Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
QUOTATION_SEPQTRA071244#U00faPDF.scr.exe

Overview

General Information

Sample name:QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
renamed because original name is a hash value
Original sample name:QUOTATION_SEPQTRA071244PDF.scr.exe
Analysis ID:1519261
MD5:631691dca7abc573a0cc911b2ddca40e
SHA1:0ddc497bb233cda946e320378cde5e5cc507eb72
SHA256:922ff7b2589cfa1d6a8dcd706bc294be4d4cb4d9baf02df5717d121097ab1859
Tags:exescruser-abuse_ch
Infos:

Detection

Snake Keylogger
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Snake Keylogger
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
AI detected suspicious sample
Creates a thread in another existing process (thread injection)
Initial sample is a PE file and has a suspicious name
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file does not import any functions
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: AspNetCompiler Execution
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • QUOTATION_SEPQTRA071244#U00faPDF.scr.exe (PID: 6044 cmdline: "C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe" MD5: 631691DCA7ABC573A0CC911B2DDCA40E)
    • aspnet_compiler.exe (PID: 5792 cmdline: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe" MD5: DF5419B32657D2896514B6A1D041FE08)
      • conhost.exe (PID: 3700 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
404 Keylogger, Snake KeyloggerSnake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
{"Exfil Mode": "SMTP", "Username": "rep3send@aoqiinflatables.com", "Password": "Zg^!Zy[?IKrs99@soltan", "Host": "gator3220.hostgator.com", "Port": "587", "Version": "5.1"}
SourceRuleDescriptionAuthorStrings
00000000.00000002.2646867703.0000028ACEA50000.00000004.00000800.00020000.00000000.sdmpWindows_Trojan_Donutloader_f40e3759unknownunknown
  • 0x1cb0:$x64: 06 B8 03 40 00 80 C3 4C 8B 49 10 49
  • 0x51e6:$x86: 04 75 EE 89 31 F0 FF 46 04 33 C0 EB
00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
      00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmpWindows_Trojan_SnakeKeylogger_af3faa65unknownunknown
      • 0x14522:$a1: get_encryptedPassword
      • 0x1480e:$a2: get_encryptedUsername
      • 0x1432e:$a3: get_timePasswordChanged
      • 0x14429:$a4: get_passwordField
      • 0x14538:$a5: set_encryptedPassword
      • 0x15b1c:$a7: get_logins
      • 0x15a7f:$a10: KeyLoggerEventArgs
      • 0x15718:$a11: KeyLoggerEventArgsEventHandler
      00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmpMAL_Envrial_Jan18_1Detects Encrial credential stealer malwareFlorian Roth
      • 0x1be25:$a2: \Comodo\Dragon\User Data\Default\Login Data
      • 0x1b057:$a3: \Google\Chrome\User Data\Default\Login Data
      • 0x1b48a:$a4: \Orbitum\User Data\Default\Login Data
      • 0x1c4c9:$a5: \Kometa\User Data\Default\Login Data
      Click to see the 18 entries
      SourceRuleDescriptionAuthorStrings
      0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ae6e50000.11.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
        5.2.aspnet_compiler.exe.22934340000.0.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          5.2.aspnet_compiler.exe.22934340000.0.unpackJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
            5.2.aspnet_compiler.exe.22934340000.0.unpackWindows_Trojan_SnakeKeylogger_af3faa65unknownunknown
            • 0x12722:$a1: get_encryptedPassword
            • 0x12a0e:$a2: get_encryptedUsername
            • 0x1252e:$a3: get_timePasswordChanged
            • 0x12629:$a4: get_passwordField
            • 0x12738:$a5: set_encryptedPassword
            • 0x13d1c:$a7: get_logins
            • 0x13c7f:$a10: KeyLoggerEventArgs
            • 0x13918:$a11: KeyLoggerEventArgsEventHandler
            5.2.aspnet_compiler.exe.22934340000.0.unpackMAL_Envrial_Jan18_1Detects Encrial credential stealer malwareFlorian Roth
            • 0x1a025:$a2: \Comodo\Dragon\User Data\Default\Login Data
            • 0x19257:$a3: \Google\Chrome\User Data\Default\Login Data
            • 0x1968a:$a4: \Orbitum\User Data\Default\Login Data
            • 0x1a6c9:$a5: \Kometa\User Data\Default\Login Data
            Click to see the 22 entries

            System Summary

            barindex
            Source: Process startedAuthor: frack113: Data: Command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe", CommandLine: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe", CommandLine|base64offset|contains: , Image: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe, NewProcessName: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe, OriginalFileName: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe, ParentCommandLine: "C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe", ParentImage: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, ParentProcessId: 6044, ParentProcessName: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, ProcessCommandLine: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe", ProcessId: 5792, ProcessName: aspnet_compiler.exe
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-26T09:23:21.173991+020020226401A Network Trojan was detected188.114.97.3443192.168.2.649713TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-26T09:23:21.173991+020020179621A Network Trojan was detected188.114.97.3443192.168.2.649713TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-26T09:24:09.511667+020028033053Unknown Traffic192.168.2.649723188.114.96.3443TCP
            2024-09-26T09:24:12.846196+020028033053Unknown Traffic192.168.2.649730188.114.96.3443TCP
            2024-09-26T09:24:14.010726+020028033053Unknown Traffic192.168.2.649732188.114.96.3443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-26T09:24:08.120101+020028032742Potentially Bad Traffic192.168.2.649721193.122.130.080TCP
            2024-09-26T09:24:08.916988+020028032742Potentially Bad Traffic192.168.2.649721193.122.130.080TCP
            2024-09-26T09:24:10.088998+020028032742Potentially Bad Traffic192.168.2.649724193.122.130.080TCP
            2024-09-26T09:24:11.182593+020028032742Potentially Bad Traffic192.168.2.649727193.122.130.080TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 00000005.00000002.3402009366.0000022935D11000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Snake Keylogger {"Exfil Mode": "SMTP", "Username": "rep3send@aoqiinflatables.com", "Password": "Zg^!Zy[?IKrs99@soltan", "Host": "gator3220.hostgator.com", "Port": "587", "Version": "5.1"}
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeReversingLabs: Detection: 28%
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeJoe Sandbox ML: detected

            Location Tracking

            barindex
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49722 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.6:49711 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.6:49713 version: TLS 1.2
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE985000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE4A2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2666267100.0000028AE7130000.00000004.08000000.00040000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE51A000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE985000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE4A2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2666267100.0000028AE7130000.00000004.08000000.00040000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE51A000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: protobuf-net.pdbSHA256}Lq source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmp
            Source: Binary string: protobuf-net.pdb source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmp
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD34859C0Bh5_2_00007FFD348599AC
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD3485874Bh5_2_00007FFD348584EC
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD3485A225h5_2_00007FFD3485A141
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD34858C7Bh5_2_00007FFD34858A1C
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD34857060h5_2_00007FFD34856E1F
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD348596DBh5_2_00007FFD34858946
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD3485A225h5_2_00007FFD34858946
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD3485742Dh5_2_00007FFD3485720A
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 4x nop then jmp 00007FFD34857EEBh5_2_00007FFD3485720A

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2017962 - Severity 1 - ET MALWARE PE EXE or DLL Windows file download disguised as ASCII : 188.114.97.3:443 -> 192.168.2.6:49713
            Source: Network trafficSuricata IDS: 2022640 - Severity 1 - ET MALWARE PE EXE or DLL Windows file download Text M2 : 188.114.97.3:443 -> 192.168.2.6:49713
            Source: global trafficHTTP traffic detected: GET /data-package/Ky4pZ0WB/download HTTP/1.1Host: filetransfer.ioConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /storage/download/klH4VFXHnzlT HTTP/1.1Host: s24.filetransfer.ioConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /data-package/Ky4pZ0WB/download HTTP/1.1Host: filetransfer.ioConnection: Keep-Alive
            Source: Joe Sandbox ViewIP Address: 188.114.97.3 188.114.97.3
            Source: Joe Sandbox ViewIP Address: 188.114.97.3 188.114.97.3
            Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
            Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
            Source: Joe Sandbox ViewASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
            Source: Joe Sandbox ViewASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
            Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
            Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
            Source: unknownDNS query: name: checkip.dyndns.org
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49721 -> 193.122.130.0:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49724 -> 193.122.130.0:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49727 -> 193.122.130.0:80
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:49730 -> 188.114.96.3:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:49723 -> 188.114.96.3:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:49732 -> 188.114.96.3:443
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49722 version: TLS 1.0
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /data-package/Ky4pZ0WB/download HTTP/1.1Host: filetransfer.ioConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /storage/download/klH4VFXHnzlT HTTP/1.1Host: s24.filetransfer.ioConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.33 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /data-package/Ky4pZ0WB/download HTTP/1.1Host: filetransfer.ioConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficDNS traffic detected: DNS query: filetransfer.io
            Source: global trafficDNS traffic detected: DNS query: s24.filetransfer.io
            Source: global trafficDNS traffic detected: DNS query: checkip.dyndns.org
            Source: global trafficDNS traffic detected: DNS query: reallyfreegeoip.org
            Source: aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E1D000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EBD000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EE8000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F30000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F42000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EFB000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935ED5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.com
            Source: aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935ED5000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E6B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org
            Source: aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935D11000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/
            Source: aspnet_compiler.exe, 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/q
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE451000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://filetransfer.io
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeString found in binary or memory: http://filetransfer.io/data-package/Ky4pZ0WB/download
            Source: aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EBD000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EE8000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E3C000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F30000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F42000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EFB000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935ED5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://reallyfreegeoip.org
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE451000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935D11000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE490000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://filetransfer.io
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE490000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://filetransfer.io/data-package/Ky4pZ0WB/download
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-net
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-netJ
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-neti
            Source: aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E1D000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EBD000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EE8000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F30000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F42000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EFB000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935ED5000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E6B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org
            Source: aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E1D000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/
            Source: aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E6B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.33
            Source: aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E1D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.33p
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE4C3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://s24.filetransfer.io
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE4C3000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE4BF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://s24.filetransfer.io/storage/download/klH4VFXHnzlT
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/11564914/23354;
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE51D000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/14436606/23354
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/2152978/23354
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
            Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
            Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
            Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
            Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.6:49711 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.6:49713 version: TLS 1.2

