ref: 0229D53D
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: Message
                          • String ID: +ZR4
                          • API String ID: 2030045667-2657457958
                          • Opcode ID: 3c9a731e7f998b4a7600b908da31a3dab60f46425505c0e849312c2fb9dfefff
                          • Instruction ID: 7967a7f415818fb0d383d2f817bb43c566e0bdabb3ee96b8827d478e45863126
                          • Opcode Fuzzy Hash: 3c9a731e7f998b4a7600b908da31a3dab60f46425505c0e849312c2fb9dfefff
                          • Instruction Fuzzy Hash: 162104B59013499FDB10DF9AD884ADEFBF5FB48314F14852ED419A7200C375A545CFA1
                          APIs
                          • SetWindowsHookExA.USER32(0000000D,00000000,?,?,?,?,?,?,?,?,?,059AEA70,00000000,00000000), ref: 059AEC83
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: HookWindows
                          • String ID: +ZR4
                          • API String ID: 2559412058-2657457958
                          • Opcode ID: e736a85f078f909533f593c93b24df8c2ad8cc94f35b0cf0f9560303ec44b687
                          • Instruction ID: c394d4c51a8741fab0b4b129222b4bc380f3d7bf792b246e048ba96c95904e96
                          • Opcode Fuzzy Hash: e736a85f078f909533f593c93b24df8c2ad8cc94f35b0cf0f9560303ec44b687
                          • Instruction Fuzzy Hash: 502147B2D002099FCB14DF99C844BDEFBF9FB88320F10842AD419A7250C774A940CFA5
                          APIs
                          • MessageBoxW.USER32(?,00000000,00000000,?), ref: 0229D53D
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: Message
                          • String ID: +ZR4
                          • API String ID: 2030045667-2657457958
                          • Opcode ID: fa8fff0409f03f9fd6dc821245d4b3522ae222c9ae42ecddd22332de10415251
                          • Instruction ID: 42cfe6dcb89c8efa60118949da05a85e9ad8dc041f08e84bc66741966c858aa1
                          • Opcode Fuzzy Hash: fa8fff0409f03f9fd6dc821245d4b3522ae222c9ae42ecddd22332de10415251
                          • Instruction Fuzzy Hash: D821EFB69013499FCB10DF9AD884ADEFBB5FB48318F10852AE919A7200C375A944CFA5
                          APIs
                          • GlobalMemoryStatusEx.KERNELBASE(?,?,?,?,?,?,?,?,?,059A4BEA), ref: 059A4CD7
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: GlobalMemoryStatus
                          • String ID: +ZR4
                          • API String ID: 1890195054-2657457958
                          • Opcode ID: cb13c16ad6f57539ea5350b7809d09a4258d1009569e53058dff23c7fbc26bdb
                          • Instruction ID: da704acd6260b084b5a640d70d1136c627be92a4e11bcbdadbdbdec396ac04e6
                          • Opcode Fuzzy Hash: cb13c16ad6f57539ea5350b7809d09a4258d1009569e53058dff23c7fbc26bdb
                          • Instruction Fuzzy Hash: BB1144B2C006599BDB10DF9AC544BDEFBF4FB08320F10812AD818A7240D378A940CFE5
                          APIs
                          • GetModuleHandleW.KERNELBASE(00000000), ref: 059AAB86
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: HandleModule
                          • String ID: +ZR4
                          • API String ID: 4139908857-2657457958
                          • Opcode ID: 4b8fac61b9e2e1110fd986385a47adf6957bf0720d9cd60b33bd8cc11b82c107
                          • Instruction ID: 4ca6dd21db26eeb874b1015032a0272eb6394f77b7a52390e20ea79bd0aea56b
                          • Opcode Fuzzy Hash: 4b8fac61b9e2e1110fd986385a47adf6957bf0720d9cd60b33bd8cc11b82c107
                          • Instruction Fuzzy Hash: DA110FB6C003498FDB10DF9AD484ADEFBF9AB89320F10842AD429A7210C375A545CFA5
                          APIs
                          • OleInitialize.OLE32(00000000), ref: 0229BED5
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: Initialize
                          • String ID: +ZR4
                          • API String ID: 2538663250-2657457958
                          • Opcode ID: 03f1c7c14645bc75a2d322df3642849ef1c8fae37ecc05730f6cfdcee88c8fb1