            System Summary

            barindex
            Source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000000.00000002.2646867703.0000028ACEA50000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown
            Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown
            Source: 00000000.00000002.2653955478.0000028ADE5A0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown
            Source: Process Memory Space: aspnet_compiler.exe PID: 5792, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: Process Memory Space: aspnet_compiler.exe PID: 5792, type: MEMORYSTRMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: initial sampleStatic PE information: Filename: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD34795DDF0_2_00007FFD34795DDF
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD349515400_2_00007FFD34951540
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD349504CA0_2_00007FFD349504CA
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD34958F080_2_00007FFD34958F08
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD349548290_2_00007FFD34954829
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD349504F80_2_00007FFD349504F8
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD349605D40_2_00007FFD349605D4
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD349604150_2_00007FFD34960415
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 5_2_0000022934032F785_2_0000022934032F78
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 5_2_0000022934032B9C5_2_0000022934032B9C
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 5_2_00000229340366545_2_0000022934036654
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 5_2_0000022934033E5C5_2_0000022934033E5C
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 5_2_00000229340333A85_2_00000229340333A8
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 5_2_0000022934031CC05_2_0000022934031CC0
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeStatic PE information: No import functions for PE file found
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000000.2141478030.0000028ACC719000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameUkyqbcntzq.exe: vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE985000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE4A2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIlvse.dll" vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2666267100.0000028AE7130000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2664755190.0000028AE6D50000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameIlvse.dll" vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE51A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE841000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIlvse.dll" vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeBinary or memory string: OriginalFilenameUkyqbcntzq.exe: vs QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
            Source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000000.00000002.2646867703.0000028ACEA50000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13
            Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13
            Source: 00000000.00000002.2653955478.0000028ADE5A0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13
            Source: Process Memory Space: aspnet_compiler.exe PID: 5792, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: Process Memory Space: aspnet_compiler.exe PID: 5792, type: MEMORYSTRMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, FF1YoNsGP8eIQ23Q2kR.csCryptographic APIs: 'CreateDecryptor'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, FF1YoNsGP8eIQ23Q2kR.csCryptographic APIs: 'CreateDecryptor'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, FF1YoNsGP8eIQ23Q2kR.csCryptographic APIs: 'CreateDecryptor'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, FF1YoNsGP8eIQ23Q2kR.csCryptographic APIs: 'CreateDecryptor'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, ITaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, TaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask', 'CreateFolder'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, Task.csTask registration methods: 'RegisterChanges', 'CreateTask'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, TaskService.csTask registration methods: 'CreateFromToken'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, ITaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, TaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask', 'CreateFolder'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, TaskPrincipal.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, User.csSecurity API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type)
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, Task.csSecurity API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections)
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, TaskSecurity.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges()
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, TaskSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule)
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, User.csSecurity API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type)
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, TaskFolder.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections)
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, TaskFolder.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections)
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, TaskPrincipal.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, TaskSecurity.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges()
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, TaskSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule)
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, Task.csSecurity API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections)
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, MockTracer.csSuspicious method names: .MockTracer.Inject
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, TextMapPropagator.csSuspicious method names: .TextMapPropagator.Inject
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, GlobalTracer.csSuspicious method names: .GlobalTracer.Inject
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, BinaryInjectAdapter.csSuspicious method names: .BinaryInjectAdapter.Set
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, BinaryInjectAdapter.csSuspicious method names: .BinaryInjectAdapter.Get
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, IPropagator.csSuspicious method names: ..Inject
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, TextMapInjectAdapter.csSuspicious method names: .TextMapInjectAdapter.GetEnumerator
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, TextMapInjectAdapter.csSuspicious method names: .TextMapInjectAdapter.Set
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, NoopTracer.csSuspicious method names: .NoopTracer.Inject
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, ConsolePropagator.csSuspicious method names: .ConsolePropagator.Inject
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, ITracer.csSuspicious method names: ..Inject
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, BinaryPropagator.csSuspicious method names: .BinaryPropagator.Inject
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@4/0@4/3
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeMutant created: NULL
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3700:120:WilError_03
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeStatic file information: TRID: Win64 Executable GUI Net Framework (217006/5) 49.88%
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: aspnet_compiler.exe, 00000005.00000002.3404892860.0000022945DCB000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935FDE000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935FFC000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.000002293602B000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022936038000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935FEE000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeReversingLabs: Detection: 28%
            Source: unknownProcess created: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe "C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe"
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe"
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe"Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: wbemcomn.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: wtsapi32.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: winsta.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: version.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE985000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE4A2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2666267100.0000028AE7130000.00000004.08000000.00040000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE51A000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE985000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE4A2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2666267100.0000028AE7130000.00000004.08000000.00040000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADE51A000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: protobuf-net.pdbSHA256}Lq source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmp
            Source: Binary string: protobuf-net.pdb source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmp

            Data Obfuscation

            barindex
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, FF1YoNsGP8eIQ23Q2kR.cs.Net Code: Type.GetTypeFromHandle(c0ymbpK5nFyouWuOkHR.KBcirswEBU(16777265)).GetMethod("GetDelegateForFunctionPointer", new Type[2]{Type.GetTypeFromHandle(c0ymbpK5nFyouWuOkHR.KBcirswEBU(16777259)),Type.GetTypeFromHandle(c0ymbpK5nFyouWuOkHR.KBcirswEBU(16777263))})
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade51a3f0.9.raw.unpack, XmlSerializationHelper.cs.Net Code: ReadObjectProperties
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ade4ca3b8.1.raw.unpack, XmlSerializationHelper.cs.Net Code: ReadObjectProperties
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ae6ed0000.12.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ae6ed0000.12.raw.unpack, ListDecorator.cs.Net Code: Read
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ae6ed0000.12.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ae6ed0000.12.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ae6ed0000.12.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
            Source: Yara matchFile source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ae6e50000.11.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf1f39b8.8.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000000.00000002.2665435188.0000028AE6E50000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2646867703.0000028ACE51D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe PID: 6044, type: MEMORYSTR
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD34795CE0 push FFFFFFE8h; ret 0_2_00007FFD34795CF9
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD3479814D push ebx; ret 0_2_00007FFD3479816A
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD347950D3 push FFFFFFE8h; ret 0_2_00007FFD347950F9
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD348B2E29 push eax; iretd 0_2_00007FFD348B2E52
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeCode function: 0_2_00007FFD3495420A push esp; iretd 0_2_00007FFD3495420B
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 5_2_0000022934010171 push ebp; iretd 5_2_0000022934010172
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeCode function: 5_2_00007FFD34858169 push ebx; ret 5_2_00007FFD3485816A
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, o8N7k9dOXypYPqAMSQ.csHigh entropy of concatenated method names: 'QGx5B6RHt', 'HB56g2Flt', 'lkL03q4Vh', 'c2leLdbUZ', 'rAvRYxe3VmqncXgcZGZ', 'p7AGGXezFEuZuht6l8b', 'AiH8He08gcIpNWhtGQq', 'LYLPpb07SCXC7bJrBK0', 'Qu5Q7f0r3rrC33vvC8N', 'wEqHke0TuDu6clIpRvj'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, AssemblyLoader.csHigh entropy of concatenated method names: 'CultureToString', 'ReadExistingAssembly', 'CopyTo', 'LoadStream', 'LoadStream', 'ReadStream', 'ReadFromEmbeddedResources', 'ResolveAssembly', 'Attach', 'Orw9BiNvFO2q0eC8Uut'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, RQZxa3jMdhrvAcCuICn.csHigh entropy of concatenated method names: 'Mukjk7benr', 'FA3j3nsPxV', 'rOLs8kYyuH', 'GODZNi9VlMjqpER4H1g', 'nqlCsV99QFJNdIQ5mHy', 'Y9bXyJ9yXf3OFf2WfF4', 'VJQdE29B2V2cyRCEpJG', 'YVSvaJ9NdceSwcyhVtq', 't7GPag9okiu4dgQG9EP'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, aVbhW4sxpqI5kjWpaaF.csHigh entropy of concatenated method names: 'v6Os27ckx4', 'fjCDatN9aLFDS9xhPBk', 'YAQYNyNNcpFAJ0ic6OH', 'YiSJmFNoP7J82rIHFIT', 's8yLO8NF0EXbPE5VMHa', 'lCFUgKNZ9a72SVnwRld', 'XQFIt9NBUd9JeDoR98T', 'EDBbjLNVe8jXOaAhRok'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, dIMFsHmh76WoTpvu4xN.csHigh entropy of concatenated method names: 'RtlInitUnicodeString', 'LdrLoadDll', 'RtlZeroMemory', 'NtQueryInformationProcess', 'ls1mxa0SPq', 'NtProtectVirtualMemory', 'wHSQtcy4aNuH27KCNw5', 'APjp4Tyt8EkOkcNn8j3', 'FGN0vyyCfdJrpJe55rG', 'FpEiRDyu5X72UwmIdrR'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, x2avBpLhQxpdUaQQ6ws.csHigh entropy of concatenated method names: 'h6aLxA943F', 'mSZLwa6Rq5', 'vHPLrWGnreMIWPR93IB', 'fxfOgIG4xDH6f0XekCp', 'dP6PywGtsUYqTyQVb8v', 'fbDJcnGiCSQvE2lDVst', 'ogtWAOGAvqdI9F31dvN', 'wyJkpLGgN6h6tkfnfAi', 'dVanNOGU7tkJVZtLXOu', 'iMx32CGpxpBPwDyY8LI'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, MHsuAVO89Ma838Xn5R.csHigh entropy of concatenated method names: 'qG9l2uS9i', 'zDyDQUIXY', 'DhCh2ILeN', 'evpqdXdJH', 'ieiJplDQq', 'FMdfRqepTimuBDbG0fs', 'piWxsVef50wELbvTXuO', 'BELgI3eI06l59JQq2cp', 'uvpLsTeHurjoP8gJNni', 'P8FuEDe1XeMeAKbsdK5'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, pk8TeRjEbj78gRXijax.csHigh entropy of concatenated method names: 'xrqjBTLH0g', 'Hy7hYnVuWNbeYtleIxM', 'A2s0v4V4erNeys8LHOB', 'j1U19VVtFIW1U6LPNbe', 'sdXTv9VnCdFqFIaJJnH', 'G8AQesViopi9QNgtXEE', 'gAui42VAfu9idwfDdq3', 'LaagWZVg0JXPI7acKas', 'hOdTYjVZjSFyoSGT9Ql', 'NU5QknVCY2KLsF5TEY1'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, Bv6rWFsrI2Y8xp0b6Hb.csHigh entropy of concatenated method names: 'LC9sPPLjJ5', 'xQRkAx9uQk0a0pp1Slj', 'OXHblZ94Bcomsm0qaRC', 'q1s1uK9t1gqOp0dhv5p', 'XJk0h99nAGwBMZRPLxQ', 'iE9KoU9iKFjvwYBQHWU', 'n25iUJ9Zb5BrgYoFwDl', 'fUgNkm9CvL0ECekkl6Y'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, aHpkZWK1dlnWZ6bvWdT.csHigh entropy of concatenated method names: 'ssnhXK8GHn', 'We7hhvV8Wa', 'MCchqdFOSD', 'RJmhxbRV3u', 'sd8hwxbuQ1', 'gcWh2hO5FO', 'MenhdcesLA', 'Y4IODqHK94', 'yOUhRIZHlX', 'H2bh5CdUwX'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, iaH6c4jIPU8kNU8R6d9.csHigh entropy of concatenated method names: 'xXoj13yxty', 'PIRjvJW1lX', 'MttjShk7ni', 'UoBNc8965GMQnS3MQco', 'zxdUAW9ee8ibNHTqwSQ', 'cHu9hs9RoNcmUtM55FS', 'dHqsBm95uPw1mu2jeWu', 'ARK9QC90lr6hlKKqHbK', 'beFMZx9GetBChIYX2u2'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, eAWhucLB2AAPW4e5xOw.csHigh entropy of concatenated method names: 'cbxL9Nq7Yx', 'SkjLNTfhlU', 'pVcLocH7fd', 'PPbFeSEZ7oLnpue8Pef', 'JYuXkbECkdxDR9AfeAn', 'm6eNtlEuD115VuHLKub', 'waKTSPE4RKmj01mRLb1', 'QM6KOqEoTAfsqyCwv5a', 'Ch5ePQEFTIXZ1NujtHN', 'TjME5iEtssiSXNgD6Jb'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, jpERS1ssS38HEoy0GRE.csHigh entropy of concatenated method names: 'CjksKpGtSF', 'Yt8sOdpXJR', 'okBgKo9SE6GmkEEIBJB', 'zOlorM9vA0dXgTNSLKD', 'pbG7ya9HQq26XwwMfGF', 'KD51vR91d5Eenp43gDn', 'XMeJ2x9W4qV9exFuHfw', 'wEAF0W9MeTLWKeUorb3', 'T6FVo29bxyEOMluSoig', 'vnwCXZ9kf4c4kJBQFCL'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, nDRO8hsDNhaU52TVjPC.csHigh entropy of concatenated method names: 'fxrshI1sCm', 'MBmsq6ZLCh', 'F3NUQFN5paxELeRDvmy', 'NsjSSZN6EP5SWeNxx5K', 'GnknhtNero2vv6obBtX', 'UKpKpKNdNxVCHSVbjoI', 'G0Bss7NRtCcinF9D2pP', 'rvi6RjN0Jtf9q0dqk41', 'psWLIFNGs42cnPtQ6WY', 'eGx76bNEI6Jfxquiqms'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, jvTuJRrX4gk1piCH5TC.csHigh entropy of concatenated method names: 'Bu5rqDLVLw', 'YZNUTl09mtqv3GLpHHT', 'cNhq1m0NVa1ikDVDgdB', 'i50jGj0oFBLr5KErb9i', 'T66oFS0FsUTmKZEPqk5', 'xRjjQx0ZudtiL49J8yI', 'ieRhFb0CiONf72vRccR', 'LW30M00uguGinUS2ar6', 'NfHuUq0426ZZDYemyNA', 'TRJaYK0tDmaLQThhgLb'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, vi2LKGL53YwMYBB6cCm.csHigh entropy of concatenated method names: 'wZCLeySa3E', 'avoL0C7mRm', 'pqJLGK8xDm', 's9GLE3l1vD', 'agwLy2cwyi', 'QSMwhEGkjl4hZHWOeLl', 'frhbDQG3RJol7hdFshs', 'hrSl2PGzCcy7IN5JlPW', 'yLEQAGE89wD09qH671i', 'Am3wI1E7DcnSvgw6Dfc'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, FF1YoNsGP8eIQ23Q2kR.csHigh entropy of concatenated method names: 'EbLkSHoouZHy8v7ImiE', 'YipXTNoFLcKs2BtF4SD', 'huNKPPR8oA', 'bKPjjXo4LG2pbKggZxA', 'inMKH8ot9eb3JZAdxTE', 'EUiflKon6Xfw4TdD8TF', 'IqJqWEoiXjCZXfqpnlE', 'zd2FVWoAt08hqRaETy2', 'lQ7oc8ogrCsCPgihbY4', 'nDxJOgoUSdbKQwFxlCY'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, vd4qFls5WRwjancQki3.csHigh entropy of concatenated method names: 'Qagnz6n3sh', 'niYAV8o5SbHR75HWjeI', 'aaI3n7o6sZ5N8gBdATS', 'Om8uqhoeHlPeqdpSDLT', 'Ek45q3o05DJfxXdSE2L', 'usrH0QoGAKCfWTyoQME', 'nWtwtPodtrX4lY6JL0A', 'WCnpLcoRpqqba1uIwNL', 'oBRub2oEukg8lRoZAH6', 'pUDPptoyOqovHFKMbPq'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, FjHAitjVKo3qIxQNcT2.csHigh entropy of concatenated method names: 'TtXjFm2btC', 'p2jjZUVNbU', 'rJKjNRfJfr', 'LLTjonCjrs', 'iBwS6EVIZmV5nEggNUk', 'rOO9BSVHD3MZYLOQnRT', 'msfWjSV14XZ1wxI6oeD', 'gRVRdOVSrC5GvslfvRi', 'RZGEGGVvcUS1EUTZTV6', 'BqrIg1VpCDLN6u4ZDfm'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, JKrcBoj4Z2y8ctFXIFu.csHigh entropy of concatenated method names: 'FEUjnESkaG', 'yMh51bVzI9uFF3lgQII', 'mH7Ffg98E4Mk2ea3bC9', 'MrQDor97vUeTGb2F1Xh', 'jd60Ax9rsCMUrN1YVIi', 'prCs9i9TklUZO1one29', 'ijm5w69PGkuZx3mJQdk', 'QmtGiA9LB6SAACnrGW3', 'MoBI529mrayTpOthv0E', 'ajX0qc9amnRrSvDqysu'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, RCREv7j6ZiYc0gtE0WM.csHigh entropy of concatenated method names: 'Ra9j0XFgJA', 'xlIjGhUB7O', 'QcksArVjG6odE3oEpT7', 'weauHDVs9IRd9qaliY3', 'l7IfbbVYcNdtn14jyQd', 'ms1ncWVKTSiytnMAACP', 'YGMTt1VOGcoLqCkNHEq', 'IbhKiAVcNpmlPC9UmbO', 'NFYKTAVJLYbdDwpuuCf', 'Ytq9gQVl68NBcQESUU9'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, MQprkFm7gmyPfFRgDko.csHigh entropy of concatenated method names: 'PRfmT1ZYVh', 'tIKmLSJVFE', 'vlwmataPZv', 'aRImjJn6DR', 'KukmsVu1C5', 'sU6mYmkGHT', 'scgmKMa4BX', 'BmymOoqtXc', 'tNnmcGZuid', 'pVmmJomIfR'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, K31p3XKEPuLttjngMib.csHigh entropy of concatenated method names: 'YDGKtQgNPg', 'JW2Kn5Ec9I', 'CPLKieVA4A', 'nlXKA2Y3wa', 'GphKgIyqLv', 'f3sKU01EC7', 'zWlKpiDCfj', 'jIfKfhvJHU', 'cKqKIWGv61', 'dg8KH4B2OO'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28adf0024e8.4.raw.unpack, LpP1VPscH6vAMIhgfkM.csHigh entropy of concatenated method names: 'rJJslituGa', 'cJiVdmNcAtiyO94vxHs', 'CXE8jjNJOAGjYggIQdP', 'xKcbn1Nlus3HKlRWaH3', 'KHN1RYNDDjeM5fTDmlW', 'JpjDgrNXWdkX7cNHNlY', 'krKcTSNheGpLHrjnSXW', 'jXWZgMNqko6fkLth3Pt', 'x0oODxNxTgLkCI8xKrF', 'yi2ZjuNwnYlZYgv7ne4'
            Source: 0.2.QUOTATION_SEPQTRA071244#U00faPDF.scr.exe.28ae6d50000.10.raw.unpack, dIMFsHmh76WoTpvu4xN.csHigh entropy of concatenated method names: 'RtlInitUnicodeString', 'LdrLoadDll', 'RtlZeroMemory', 'NtQueryInformationProcess', 'ls1mxa0SPq', 'NtProtectVirtualMemory', 'wHSQtcy4aNuH27KCNw5', 'APjp4Tyt8EkOkcNn8j3', 'FGN0vyyCfdJrpJe55rG', 'FpEiRDyu5X72UwmIdrR'
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL`Z
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE51D000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: EXPLORERESBIEDLL.DLLFCUCKOOMON.DLLGWIN32_PROCESS.HANDLE='{0}'HPARENTPROCESSIDICMDJSELECT * FROM WIN32_BIOS8UNEXPECTED WMI QUERY FAILUREKVERSIONLSERIALNUMBERNVMWARE|VIRTUAL|A M I|XENOSELECT * FROM WIN32_COMPUTERSYSTEMPMANUFACTURERQMODELRMICROSOFT|VMWARE|VIRTUALSJOHNTANNAUXXXXXXXX
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeMemory allocated: 28ACE200000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeMemory allocated: 28AE6450000 memory reserve | memory write watchJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeMemory allocated: 22934310000 memory reserve | memory write watchJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeMemory allocated: 2294DD10000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599886Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599780Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599656Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599523Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599405Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599082Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598616Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598493Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598375Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598266Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598156Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598047Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597938Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597828Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597703Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597594Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597484Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597375Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597250Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597141Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597031Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596922Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596812Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596688Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596578Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596469Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596353Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596200Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595927Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595799Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595686Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595578Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595469Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595359Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595250Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595141Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595016Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594891Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594781Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594672Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594563Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594438Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594313Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594203Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594094Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593969Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593859Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593750Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593639Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593530Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593422Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593304Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599874Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599765Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599654Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599544Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599429Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599317Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599203Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599063Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598928Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598777Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598671Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598562Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598453Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598343Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598233Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598125Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598015Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597906Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597797Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597687Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597578Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597468Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597359Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597250Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597140Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597027Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596922Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596812Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596702Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596593Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596180Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596054Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595906Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595779Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595656Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595547Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595437Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595328Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595218Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595109Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594999Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594890Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594781Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594671Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594562Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594453Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594343Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594234Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594125Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594015Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 593906Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeWindow / User API: threadDelayed 3465Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeWindow / User API: threadDelayed 6287Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeWindow / User API: threadDelayed 1831Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeWindow / User API: threadDelayed 8005Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep count: 38 > 30Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -35048813740048126s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -600000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -599886s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 6552Thread sleep count: 3465 > 30Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -599780s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -599656s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 6552Thread sleep count: 6287 > 30Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -599523s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -599405s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -599082s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -598616s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -598493s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -598375s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -598266s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -598156s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -598047s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597938s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597828s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597703s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597594s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597484s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597375s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597250s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597141s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -597031s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -596922s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -596812s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -596688s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -596578s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -596469s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -596353s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -596200s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595927s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595799s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595686s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595578s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595469s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595359s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595250s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595141s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -595016s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -594891s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -594781s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -594672s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -594563s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -594438s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -594313s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -594203s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -594094s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -593969s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -593859s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -593750s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -593639s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -593530s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -593422s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe TID: 5396Thread sleep time: -593304s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep count: 33 > 30Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -30437127721620741s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -600000s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 6716Thread sleep count: 1831 > 30Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -599874s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 6716Thread sleep count: 8005 > 30Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -599765s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -599654s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -599544s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -599429s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -599317s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -599203s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -599063s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598928s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598777s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598671s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598562s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598453s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598343s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598233s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598125s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -598015s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597906s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597797s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597687s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597578s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597468s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597359s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597250s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597140s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -597027s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -596922s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -596812s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -596702s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -596593s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -596180s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -596054s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -595906s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -595779s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -595656s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -595547s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -595437s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -595328s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -595218s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -595109s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594999s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594890s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594781s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594671s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594562s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594453s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594343s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594234s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594125s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -594015s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe TID: 3976Thread sleep time: -593906s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from Win32_BIOS
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from Win32_ComputerSystem
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599886Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599780Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599656Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599523Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599405Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 599082Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598616Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598493Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598375Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598266Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598156Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 598047Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597938Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597828Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597703Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597594Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597484Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597375Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597250Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597141Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 597031Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596922Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596812Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596688Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596578Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596469Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596353Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 596200Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595927Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595799Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595686Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595578Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595469Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595359Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595250Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595141Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 595016Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594891Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594781Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594672Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594563Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594438Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594313Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594203Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 594094Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593969Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593859Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593750Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593639Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593530Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593422Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread delayed: delay time: 593304Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599874Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599765Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599654Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599544Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599429Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599317Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599203Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 599063Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598928Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598777Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598671Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598562Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598453Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598343Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598233Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598125Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 598015Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597906Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597797Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597687Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597578Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597468Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597359Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597250Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597140Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 597027Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596922Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596812Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596702Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596593Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596180Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 596054Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595906Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595779Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595656Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595547Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595437Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595328Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595218Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 595109Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594999Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594890Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594781Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594671Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594562Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594453Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594343Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594234Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594125Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 594015Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 593906Jump to behavior
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 1:en-CH:VMware|VIRTUAL|A M I|Xen
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 1:en-CH:Microsoft|VMWare|Virtual
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmware
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware|VIRTUAL|A M I|Xen
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 0VMware|VIRTUAL|A M I|Xen
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 0Microsoft|VMWare|Virtual
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWare
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE7F2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Microsoft|VMWare|Virtual
            Source: aspnet_compiler.exe, 00000005.00000002.3400493487.00000229342C7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW %SystemRoot%\system32\mswsock.dllers>
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE51D000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: explorerESbieDll.dllFcuckoomon.dllGwin32_process.handle='{0}'HParentProcessIdIcmdJselect * from Win32_BIOS8Unexpected WMI query failureKversionLSerialNumberNVMware|VIRTUAL|A M I|XenOselect * from Win32_ComputerSystemPmanufacturerQmodelRMicrosoft|VMWare|VirtualSjohnTannaUxxxxxxxx
            Source: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646512813.0000028ACC9A5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeMemory allocated: page read and write | page guardJump to behavior