                          • Instruction ID: 3980715e0319d78a212513239a880526f38f0944c6afda52cc836b4e04ffe9ee
                          • Opcode Fuzzy Hash: 03f1c7c14645bc75a2d322df3642849ef1c8fae37ecc05730f6cfdcee88c8fb1
                          • Instruction Fuzzy Hash: 131145B4D002498FDB20DFAAD485BDEFFF8EB48324F10842AD558A3210C378A584CFA5
                          APIs
                          • KiUserCallbackDispatcher.NTDLL(?,?,?,?,?,059AC675), ref: 059AC6FF
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: CallbackDispatcherUser
                          • String ID: +ZR4
                          • API String ID: 2492992576-2657457958
                          • Opcode ID: f92fb2118dad14c5fb57716526780bfbfee53e87a6caf0099ab51e58414bd780
                          • Instruction ID: 5ef78a6f23559509ec7973dff98571504281d80a1c80e0861005e9198eb6ccb3
                          • Opcode Fuzzy Hash: f92fb2118dad14c5fb57716526780bfbfee53e87a6caf0099ab51e58414bd780
                          • Instruction Fuzzy Hash: 2F1145B5800248CFCB10DF9AD489BDEFFF8EB48324F20841AE559A7250C374A944CFA5
                          APIs
                          • KiUserCallbackDispatcher.NTDLL(?,?,?,?,?,059AC675), ref: 059AC6FF
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: CallbackDispatcherUser
                          • String ID: +ZR4
                          • API String ID: 2492992576-2657457958
                          • Opcode ID: 1c952c5572bb53937d66e2dfcf76dfaa70f4577fe96e645c65509b56914f5882
                          • Instruction ID: f2780d78f58b8ff5599d0635978d05e49de0b6c679af6ee772752e320c1ac9d5
                          • Opcode Fuzzy Hash: 1c952c5572bb53937d66e2dfcf76dfaa70f4577fe96e645c65509b56914f5882
                          • Instruction Fuzzy Hash: 6C1115B5800349CFCB10DF9AD485BDEFBF8EB48324F20845AE559A7250D375A944CFA5
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4146174511.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_5e60000_AddInProcess32.jbxd
                          Similarity
                          • API ID: DispatchMessage
                          • String ID: +ZR4
                          • API String ID: 2061451462-2657457958
                          • Opcode ID: 937823e9151838a51544d97bf458e96bffcfc481f48515e36d7c48e558db086d
                          • Instruction ID: e23af6d7dbac6adfb2c04af279fddac7de4a2188084c42eaec63a953475305ab
                          • Opcode Fuzzy Hash: 937823e9151838a51544d97bf458e96bffcfc481f48515e36d7c48e558db086d
                          • Instruction Fuzzy Hash: AE11E0B1C006488FCB10DF9AD445B8EFBF4EB48314F10846AD559A7250D374A545CFA5
                          APIs
                          • OleInitialize.OLE32(00000000), ref: 0229BED5
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: Initialize
                          • String ID: +ZR4
                          • API String ID: 2538663250-2657457958
                          • Opcode ID: e3e935d8268e186b727703a8ee5fddaff03f31e6c5dbf0394900fc6ec75210be
                          • Instruction ID: 9b49f484ebc86f41de4e64e73563823bc8b52029200ad820e9aeca7a34946de5
                          • Opcode Fuzzy Hash: e3e935d8268e186b727703a8ee5fddaff03f31e6c5dbf0394900fc6ec75210be
                          • Instruction Fuzzy Hash: F11145B49003488FCB20DF9AD484BDEFBF8EB48328F108459D659A7210C374A944CFA5
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4146174511.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_5e60000_AddInProcess32.jbxd
                          Similarity
                          • API ID: DispatchMessage
                          • String ID: +ZR4
                          • API String ID: 2061451462-2657457958
                          • Opcode ID: dcc2c396bc0b46877f848af14902cdd6a538b8f1da7ab762ac6c03486859f648
                          • Instruction ID: 464c61988003cba000ed1ad0f7d4475547e6d20832276e6cdf4d17acecc92ac5
                          • Opcode Fuzzy Hash: dcc2c396bc0b46877f848af14902cdd6a538b8f1da7ab762ac6c03486859f648