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeThread created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe EIP: 34010000Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeMemory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe base: 22934010000Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeProcess created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe"Jump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeQueries volume information: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.3402009366.0000022935F56000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.3402009366.0000022935D11000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: aspnet_compiler.exe PID: 5792, type: MEMORYSTR
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: aspnet_compiler.exe PID: 5792, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22934340000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22945d200e8.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22934340000.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 5.2.aspnet_compiler.exe.22945d200e8.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.3402009366.0000022935F56000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.3402009366.0000022935D11000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: aspnet_compiler.exe PID: 5792, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
            Windows Management Instrumentation
            1
            Scheduled Task/Job
            211
            Process Injection
            1
            Disable or Modify Tools
            1
            OS Credential Dumping
            1
            Query Registry
            Remote Services1
            Email Collection
            11
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault Accounts1
            Scheduled Task/Job
            1
            DLL Side-Loading
            1
            Scheduled Task/Job
            41
            Virtualization/Sandbox Evasion
            LSASS Memory111
            Security Software Discovery
            Remote Desktop Protocol11
            Archive Collected Data
            1
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
            DLL Side-Loading
            211
            Process Injection
            Security Account Manager1
            Process Discovery
            SMB/Windows Admin Shares1
            Data from Local System
            2
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            Deobfuscate/Decode Files or Information
            NTDS41
            Virtualization/Sandbox Evasion
            Distributed Component Object ModelInput Capture13
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
            Obfuscated Files or Information
            LSA Secrets1
            Application Window Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts2
            Software Packing
            Cached Domain Credentials1
            System Network Configuration Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
            DLL Side-Loading
            DCSync33
            System Information Discovery
            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            QUOTATION_SEPQTRA071244#U00faPDF.scr.exe29%ReversingLabsWin64.Trojan.Mardom
            QUOTATION_SEPQTRA071244#U00faPDF.scr.exe100%Joe Sandbox ML
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            http://checkip.dyndns.org/0%URL Reputationsafe
            https://stackoverflow.com/q/14436606/233540%URL Reputationsafe
            https://stackoverflow.com/q/11564914/23354;0%URL Reputationsafe
            https://stackoverflow.com/q/2152978/233540%URL Reputationsafe
            http://checkip.dyndns.org/q0%URL Reputationsafe
            https://reallyfreegeoip.org0%URL Reputationsafe
            http://checkip.dyndns.org0%URL Reputationsafe
            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0%URL Reputationsafe
            https://reallyfreegeoip.org/xml/0%URL Reputationsafe
            https://s24.filetransfer.io/storage/download/klH4VFXHnzlT0%Avira URL Cloudsafe
            https://github.com/mgravell/protobuf-net0%Avira URL Cloudsafe
            https://github.com/mgravell/protobuf-neti0%Avira URL Cloudsafe
            https://github.com/mgravell/protobuf-netJ0%Avira URL Cloudsafe
            http://filetransfer.io/data-package/Ky4pZ0WB/download0%Avira URL Cloudsafe
            https://filetransfer.io0%Avira URL Cloudsafe
            http://checkip.dyndns.com0%Avira URL Cloudsafe
            http://reallyfreegeoip.org0%Avira URL Cloudsafe
            https://reallyfreegeoip.org/xml/8.46.123.33p0%Avira URL Cloudsafe
            https://filetransfer.io/data-package/Ky4pZ0WB/download0%Avira URL Cloudsafe
            http://filetransfer.io0%Avira URL Cloudsafe
            https://reallyfreegeoip.org/xml/8.46.123.330%Avira URL Cloudsafe
            https://s24.filetransfer.io0%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            s24.filetransfer.io
            188.114.97.3
            truetrue
              unknown
              filetransfer.io
              188.114.97.3
              truetrue
                unknown
                reallyfreegeoip.org
                188.114.96.3
                truetrue
                  unknown
                  checkip.dyndns.com
                  193.122.130.0
                  truefalse
                    unknown
                    checkip.dyndns.org
                    unknown
                    unknowntrue
                      unknown
                      NameMaliciousAntivirus DetectionReputation
                      https://s24.filetransfer.io/storage/download/klH4VFXHnzlTtrue
                      • Avira URL Cloud: safe
                      unknown
                      http://checkip.dyndns.org/false
                      • URL Reputation: safe
                      unknown
                      http://filetransfer.io/data-package/Ky4pZ0WB/downloadtrue
                      • Avira URL Cloud: safe
                      unknown
                      https://filetransfer.io/data-package/Ky4pZ0WB/downloadtrue
                      • Avira URL Cloud: safe
                      unknown
                      https://reallyfreegeoip.org/xml/8.46.123.33false
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://reallyfreegeoip.org/xml/8.46.123.33paspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E1D000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://github.com/mgravell/protobuf-netiQUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://stackoverflow.com/q/14436606/23354QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE51D000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://github.com/mgravell/protobuf-netJQUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://stackoverflow.com/q/11564914/23354;QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://stackoverflow.com/q/2152978/23354QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://checkip.dyndns.org/qaspnet_compiler.exe, 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://reallyfreegeoip.orgaspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EBD000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EE8000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E3C000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F30000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F42000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EFB000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935ED5000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://filetransfer.ioQUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE490000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://github.com/mgravell/protobuf-netQUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2653955478.0000028ADF2E2000.00000004.00000800.00020000.00000000.sdmp, QUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2665927288.0000028AE6ED0000.00000004.08000000.00040000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://reallyfreegeoip.orgaspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E1D000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EBD000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EE8000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F30000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F42000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EFB000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935ED5000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E6B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://checkip.dyndns.orgaspnet_compiler.exe, 00000005.00000002.3402009366.0000022935ED5000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E6B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://checkip.dyndns.comaspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E1D000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EBD000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EE8000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F30000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935F42000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935EFB000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935ED5000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://filetransfer.ioQUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE451000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameQUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE451000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935D11000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://s24.filetransfer.ioQUOTATION_SEPQTRA071244#U00faPDF.scr.exe, 00000000.00000002.2646867703.0000028ACE4C3000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://reallyfreegeoip.org/xml/aspnet_compiler.exe, 00000005.00000002.3402009366.0000022935E1D000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, aspnet_compiler.exe, 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      188.114.97.3
                      s24.filetransfer.ioEuropean Union
                      13335CLOUDFLARENETUStrue
                      188.114.96.3
                      reallyfreegeoip.orgEuropean Union
                      13335CLOUDFLARENETUStrue
                      193.122.130.0
                      checkip.dyndns.comUnited States
                      31898ORACLE-BMC-31898USfalse
                      Joe Sandbox version:41.0.0 Charoite
                      Analysis ID:1519261
                      Start date and time:2024-09-26 09:22:23 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 6m 12s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:7
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
                      renamed because original name is a hash value
                      Original Sample Name:QUOTATION_SEPQTRA071244PDF.scr.exe
                      Detection:MAL
                      Classification:mal100.troj.spyw.evad.winEXE@4/0@4/3
                      EGA Information:
                      • Successful, ratio: 100%
                      HCA Information:
                      • Successful, ratio: 57%
                      • Number of executed functions: 86
                      • Number of non-executed functions: 6
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                      • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                      • VT rate limit hit for: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
                      TimeTypeDescription
                      03:23:16API Interceptor9690x Sleep call for process: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe modified
                      03:24:07API Interceptor54909x Sleep call for process: aspnet_compiler.exe modified
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      188.114.97.3ADNOC requesting RFQ.exeGet hashmaliciousFormBookBrowse
                      • www.1win-moldovia.fun/1g7m/
                      http://www.tiktok758.com/Get hashmaliciousUnknownBrowse
                      • www.tiktok758.com/img/logo.4c830710.svg
                      TRmSF36qQG.exeGet hashmaliciousFormBookBrowse
                      • www.zhxgtlw.top/bopi/?0T5=UL08qvZHLtV&EnAHS=tIrAt1o0vWdNGbj/SzADcCGpASEIYc8Vm+jYIgWXaQC1p/Id9tI9XA8Ni4JOdI1EXss+
                      PO5118000306 pdf.exeGet hashmaliciousFormBookBrowse
                      • www.rtprajalojago.live/2wnz/
                      (PO403810)_VOLEX_doc.exeGet hashmaliciousLokibotBrowse
                      • dddotx.shop/Mine/PWS/fre.php
                      QUOTATION_SEPQTRA071244PDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                      • filetransfer.io/data-package/DiF66Hbf/download
                      http://easyantrim.pages.dev/id.htmlGet hashmaliciousHTMLPhisherBrowse
                      • easyantrim.pages.dev/id.html
                      QUOTATION_SEPQTRA071244PDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                      • filetransfer.io/data-package/13rSMZZi/download
                      Purchase Order_ AEPL-2324-1126.exeGet hashmaliciousFormBookBrowse
                      • www.rtpngk.xyz/yhsl/
                      PO-001.exeGet hashmaliciousFormBookBrowse
                      • www.x0x9x8x8x7x6.shop/assb/
                      188.114.96.3ADNOC requesting RFQ.exeGet hashmaliciousFormBookBrowse
                      • www.chinaen.org/zi4g/
                      http://twint.ch-daten.com/de/receive/bank/sgkb/79469380Get hashmaliciousUnknownBrowse
                      • twint.ch-daten.com/socket.io/?EIO=4&transport=polling&t=P8hxwsc
                      Cbequipment-Voice Audio Interface.pdfGet hashmaliciousHTMLPhisherBrowse
                      • www.444317.com/
                      Sept order.docGet hashmaliciousFormBookBrowse
                      • www.rajalele.xyz/bopi/?1b=1soTE/gd/ZpFZmuHMdkP9CmM1erq3xsEeOQ9nFH+Tv+qMlBfxeqrLL5BDR/2l62DivVTHQ==&BfL=LxlT-
                      1e#U0414.exeGet hashmaliciousLokibotBrowse
                      • dddotx.shop/Mine/PWS/fre.php
                      https://laurachenel-my.sharepoint.com/:f:/p/durae/EqNLWpSMEBRJoccjxMrYR9cBuepxDM4GGslgNeOpyvFENQ?e=1C1jRHGet hashmaliciousUnknownBrowse
                      • hdcy.emcl00.com/qRCfs/
                      PO23100072.exeGet hashmaliciousFormBookBrowse
                      • www.cc101.pro/ttiz/
                      RFQ urrgently.exeGet hashmaliciousFormBookBrowse
                      • www.1win-moldovia.fun/1g7m/
                      TNT AWB TRACKING DETAILS.exeGet hashmaliciousFormBookBrowse
                      • www.weight-loss-003.today/jd21/?Bl=8pSpW470ix&FjUh5xw=8QhlJgbwFiNHSz6ilu/NO/QAEgywgMMp9yv6yRtWAY1NzG57DnL+pjMXQcNu92teMaGp
                      Petronas quotation request.exeGet hashmaliciousFormBookBrowse
                      • www.chinaen.org/zi4g/
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      s24.filetransfer.ioQUOTATION_SEPQTRA071244PDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 188.114.97.3
                      QUOTATION_SEPQTRA071244#U00faPDF.scrGet hashmaliciousFormBookBrowse
                      • 188.114.96.3
                      QUOTATION_SEPQTRA071244#U00faPDF.scrGet hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.97.3
                      QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      QUOTATION_AUGQTRA071244PDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.97.3
                      QUOTATION_JULQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      QUOTATION_JULQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.97.3
                      QUOTATION_JULQTRA071244#U00b7PDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      reallyfreegeoip.orgTEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exeGet hashmaliciousMassLogger RAT, Snake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      Payment Slip.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      SecuriteInfo.com.Trojan.Packed2.48025.4038.12608.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.97.3
                      z95g0YV3PKzM3LA5zt.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 188.114.96.3
                      SecuriteInfo.com.Win32.PWSX-gen.19525.31847.exeGet hashmaliciousVIP KeyloggerBrowse
                      • 188.114.97.3
                      inquiry.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      SecuriteInfo.com.W32.Autoit.AOY.gen.Eldorado.13807.19631.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.97.3
                      Halkbank_Ekstre_22#U202693.25.09.24.pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      E-dekont.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 188.114.97.3
                      Thyssenkrupp PO040232.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.97.3
                      checkip.dyndns.comTEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exeGet hashmaliciousMassLogger RAT, Snake Keylogger, VIP KeyloggerBrowse
                      • 132.226.8.169
                      Payment Slip.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 132.226.8.169
                      SecuriteInfo.com.Trojan.Packed2.48025.4038.12608.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 193.122.6.168
                      z95g0YV3PKzM3LA5zt.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 132.226.247.73
                      SecuriteInfo.com.Win32.PWSX-gen.19525.31847.exeGet hashmaliciousVIP KeyloggerBrowse
                      • 193.122.130.0
                      inquiry.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 158.101.44.242
                      SecuriteInfo.com.W32.Autoit.AOY.gen.Eldorado.13807.19631.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 132.226.247.73
                      Halkbank_Ekstre_22#U202693.25.09.24.pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 132.226.247.73
                      E-dekont.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 193.122.130.0
                      Thyssenkrupp PO040232.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 193.122.6.168
                      filetransfer.ioQUOTATION_SEPQTRA071244PDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 188.114.96.3
                      QUOTATION_SEPQTRA071244PDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 188.114.96.3
                      QUOTATION_SEPQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 188.114.96.3
                      QUOTATION_SEPQTRA071244#U00faPDF.scr.exeGet hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      QUOTATION_SEPQTRA071244#U00faPDF.scr.exeGet hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      QUOTATION_SEPQTRA071244PDF.scr.exeGet hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      CLOUDFLARENETUSThyssenkrupp PO040232.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      450230549.exeGet hashmaliciousAgentTeslaBrowse
                      • 162.159.134.233
                      64.exeGet hashmaliciousUnknownBrowse
                      • 162.159.61.3
                      450230549.exeGet hashmaliciousUnknownBrowse
                      • 162.159.134.233
                      PO-100001499.exeGet hashmaliciousFormBookBrowse
                      • 188.114.96.3
                      ADNOC requesting RFQ.exeGet hashmaliciousFormBookBrowse
                      • 104.21.64.108
                      TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exeGet hashmaliciousMassLogger RAT, Snake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      https://qwehikd-asdu.xyz/Get hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      https://geminishdw-dws.top/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      https://geminiqwc-sw.top/Get hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      CLOUDFLARENETUSThyssenkrupp PO040232.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      450230549.exeGet hashmaliciousAgentTeslaBrowse
                      • 162.159.134.233
                      64.exeGet hashmaliciousUnknownBrowse
                      • 162.159.61.3
                      450230549.exeGet hashmaliciousUnknownBrowse
                      • 162.159.134.233
                      PO-100001499.exeGet hashmaliciousFormBookBrowse
                      • 188.114.96.3
                      ADNOC requesting RFQ.exeGet hashmaliciousFormBookBrowse
                      • 104.21.64.108
                      TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exeGet hashmaliciousMassLogger RAT, Snake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      https://qwehikd-asdu.xyz/Get hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      https://geminishdw-dws.top/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      https://geminiqwc-sw.top/Get hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      ORACLE-BMC-31898USThyssenkrupp PO040232.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 158.101.44.242
                      Payment Slip.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 158.101.44.242
                      http://ec44d1ee.freyy.pages.dev/Zimbra%20Web%20Client%20Sign%20In/Get hashmaliciousUnknownBrowse
                      • 147.154.16.196
                      SecuriteInfo.com.Trojan.Packed2.48025.4038.12608.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 193.122.6.168
                      SecuriteInfo.com.Win32.PWSX-gen.19525.31847.exeGet hashmaliciousVIP KeyloggerBrowse
                      • 193.122.130.0
                      inquiry.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 158.101.44.242
                      SecuriteInfo.com.W32.Autoit.AOY.gen.Eldorado.13807.19631.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 158.101.44.242
                      E-dekont.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 193.122.130.0
                      Thyssenkrupp PO040232.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 158.101.44.242
                      z84TTREMITTANCEUSD347_432_63.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 193.122.130.0
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      54328bd36c14bd82ddaa0c04b25ed9adTEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exeGet hashmaliciousMassLogger RAT, Snake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      SecuriteInfo.com.Trojan.Packed2.48025.4038.12608.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      z95g0YV3PKzM3LA5zt.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 188.114.96.3
                      SecuriteInfo.com.Win32.PWSX-gen.19525.31847.exeGet hashmaliciousVIP KeyloggerBrowse
                      • 188.114.96.3
                      inquiry.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      SecuriteInfo.com.W32.Autoit.AOY.gen.Eldorado.13807.19631.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      Halkbank_Ekstre_22#U202693.25.09.24.pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      E-dekont.exeGet hashmaliciousSnake KeyloggerBrowse
                      • 188.114.96.3