                          • Instruction Fuzzy Hash: DE11FBB1C00648CFCB20DF9AD488ACEFBF4EB48324F10846AE859A3250D378A544CFA5
                          APIs
                          • KiUserCallbackDispatcher.NTDLL(?,?,?,?,?,059AC675), ref: 059AC6FF
                          Memory Dump Source
                          • Source File: 00000001.00000002.4145817742.00000000059A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059A0000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_59a0000_AddInProcess32.jbxd
                          Similarity
                          • API ID: CallbackDispatcherUser
                          • String ID:
                          • API String ID: 2492992576-0
                          • Opcode ID: 66c8d96fb4b02551bc0c434e6c62d29b30dd7a7bc4ac3182ecf7732af8b56547
                          • Instruction ID: 913f7cab5f35eae82fab447fa096fd8d2d494807a25f5c49a02ff5c522239bad
                          • Opcode Fuzzy Hash: 66c8d96fb4b02551bc0c434e6c62d29b30dd7a7bc4ac3182ecf7732af8b56547
                          • Instruction Fuzzy Hash: 23F0F0B3808380CEDB11CB99C4593DABFF0EB51308F18808AD19A9B261D3799545CBA1
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138734746.000000000212D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0212D000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_212d000_AddInProcess32.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: b8b68eddb014ad2dd53881db10ef905826873e577561d2075639075a2254e373
                          • Instruction ID: 96852a32a390875daa27e44a18445c369619d0a8532ea00433fed8f6a71ce5e9
                          • Opcode Fuzzy Hash: b8b68eddb014ad2dd53881db10ef905826873e577561d2075639075a2254e373
                          • Instruction Fuzzy Hash: 6C212671684224DFDB04DF24E9C0B26BBA5FB88314F20C56DF8494B796C336D46ACB61
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138734746.000000000212D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0212D000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_212d000_AddInProcess32.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: c052e80f6bfbb93ac6b74779f94ec173d0d72e7d8ef0a4d362dd661037828e93
                          • Instruction ID: 37e3ef4a6bc2b3b34e2892dc2493e448a4571658e15e1c5f88e8909e9c48dc84
                          • Opcode Fuzzy Hash: c052e80f6bfbb93ac6b74779f94ec173d0d72e7d8ef0a4d362dd661037828e93
                          • Instruction Fuzzy Hash: 922105B1584244DFDB04DF14FAC4B2BBBA5FB88324F24C569F8494B355C33AD46ACAA1
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138734746.000000000212D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0212D000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_212d000_AddInProcess32.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: f3c1fad6e570cfa6accb7d23ac755312d717cd760a43db51bdf4ff7b1f997570
                          • Instruction ID: eda8b4c7e3df113ce9f4a72b17cd5ec4ce6a9f0bf6f62a425d35a0f76d5bbbff
                          • Opcode Fuzzy Hash: f3c1fad6e570cfa6accb7d23ac755312d717cd760a43db51bdf4ff7b1f997570
                          • Instruction Fuzzy Hash: 9A212971584240EFDB08DF24E5C4B16BBB5FB84318F24C56DF8094B256C37AD45ACB61
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138734746.000000000212D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0212D000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_212d000_AddInProcess32.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 72d23902bf60047e6ac5528eaef86f122a9a091f4bdaa5726a35430d0a81cb07
                          • Instruction ID: 43c9c5350c250734b87d530a2feefba3b610a5c2eeee19605f838f91b80051a2
                          • Opcode Fuzzy Hash: 72d23902bf60047e6ac5528eaef86f122a9a091f4bdaa5726a35430d0a81cb07
                          • Instruction Fuzzy Hash: B311C8B5544244CFDB11CF14E5C4B1AFF71FB84314F24C5AAD8494B656C33AD41ACB91