                      file.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                      • 188.114.96.3
                      z84TTREMITTANCEUSD347_432_63.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                      • 188.114.96.3
                      3b5074b1b5d032e5620f69f9f700ff0e450230549.exeGet hashmaliciousAgentTeslaBrowse
                      • 188.114.97.3
                      450230549.exeGet hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exeGet hashmaliciousMassLogger RAT, Snake Keylogger, VIP KeyloggerBrowse
                      • 188.114.97.3
                      https://geminiqwc-sw.top/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      http://tiktok1688.cc/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      https://qwekorqw-eqo.top/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      https://qwoms-dei3.top/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      http://cmn.pkgu192.vip/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      http://frt.asan192.vip/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      https://tiktokshopxx.top/Get hashmaliciousUnknownBrowse
                      • 188.114.97.3
                      No context
                      No created / dropped files found
                      File type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                      Entropy (8bit):2.725066233885776
                      TrID:
                      • Win64 Executable GUI Net Framework (217006/5) 49.88%
                      • Win64 Executable GUI (202006/5) 46.43%
                      • Win64 Executable (generic) (12005/4) 2.76%
                      • Generic Win/DOS Executable (2004/3) 0.46%
                      • DOS Executable Generic (2002/1) 0.46%
                      File name:QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
                      File size:361'472 bytes
                      MD5:631691dca7abc573a0cc911b2ddca40e
                      SHA1:0ddc497bb233cda946e320378cde5e5cc507eb72
                      SHA256:922ff7b2589cfa1d6a8dcd706bc294be4d4cb4d9baf02df5717d121097ab1859
                      SHA512:4a94910b35a95038ba787095970ee32281011021f3cd33066bc8b350c2b1824e1f67a303492fbaae41e9872e75667325e3a4b8d759dce3a79105a00a09782dd9
                      SSDEEP:768:BiHqbOcbd5LGOcccCM8AMx9m24IeGFfRhQg2ZzEjss2VSg1I1cn0sspAgpq8hLy8:oHqbbJGwrThRhQ7qPpqOLy0uyL+fS
                      TLSH:9B743F1976B49132ED04CB7428F29E11C2E7EE5D2BE1921E25C8B66D1B326FD8F035C6
                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f.........."......f............... ....@...... ....................................`...@......@............... .....
                      Icon Hash:0e3333b0bbb3b035
                      Entrypoint:0x400000
                      Entrypoint Section:
                      Digitally signed:false
                      Imagebase:0x400000
                      Subsystem:windows gui
                      Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                      DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Time Stamp:0x66F3BCB4 [Wed Sep 25 07:33:08 2024 UTC]
                      TLS Callbacks:
                      CLR (.Net) Version:
                      OS Version Major:4
                      OS Version Minor:0
                      File Version Major:4
                      File Version Minor:0
                      Subsystem Version Major:4
                      Subsystem Version Minor:0
                      Import Hash:
                      Instruction
                      dec ebp
                      pop edx
                      nop
                      add byte ptr [ebx], al
                      add byte ptr [eax], al
                      add byte ptr [eax+eax], al
                      add byte ptr [eax], al
                      NameVirtual AddressVirtual Size Is in Section
                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_RESOURCE0xa0000x51aaa.rsrc
                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20000x48.text
                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                      .text0x20000x64940x66002d608fbb5362c6929620a3cf71b7e840False0.45036764705882354data5.532781563761647IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      .rsrc0xa0000x51aaa0x51c00c3f73acd94c48cdff4272b119e3ddd99False0.07137268253058104data2.3514408487511735IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      NameRVASizeTypeLanguageCountryZLIB Complexity
                      RT_ICON0xa3700x128Device independent bitmap graphic, 16 x 32 x 4, image size 1920.7601351351351351
                      RT_ICON0xa4980x368Device independent bitmap graphic, 16 x 32 x 24, image size 8320.7155963302752294
                      RT_ICON0xa8000x468Device independent bitmap graphic, 16 x 32 x 32, image size 00.6826241134751773
                      RT_ICON0xac680x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 6400.5389784946236559
                      RT_ICON0xaf500xca8Device independent bitmap graphic, 32 x 64 x 24, image size 32000.470679012345679
                      RT_ICON0xbbf80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 00.4378517823639775
                      RT_ICON0xcca00x668Device independent bitmap graphic, 48 x 96 x 4, image size 15360.36402439024390243
                      RT_ICON0xd3080x1ca8Device independent bitmap graphic, 48 x 96 x 24, image size 72960.33110687022900764
                      RT_ICON0xefb00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.30881742738589213
                      RT_ICON0x115580xa68Device independent bitmap graphic, 64 x 128 x 4, image size 25600.2924174174174174
                      RT_ICON0x11fc00x3228Device independent bitmap graphic, 64 x 128 x 24, image size 128000.26580996884735203
                      RT_ICON0x151e80x4228Device independent bitmap graphic, 64 x 128 x 32, image size 00.24244213509683515
                      RT_ICON0x194100x42028Device independent bitmap graphic, 256 x 512 x 32, image size 00.014139568600763382
                      RT_GROUP_ICON0x5b4380xbcdata0.5797872340425532
                      RT_VERSION0x5b4f40x3cadata0.4144329896907217
                      RT_MANIFEST0x5b8c00x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                      2024-09-26T09:23:21.173991+02002017962ET MALWARE PE EXE or DLL Windows file download disguised as ASCII1188.114.97.3443192.168.2.649713TCP
                      2024-09-26T09:23:21.173991+02002022640ET MALWARE PE EXE or DLL Windows file download Text M21188.114.97.3443192.168.2.649713TCP
                      2024-09-26T09:24:08.120101+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.649721193.122.130.080TCP
                      2024-09-26T09:24:08.916988+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.649721193.122.130.080TCP
                      2024-09-26T09:24:09.511667+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.649723188.114.96.3443TCP
                      2024-09-26T09:24:10.088998+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.649724193.122.130.080TCP
                      2024-09-26T09:24:11.182593+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.649727193.122.130.080TCP
                      2024-09-26T09:24:12.846196+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.649730188.114.96.3443TCP
                      2024-09-26T09:24:14.010726+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.649732188.114.96.3443TCP
                      TimestampSource PortDest PortSource IPDest IP
                      Sep 26, 2024 09:23:17.136116028 CEST4971080192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:17.141160011 CEST8049710188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:17.141263962 CEST4971080192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:17.143163919 CEST4971080192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:17.148108006 CEST8049710188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:17.800228119 CEST8049710188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:17.812596083 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:17.812648058 CEST44349711188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:17.812725067 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:17.854473114 CEST4971080192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:17.885476112 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:17.885513067 CEST44349711188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:18.359325886 CEST44349711188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:18.359457016 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:18.391016960 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:18.391052008 CEST44349711188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:18.391554117 CEST44349711188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:18.432624102 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:19.048492908 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:19.091403008 CEST44349711188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:19.806668043 CEST44349711188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:19.806792021 CEST44349711188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:19.806848049 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:19.825942993 CEST49711443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:19.838089943 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:19.838139057 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:19.838207006 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:19.838618994 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:19.838630915 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:20.336760044 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:20.336935043 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:20.339198112 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:20.339206934 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:20.339565039 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:20.340924978 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:20.387394905 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.079103947 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.079245090 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.079313040 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.079339027 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.079443932 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.079492092 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.079503059 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.079611063 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.079658031 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.079668045 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.080205917 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.080261946 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.080269098 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.083601952 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.083674908 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.083677053 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.083702087 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.083741903 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.171190977 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.171288967 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.171329021 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.171351910 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.171381950 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.171436071 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.171444893 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.171499014 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.171531916 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.171540022 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.171586990 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.171622992 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.171627998 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.172277927 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.172310114 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.172323942 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.172329903 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.172363997 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.172386885 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.172451019 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.172493935 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.172498941 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.173167944 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.173203945 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.173213005 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.173227072 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.173261881 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.173268080 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.174021959 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.174060106 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.174067974 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.174084902 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.174119949 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.174124956 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.174144030 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.174180031 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.263642073 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.263746977 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.263787985 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.263797045 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.263819933 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.263854980 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.263855934 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.263865948 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.263906002 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.263915062 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.263994932 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.264703035 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.264750004 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.264760017 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.264771938 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.264811039 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.265161991 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.265217066 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.265284061 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.265336990 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.266063929 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.266124964 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.266189098 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.266237974 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.266310930 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.266360998 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.267080069 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.267115116 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.267144918 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.267157078 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.267173052 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.267884016 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.267935038 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.267946959 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.267987967 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.268007040 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.268054962 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.304238081 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.304364920 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.356247902 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.356367111 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.356383085 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.356400967 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.356446981 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.356494904 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.356537104 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.356591940 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.356632948 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.356969118 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.357023954 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.357063055 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.357110977 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.357187986 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.357234955 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.357484102 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.357537031 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.357677937 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.357728958 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.357852936 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.357902050 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.357942104 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.357991934 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.358459949 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.358510971 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.358562946 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.358612061 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.358764887 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.358815908 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.358846903 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.358896971 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.359442949 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.359523058 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.359605074 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.359653950 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.359736919 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.359787941 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.359814882 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.359863997 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.360394001 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.360446930 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.360548019 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.360599041 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.360861063 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.360913038 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.360955954 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.361002922 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.361232042 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.361284018 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.396846056 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.397016048 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.448419094 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.448530912 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.448559046 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.448575974 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.448589087 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.448616028 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.449002981 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.449012041 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.449032068 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.449059963 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.449067116 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.449100018 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.449120998 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.449398041 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.449436903 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.449441910 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.449450016 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.449515104 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.449898005 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.449920893 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.450006008 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.450006008 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.450011015 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.450500965 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.450527906 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.450624943 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.450632095 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.450639963 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.454030991 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.454056025 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.454086065 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.454092979 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.454138041 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.454515934 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.454535007 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.454575062 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.454580069 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.454607010 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.455195904 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.455218077 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.455245018 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.455250025 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.455285072 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.495124102 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.541013956 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.541042089 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.541266918 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.541300058 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.541351080 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.541515112 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.541534901 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.541590929 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.541601896 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.541623116 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.541630983 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.542011023 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.542028904 