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138734746.000000000212D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0212D000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_212d000_AddInProcess32.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 48042a67946fd5b471a152cae87ddc5a96e5ad52caa5f07da488830fbc7c129d
                          • Instruction ID: 849e0d805daeffb35edd65e676488a7f6e7f2156ef34251ef9588d291f7ec9c4
                          • Opcode Fuzzy Hash: 48042a67946fd5b471a152cae87ddc5a96e5ad52caa5f07da488830fbc7c129d
                          • Instruction Fuzzy Hash: 3C11DD76544280CFCB01CF20E5C4B15BFB1FB84318F28C6AEE8094B296C37AD41ACB62
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138734746.000000000212D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0212D000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_212d000_AddInProcess32.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 48042a67946fd5b471a152cae87ddc5a96e5ad52caa5f07da488830fbc7c129d
                          • Instruction ID: a58197afdbdd8718c2df98eda95f41fdc0388c078ddf1410f8af50b7d119bd3e
                          • Opcode Fuzzy Hash: 48042a67946fd5b471a152cae87ddc5a96e5ad52caa5f07da488830fbc7c129d
                          • Instruction Fuzzy Hash: A311DD75544280CFDB01CF10E9C4B15FFB2FB88318F24C6AAE8494B656C33AD45ACB62
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4138979821.0000000002290000.00000040.00000800.00020000.00000000.sdmp, Offset: 02290000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_2290000_AddInProcess32.jbxd
                          Similarity
                          • API ID: ActiveFocusWindow
                          • String ID: +ZR4
                          • API String ID: 2022189218-2657457958
                          • Opcode ID: f96cb81a148b907827b428f0321f39ffd208bab670c71ed96565fe61a2973f2e
                          • Instruction ID: e3471c9171be87eb707ea1e2b15dcd74c7e04a76ba97f87ca1fb2b872022628d
                          • Opcode Fuzzy Hash: f96cb81a148b907827b428f0321f39ffd208bab670c71ed96565fe61a2973f2e
                          • Instruction Fuzzy Hash: 4B7159B4A1020A8FDB14EFA9C584AAEBBF5EF49304F1584A9E804EB355C734ED41CF61
                          APIs
                          • GetSystemMetrics.USER32(00000050), ref: 05E6C0E3
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4146174511.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_5e60000_AddInProcess32.jbxd
                          Similarity
                          • API ID: MetricsSystem
                          • String ID: +ZR4$4'^q
                          • API String ID: 4116985748-2094718428
                          • Opcode ID: 4b20a0a13a95e53233f321a8ed5fa2c2d680d088a50e86577397403e269ef4a6
                          • Instruction ID: fd4aec20f0d6bad744932fc4d8e8be61df933df8fca05e9d7adf1461b5cda4b4
                          • Opcode Fuzzy Hash: 4b20a0a13a95e53233f321a8ed5fa2c2d680d088a50e86577397403e269ef4a6
                          • Instruction Fuzzy Hash: D52134B1D002098FDB00DFA9D8466EEBBF4EB08324F10895AD859B7381C779A945CFA5
                          APIs
                          • GetSystemMetrics.USER32(00000050), ref: 05E6C0E3
                          Strings
                          Memory Dump Source
                          • Source File: 00000001.00000002.4146174511.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_1_2_5e60000_AddInProcess32.jbxd
                          Similarity
                          • API ID: MetricsSystem
                          • String ID: +ZR4$4'^q
                          • API String ID: 4116985748-2094718428
                          • Opcode ID: 31b2a62b44fd439f7198dc2d87b40b12aefc555f19ec649e140d530516e1bd74
                          • Instruction ID: aa4307457d28bff7f1ca294933ab406e13bcab1b78433036ae13e010636fb4df
                          • Opcode Fuzzy Hash: 31b2a62b44fd439f7198dc2d87b40b12aefc555f19ec649e140d530516e1bd74
                          • Instruction Fuzzy Hash: 022123B0D00209CFCB10DFA9D8456EEBBF4EB08324F10855AD869B7280C7796944CFA5