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.542068005 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.542083025 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.542105913 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.542120934 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.542640924 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.542658091 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.542700052 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.542716026 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.542753935 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.542771101 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.543313026 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.543333054 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.543421030 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.543421984 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.543438911 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.543477058 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.543992043 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544020891 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544050932 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.544064999 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544085979 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.544101000 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.544279099 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544297934 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544323921 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.544332981 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544353962 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.544372082 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.544858932 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544879913 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544917107 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.544928074 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.544945955 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.544992924 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.550194025 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.633671045 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.633699894 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.633752108 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.633781910 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.633804083 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.633824110 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.634011030 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.634031057 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.634057045 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.634063959 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.634087086 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.634102106 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.634605885 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.634624004 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.634655952 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.634671926 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.634687901 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.634707928 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.635231018 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.635258913 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.635281086 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.635298014 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.635315895 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.635335922 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.635804892 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.635823965 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.635852098 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.635862112 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.635885000 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.635895967 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.636420012 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.636440039 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.636496067 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.636511087 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.636552095 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.636728048 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.636735916 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.636745930 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.636778116 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.636784077 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.636806011 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.636822939 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.637022972 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.637458086 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.637478113 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.637506008 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.637520075 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.637535095 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.637548923 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.726072073 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.726094961 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.726206064 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.726224899 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.726267099 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.726574898 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.726598024 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.726629972 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.726634979 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.726674080 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.726674080 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.727195024 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.727215052 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.727257967 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.727262974 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.727303982 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.727703094 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.727724075 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.727761030 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.727766037 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.727790117 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.727808952 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.728068113 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.728085995 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.728127003 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.728132010 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.728159904 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.728174925 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.728801966 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.728826046 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.728853941 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.728858948 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.728892088 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.728904963 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.729392052 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.729413033 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.729492903 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.729499102 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.729533911 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.729953051 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.729976892 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.730009079 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.730015039 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.730037928 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.730052948 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.819293976 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.819338083 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.819422007 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.819434881 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.819482088 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820055962 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820076942 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820111036 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820116997 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820128918 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820151091 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820375919 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820400000 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820435047 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820439100 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820465088 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820482969 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820837975 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820858002 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820884943 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820889950 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.820915937 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.820934057 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.821315050 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.821336031 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.821372986 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.821377993 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.821408987 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.821417093 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.821969032 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.821996927 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.822042942 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.822047949 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.822056055 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.822081089 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.822211027 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.822235107 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.822269917 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.822273970 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.822299957 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.822318077 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.822947025 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.822971106 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.822998047 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.823004007 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.823029995 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.823044062 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.833308935 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.911160946 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.911211967 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.911253929 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.911266088 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.911288977 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.911315918 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.911640882 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.911667109 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.911695957 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.911703110 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.911725044 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.911740065 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.912194014 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.912214041 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.912242889 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.912247896 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.912273884 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.912292004 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.912810087 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.912827969 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.912900925 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.912906885 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.912947893 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.913285971 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.913306952 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.913341999 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.913347006 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.913373947 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.913388014 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.913866043 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.913889885 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.913922071 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.913925886 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.913953066 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.913966894 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.914400101 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.914429903 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.914455891 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.914460897 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.914484024 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.914508104 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.915035009 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.915055990 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.915083885 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.915087938 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:21.915115118 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.915133953 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:21.918379068 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.003870010 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.003941059 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.004089117 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.004117966 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.004133940 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.004162073 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.004369020 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.004417896 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.004447937 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.004456043 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.004481077 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.004498959 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.004806995 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.004853964 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.004863977 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.004880905 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.004890919 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.004920959 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.005393028 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.005435944 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.005448103 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.005455971 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.005481005 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.005497932 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.005899906 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.005955935 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.005970955 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.005978107 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.006004095 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.006019115 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.006753922 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.006795883 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.006818056 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.006825924 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.006846905 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.006864071 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.006964922 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.007003069 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.007015944 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.007026911 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.007054090 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.007070065 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.007266045 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.007675886 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.007721901 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.007740974 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.007746935 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.007775068 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.096195936 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.096235037 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.096343994 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.096359968 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.096400023 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.096739054 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.096769094 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.096800089 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.096805096 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.096833944 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.096847057 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.097349882 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.097373962 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.097404957 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.097409964 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.097455025 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.097455025 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.097857952 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.097879887 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.097908020 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.097912073 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.097939968 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.097958088 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.098484993 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.098520041 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.098541021 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.098546028 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.098572969 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.098588943 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.099097013 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.099123955 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.099153996 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.099159956 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.099185944 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.099205017 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.099674940 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.099706888 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.099740028 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.099745035 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.099771023 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.099786997 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.099956989 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.099986076 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.100013018 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.100018024 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.100055933 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.100055933 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.117187977 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.188822031 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.188863039 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.188981056 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.189001083 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.189042091 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.189225912 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.189245939 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.189275980 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.189280987 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.189308882 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.189327955 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.189858913 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.189878941 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.189918041 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.189923048 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.189950943 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.189968109 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.190392017 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.190409899 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.190452099 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.190458059 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.190489054 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.190974951 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.190992117 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.191023111 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.191028118 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.191076994 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.191447020 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.191473961 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.191493988 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.191493988 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.191499949 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.191524982 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.191555023 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.192003965 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.192023039 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.192053080 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.192056894 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.192085028 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.192085981 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.192604065 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.192625999 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.192655087 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.192660093 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.192681074 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.192714930 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.192714930 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.281529903 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.281569004 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.281663895 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.281697989 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.281718016 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.281744003 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.281975031 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.281991959 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.282036066 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.282042027 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.282073975 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.282090902 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.282583952 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.282601118 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.282660007 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.282668114 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.282708883 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.283155918 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.283173084 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.283217907 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.283224106 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.283252954 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.283265114 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.283876896 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.283900976 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.283947945 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.283955097 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.283984900 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.284001112 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.284216881 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.284235001 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.284286976 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.284293890 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.284338951 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.284888029 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.284908056 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.284950972 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.284956932 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.284984112 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.285006046 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.285289049 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.285311937 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.285357952 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.285363913 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.285393953 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.285403967 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.374162912 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.374195099 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.374290943 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.374305964 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.374352932 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.374589920 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.374607086 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.374651909 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.374658108 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.374691010 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.375158072 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.375174046 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.375211000 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.375216961 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.375241041 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.375257015 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.375439882 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.375457048 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.375492096 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.375497103 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.375520945 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.375536919 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.376216888 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.376231909 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.376271963 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.376276970 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.376300097 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.376321077 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.376537085 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.376552105 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.376589060 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.376595020 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.376617908 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.376631975 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.377310991 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.377329111 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.377362967 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.377379894 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.377392054 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.377420902 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.377892971 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.377907991 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.377947092 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.377953053 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.377974987 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.377995968 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.467554092 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.467578888 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.467668056 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.467684984 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.467726946 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.467853069 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.467868090 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.467899084 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.467905045 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.467931986 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.467951059 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.468215942 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.468230963 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.468283892 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.468290091 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.468322992 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.468579054 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.468590975 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.468656063 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.468662024 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.468698025 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.468945980 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.468964100 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.469028950 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.469033957 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.469069004 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.469512939 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.469538927 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.469577074 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.469583988 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.469597101 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.469615936 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.469871998 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.469887018 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.469935894 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.469942093 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.469978094 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.470855951 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.470870972 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.470922947 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.470928907 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.470963955 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.559525013 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.559601068 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.559684992 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.559712887 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.559747934 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.559762955 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.559844017 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.559871912 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.559906960 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.559915066 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.559937000 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.559957981 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.560478926 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.560493946 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.560544014 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.560551882 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.560592890 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.560966969 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.560983896 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.561028957 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.561034918 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.561059952 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.561079979 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.561602116 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.561616898 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.561655998 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.561662912 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.561686993 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.561706066 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.561917067 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.561933041 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.561969995 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.561975002 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.561999083 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.562016010 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.562711000 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.562732935 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.562767029 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.562772989 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.562798023 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.562813997 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.563299894 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.563318014 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.563357115 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.563363075 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.563411951 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.563411951 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.652157068 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.652187109 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.652400970 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.652420998 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.652471066 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.652599096 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.652616024 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.652676105 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.652683020 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.652695894 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.652731895 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.653105021 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.653124094 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.653178930 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.653187037 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.653209925 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.653233051 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.653732061 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.653747082 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.653795958 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.653804064 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.653841972 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.654323101 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.654359102 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.654401064 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.654407978 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.654436111 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.654459953 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.654928923 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.654944897 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.654994011 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.654999971 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.655014992 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.655046940 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.655421019 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.655437946 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.655494928 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.655503035 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.655545950 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.656053066 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.656068087 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.656121969 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.656130075 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.656176090 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.744834900 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.744890928 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.744951010 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.744965076 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.744992971 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.745009899 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.745126963 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.745193005 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.745198965 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.745242119 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.745292902 CEST44349713188.114.97.3192.168.2.6
                      Sep 26, 2024 09:23:22.745342016 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:23:22.746695995 CEST49713443192.168.2.6188.114.97.3
                      Sep 26, 2024 09:24:07.496129990 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:07.501146078 CEST8049721193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:07.501265049 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:07.501533985 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:07.506416082 CEST8049721193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:07.957529068 CEST8049721193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:07.962793112 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:07.967720032 CEST8049721193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:08.067563057 CEST8049721193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:08.103247881 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.103281975 CEST44349722188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.104872942 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.109081030 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.109096050 CEST44349722188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.120100975 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:08.583930016 CEST44349722188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.584002972 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.586654902 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.586666107 CEST44349722188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.587068081 CEST44349722188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.635740995 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.644130945 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.691406965 CEST44349722188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.753200054 CEST44349722188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.753437042 CEST44349722188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.754168987 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.768476009 CEST49722443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.774626017 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:08.780647993 CEST8049721193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:08.875153065 CEST8049721193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:08.880737066 CEST49723443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.880779028 CEST44349723188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.881016016 CEST49723443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.881417036 CEST49723443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:08.881432056 CEST44349723188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:08.916987896 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:09.344171047 CEST44349723188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:09.385863066 CEST49723443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:09.403892994 CEST49723443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:09.403902054 CEST44349723188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:09.511673927 CEST44349723188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:09.511768103 CEST44349723188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:09.511873960 CEST49723443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:09.518909931 CEST49723443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:09.557792902 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:09.564141989 CEST8049721193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:09.565211058 CEST4972180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:09.566318989 CEST4972480192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:09.571927071 CEST8049724193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:09.573236942 CEST4972480192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:09.574687004 CEST4972480192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:09.579672098 CEST8049724193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:09.821667910 CEST4971080192.168.2.6188.114.97.3
                      Sep 26, 2024 09:24:10.036540985 CEST8049724193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:10.037786007 CEST49725443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:10.037826061 CEST44349725188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:10.037897110 CEST49725443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:10.038280010 CEST49725443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:10.038289070 CEST44349725188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:10.088998079 CEST4972480192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:10.509722948 CEST44349725188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:10.511091948 CEST49725443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:10.511127949 CEST44349725188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:10.659065008 CEST44349725188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:10.659168005 CEST44349725188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:10.659219980 CEST49725443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:10.659629107 CEST49725443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:10.662763119 CEST4972480192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:10.663999081 CEST4972780192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:10.667995930 CEST8049724193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:10.668049097 CEST4972480192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:10.668833971 CEST8049727193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:10.668891907 CEST4972780192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:10.668996096 CEST4972780192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:10.673855066 CEST8049727193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:11.135719061 CEST8049727193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:11.137037992 CEST49728443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:11.137080908 CEST44349728188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:11.137168884 CEST49728443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:11.137394905 CEST49728443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:11.137408972 CEST44349728188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:11.182593107 CEST4972780192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:11.597151041 CEST44349728188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:11.598499060 CEST49728443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:11.598516941 CEST44349728188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:11.746350050 CEST44349728188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:11.746464968 CEST44349728188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:11.746575117 CEST49728443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:11.747402906 CEST49728443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:11.751709938 CEST4972980192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:11.756724119 CEST8049729193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:11.756825924 CEST4972980192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:11.756902933 CEST4972980192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:11.761727095 CEST8049729193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:12.240467072 CEST8049729193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:12.241681099 CEST49730443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:12.241727114 CEST44349730188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:12.241889000 CEST49730443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:12.242167950 CEST49730443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:12.242183924 CEST44349730188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:12.291976929 CEST4972980192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:12.715090036 CEST44349730188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:12.719610929 CEST49730443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:12.719635963 CEST44349730188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:12.846224070 CEST44349730188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:12.846365929 CEST44349730188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:12.846457005 CEST49730443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:12.884553909 CEST49730443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:12.926213980 CEST4972980192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:12.926837921 CEST4973180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:12.932277918 CEST8049729193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:12.932351112 CEST4972980192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:12.932535887 CEST8049731193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:12.932635069 CEST4973180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:12.936882973 CEST4973180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:12.941739082 CEST8049731193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:13.423831940 CEST8049731193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:13.425425053 CEST49732443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:13.425544977 CEST44349732188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:13.425653934 CEST49732443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:13.425940990 CEST49732443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:13.425975084 CEST44349732188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:13.479664087 CEST4973180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:13.879364967 CEST44349732188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:13.881109953 CEST49732443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:13.881192923 CEST44349732188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:14.010689974 CEST44349732188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:14.010798931 CEST44349732188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:14.011059999 CEST49732443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:14.011594057 CEST49732443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:14.015115976 CEST4973180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:14.016176939 CEST4973380192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:14.020369053 CEST8049731193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:14.020467043 CEST4973180192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:14.021069050 CEST8049733193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:14.021158934 CEST4973380192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:14.021230936 CEST4973380192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:14.027554035 CEST8049733193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:14.543195963 CEST8049733193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:14.544373035 CEST49734443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:14.544430971 CEST44349734188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:14.544508934 CEST49734443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:14.544734955 CEST49734443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:14.544748068 CEST44349734188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:14.588974953 CEST4973380192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:15.026631117 CEST44349734188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:15.028023005 CEST49734443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:15.028039932 CEST44349734188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:15.155863047 CEST44349734188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:15.155987978 CEST44349734188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:15.156116962 CEST49734443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:15.156790972 CEST49734443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:15.160166979 CEST4973380192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:15.161300898 CEST4973580192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:15.165354013 CEST8049733193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:15.165443897 CEST4973380192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:15.166168928 CEST8049735193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:15.166237116 CEST4973580192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:15.166368008 CEST4973580192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:15.171145916 CEST8049735193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:16.007286072 CEST8049735193.122.130.0192.168.2.6
                      Sep 26, 2024 09:24:16.015923977 CEST49736443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:16.015968084 CEST44349736188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:16.016048908 CEST49736443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:16.016288042 CEST49736443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:16.016299963 CEST44349736188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:16.057693005 CEST4973580192.168.2.6193.122.130.0
                      Sep 26, 2024 09:24:16.500582933 CEST44349736188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:16.501952887 CEST49736443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:16.501982927 CEST44349736188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:16.652475119 CEST44349736188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:16.652570963 CEST44349736188.114.96.3192.168.2.6
                      Sep 26, 2024 09:24:16.652637005 CEST49736443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:24:16.653209925 CEST49736443192.168.2.6188.114.96.3
                      Sep 26, 2024 09:25:16.135379076 CEST8049727193.122.130.0192.168.2.6
                      Sep 26, 2024 09:25:16.135516882 CEST4972780192.168.2.6193.122.130.0
                      Sep 26, 2024 09:25:21.006797075 CEST8049735193.122.130.0192.168.2.6
                      Sep 26, 2024 09:25:21.006966114 CEST4973580192.168.2.6193.122.130.0
                      TimestampSource PortDest PortSource IPDest IP
                      Sep 26, 2024 09:23:17.120726109 CEST5329053192.168.2.61.1.1.1
                      Sep 26, 2024 09:23:17.129074097 CEST53532901.1.1.1192.168.2.6
                      Sep 26, 2024 09:23:19.827397108 CEST5032753192.168.2.61.1.1.1
                      Sep 26, 2024 09:23:19.837196112 CEST53503271.1.1.1192.168.2.6
                      Sep 26, 2024 09:24:07.483951092 CEST5580253192.168.2.61.1.1.1
                      Sep 26, 2024 09:24:07.490923882 CEST53558021.1.1.1192.168.2.6
                      Sep 26, 2024 09:24:08.092330933 CEST6187953192.168.2.61.1.1.1
                      Sep 26, 2024 09:24:08.101630926 CEST53618791.1.1.1192.168.2.6
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Sep 26, 2024 09:23:17.120726109 CEST192.168.2.61.1.1.10x3f79Standard query (0)filetransfer.ioA (IP address)IN (0x0001)false
                      Sep 26, 2024 09:23:19.827397108 CEST192.168.2.61.1.1.10x4b21Standard query (0)s24.filetransfer.ioA (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:07.483951092 CEST192.168.2.61.1.1.10x6429Standard query (0)checkip.dyndns.orgA (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:08.092330933 CEST192.168.2.61.1.1.10xdc4bStandard query (0)reallyfreegeoip.orgA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Sep 26, 2024 09:23:17.129074097 CEST1.1.1.1192.168.2.60x3f79No error (0)filetransfer.io188.114.97.3A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:23:17.129074097 CEST1.1.1.1192.168.2.60x3f79No error (0)filetransfer.io188.114.96.3A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:23:19.837196112 CEST1.1.1.1192.168.2.60x4b21No error (0)s24.filetransfer.io188.114.97.3A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:23:19.837196112 CEST1.1.1.1192.168.2.60x4b21No error (0)s24.filetransfer.io188.114.96.3A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:07.490923882 CEST1.1.1.1192.168.2.60x6429No error (0)checkip.dyndns.orgcheckip.dyndns.comCNAME (Canonical name)IN (0x0001)false
                      Sep 26, 2024 09:24:07.490923882 CEST1.1.1.1192.168.2.60x6429No error (0)checkip.dyndns.com193.122.130.0A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:07.490923882 CEST1.1.1.1192.168.2.60x6429No error (0)checkip.dyndns.com132.226.8.169A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:07.490923882 CEST1.1.1.1192.168.2.60x6429No error (0)checkip.dyndns.com193.122.6.168A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:07.490923882 CEST1.1.1.1192.168.2.60x6429No error (0)checkip.dyndns.com132.226.247.73A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:07.490923882 CEST1.1.1.1192.168.2.60x6429No error (0)checkip.dyndns.com158.101.44.242A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:08.101630926 CEST1.1.1.1192.168.2.60xdc4bNo error (0)reallyfreegeoip.org188.114.96.3A (IP address)IN (0x0001)false
                      Sep 26, 2024 09:24:08.101630926 CEST1.1.1.1192.168.2.60xdc4bNo error (0)reallyfreegeoip.org188.114.97.3A (IP address)IN (0x0001)false
                      • filetransfer.io
                      • s24.filetransfer.io
                      • reallyfreegeoip.org
                      • checkip.dyndns.org
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.649710188.114.97.3806044C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
                      TimestampBytes transferredDirectionData
                      Sep 26, 2024 09:23:17.143163919 CEST95OUTGET /data-package/Ky4pZ0WB/download HTTP/1.1
                      Host: filetransfer.io
                      Connection: Keep-Alive
                      Sep 26, 2024 09:23:17.800228119 CEST865INHTTP/1.1 301 Moved Permanently
                      Date: Thu, 26 Sep 2024 07:23:17 GMT
                      Content-Type: text/html
                      Transfer-Encoding: chunked
                      Connection: keep-alive
                      Location: https://filetransfer.io/data-package/Ky4pZ0WB/download
                      CF-Cache-Status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=7WhHY9JZ8Ms6FZAgThsge%2Fnn2z9jRNxxVEfJut4aShncyxmA%2FQ8%2FL314gGEa2NytyLDb4t%2FcZWbTTdODRZ182a5oWiguWGPIZHuCjscm0MLTdT1hU2fjuhAfzMn8WC8d%2BUY%3D"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Speculation-Rules: "/cdn-cgi/speculation"
                      Server: cloudflare
                      CF-RAY: 8c9181fab94b41a9-EWR
                      alt-svc: h3=":443"; ma=86400
                      Data Raw: 61 32 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 0d 0a 30 0d 0a 0d 0a
                      Data Ascii: a2<html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.649721193.122.130.0805792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      Sep 26, 2024 09:24:07.501533985 CEST151OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Connection: Keep-Alive
                      Sep 26, 2024 09:24:07.957529068 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:07 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: dbf3e777585df63960781e4d0245857d
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>
                      Sep 26, 2024 09:24:07.962793112 CEST127OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Sep 26, 2024 09:24:08.067563057 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:08 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: 5a38a1db8cfdbaa5b04755acf7c7b2bd
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>
                      Sep 26, 2024 09:24:08.774626017 CEST127OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Sep 26, 2024 09:24:08.875153065 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:08 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: 68adc3046578518187ca9cfe7ac4faa3
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.649724193.122.130.0805792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      Sep 26, 2024 09:24:09.574687004 CEST127OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Sep 26, 2024 09:24:10.036540985 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:09 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: 8f14e4c1f6620edd09ce24d250973583
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      3192.168.2.649727193.122.130.0805792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      Sep 26, 2024 09:24:10.668996096 CEST127OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Sep 26, 2024 09:24:11.135719061 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:11 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: 41d8bd33cb43474a9a1d196d32be88c4
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      4192.168.2.649729193.122.130.0805792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      Sep 26, 2024 09:24:11.756902933 CEST151OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Connection: Keep-Alive
                      Sep 26, 2024 09:24:12.240467072 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:12 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: 3b1377feceb8e7544638535b56a9899f
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      5192.168.2.649731193.122.130.0805792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      Sep 26, 2024 09:24:12.936882973 CEST151OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Connection: Keep-Alive
                      Sep 26, 2024 09:24:13.423831940 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:13 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: 27ea0d1929e975410390d23b4762e995
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      6192.168.2.649733193.122.130.0805792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      Sep 26, 2024 09:24:14.021230936 CEST151OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Connection: Keep-Alive
                      Sep 26, 2024 09:24:14.543195963 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:14 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: 9ed366a3925d47661488969f01e9de48
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      7192.168.2.649735193.122.130.0805792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      Sep 26, 2024 09:24:15.166368008 CEST151OUTGET / HTTP/1.1
                      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                      Host: checkip.dyndns.org
                      Connection: Keep-Alive
                      Sep 26, 2024 09:24:16.007286072 CEST320INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:15 GMT
                      Content-Type: text/html
                      Content-Length: 103
                      Connection: keep-alive
                      Cache-Control: no-cache
                      Pragma: no-cache
                      X-Request-ID: d7500d7690702ff196b3915550f9391e
                      Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                      Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 8.46.123.33</body></html>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.649711188.114.97.34436044C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:23:19 UTC95OUTGET /data-package/Ky4pZ0WB/download HTTP/1.1
                      Host: filetransfer.io
                      Connection: Keep-Alive
                      2024-09-26 07:23:19 UTC1074INHTTP/1.1 302 Found
                      Date: Thu, 26 Sep 2024 07:23:19 GMT
                      Content-Type: text/html; charset=utf-8
                      Transfer-Encoding: chunked
                      Connection: close
                      X-Powered-By: Nette Framework 3
                      X-Frame-Options: SAMEORIGIN
                      Set-Cookie: nette-samesite=1; path=/; SameSite=Strict; HttpOnly
                      Set-Cookie: PHPSESSID=fbegh31s08vkf5dnudmvb3pubr; expires=Thu, 10-Oct-2024 07:23:19 GMT; Max-Age=1209600; path=/; SameSite=Lax; secure; HttpOnly
                      Expires: Thu, 19 Nov 1981 08:52:00 GMT
                      Cache-Control: no-store, no-cache, must-revalidate
                      Pragma: no-cache
                      Vary: X-Requested-With
                      Location: https://s24.filetransfer.io/storage/download/klH4VFXHnzlT
                      CF-Cache-Status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=iSnyD%2BPCmD14U55oLw1KhMDJGzsqXeaX6ZEC9jNrzhf%2BNkTgCy%2F5pl4tshd32fNc%2F3eXnWu6ZiE3M0twBpe5gqxRTZAa5SCn%2F%2FfpeRD06Ci6j6UaKyVPTvomijs%2FjTz5uXo%3D"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Speculation-Rules: "/cdn-cgi/speculation"
                      Server: cloudflare
                      CF-RAY: 8c91820458d27c6a-EWR
                      2024-09-26 07:23:19 UTC134INData Raw: 38 30 0d 0a 3c 68 31 3e 52 65 64 69 72 65 63 74 3c 2f 68 31 3e 0a 0a 3c 70 3e 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 73 32 34 2e 66 69 6c 65 74 72 61 6e 73 66 65 72 2e 69 6f 2f 73 74 6f 72 61 67 65 2f 64 6f 77 6e 6c 6f 61 64 2f 6b 6c 48 34 56 46 58 48 6e 7a 6c 54 22 3e 50 6c 65 61 73 65 20 63 6c 69 63 6b 20 68 65 72 65 20 74 6f 20 63 6f 6e 74 69 6e 75 65 3c 2f 61 3e 2e 3c 2f 70 3e 0d 0a
                      Data Ascii: 80<h1>Redirect</h1><p><a href="https://s24.filetransfer.io/storage/download/klH4VFXHnzlT">Please click here to continue</a>.</p>
                      2024-09-26 07:23:19 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.649713188.114.97.34436044C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:23:20 UTC98OUTGET /storage/download/klH4VFXHnzlT HTTP/1.1
                      Host: s24.filetransfer.io
                      Connection: Keep-Alive
                      2024-09-26 07:23:21 UTC1026INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:23:21 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 2054144
                      Connection: close
                      Last-Modified: Wed, 25 Sep 2024 07:31:09 GMT
                      Set-Cookie: nette-samesite=1; path=/; SameSite=Strict; HttpOnly
                      Set-Cookie: PHPSESSID=50d5196d52eadc458faa37754a3a999a; expires=Thu, 10-Oct-2024 07:23:20 GMT; Max-Age=1209600; path=/; SameSite=Lax; secure; HttpOnly
                      Expires: Thu, 19 Nov 1981 08:52:00 GMT
                      Cache-Control: no-store, no-cache, must-revalidate
                      Content-Disposition: attachment; filename="Vdaykckgctm.wav"
                      Accept-Ranges: bytes
                      Accept-Ranges: bytes
                      ETag: "66f3bc3d-1f5800"
                      CF-Cache-Status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8X30q8iH9GCNq0UAY6N%2Ft8acvXhw0PrYWItvxW7ghrgKJzZZOPCgsY3q3vr8xQmpN6x5dnbC4JzpbUH9SP7s0I3H%2FkqaFXVXT36nRblG9idJJyfwOXyf4HsY8LL0F5OKClMmiTPV"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c91820caab4447a-EWR
                      2024-09-26 07:23:21 UTC343INData Raw: 34 44 35 41 39 30 30 30 30 33 30 30 30 30 30 30 30 34 30 30 30 30 30 30 46 46 46 46 30 30 30 30 42 38 30 30 30 30 30 30 30 30 30 30 30 30 30 30 34 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 38 30 30 30 30 30 30 30 30 45 31 46 42 41 30 45 30 30 42 34 30 39 43 44 32 31 42 38 30 31 34 43 43 44 32 31 35 34 36 38 36 39 37 33 32 30 37 30 37 32 36 46 36 37 37 32 36 31 36 44 32 30 36 33 36 31 36 45 36 45 36 46 37 34 32 30 36 32 36 35 32 30 37 32 37 35 36 45 32 30 36 39 36 45 32 30 34 34 34 46 35 33 32 30 36 44 36 46 36 34 36 35 32 45 30 44 30 44 30 41 32 34 30 30 30 30 30 30 30 30 30 30 30 30 30
                      Data Ascii: 4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000800000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A240000000000000
                      2024-09-26 07:23:21 UTC1369INData Raw: 30 30 30 32 30 30 30 30 30 30 30 45 30 30 46 30 30 30 30 30 30 34 30 30 30 30 30 32 30 30 30 30 30 30 30 30 32 30 30 30 30 30 34 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 34 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 32 30 31 30 30 30 30 30 30 32 30 30 30 30 30 30 30 30 30 30 30 30 30 33 30 30 34 30 38 35 30 30 30 30 31 30 30 30 30 30 31 30 30 30 30 30 30 30 30 30 31 30 30 30 30 30 31 30 30 30 30 30 30 30 30 30 30 30 30 30 30 46 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 43 32 30 46 30 30 34 42 30 30 30 30 30 30 30 30 45 30 30 46 30 30 32 34 30 33 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 31 30 30 30 30 43 30 30 30 30 30 30 30 30 30 30 30 30
                      Data Ascii: 00020000000E00F00000040000020000000020000040000000000000004000000000000000020100000020000000000000300408500001000001000000000100000100000000000000F000000000000000000000000C20F004B00000000E00F002403000000000000000000000000000000000000000010000C000000000000
                      2024-09-26 07:23:21 UTC1369INData Raw: 30 30 32 38 39 33 30 34 30 30 30 36 32 41 30 30 33 41 32 42 30 35 32 38 36 39 33 31 33 39 33 31 30 30 32 38 34 37 30 33 30 30 30 36 32 41 30 30 34 32 32 42 30 35 32 38 42 30 31 45 32 45 33 34 37 45 30 31 30 30 30 30 30 34 31 34 46 45 30 31 32 41 30 30 30 30 30 30 33 36 32 42 30 35 32 38 36 38 45 43 35 45 36 35 37 45 30 31 30 30 30 30 30 34 32 41 30 30 30 30 31 33 33 30 30 33 30 30 30 34 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 32 41 31 33 33 30 30 33 30 30 38 30 30 30 30 30 30 30 30 31 30 30 30 30 31 31 32 38 39 32 30 33 30 30 30 36 32 30 30 31 30 30 30 30 30 30 46 45 30 45 30 30 30 30 33 38 30 30 30 30 30 30 30 30 46 45 30 43 30 30 30 30 34 35 30 33 30 30 30 30 30 30 30 35 30 30 30 30 30 30 32 45 30 30 30 30 30 30 35 37 30 30 30 30 30
                      Data Ascii: 0028930400062A003A2B0528693139310028470300062A00422B0528B01E2E347E0100000414FE012A000000362B052868EC5E657E010000042A00001330030004000000000000000000002A13300300800000000100001128920300062001000000FE0E00003800000000FE0C00004503000000050000002E0000005700000
                      2024-09-26 07:23:21 UTC1369INData Raw: 32 30 30 30 30 31 37 32 41 30 30 30 30 30 30 31 32 30 30 30 30 31 34 32 41 30 30 30 30 30 30 30 33 33 30 30 38 30 30 30 34 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 31 37 32 41 34 31 31 43 30 30 30 30 30 30 30 30 30 30 30 30 37 42 30 30 30 30 30 30 32 42 30 33 30 30 30 30 41 36 30 33 30 30 30 30 33 39 30 30 30 30 30 30 31 37 30 30 30 30 30 31 30 33 33 30 30 38 30 30 30 34 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 31 37 32 41 34 31 31 43 30 30 30 30 30 30 30 30 30 30 30 30 34 41 30 30 30 30 30 30 37 42 30 31 30 30 30 30 43 35 30 31 30 30 30 30 33 39 30 30 30 30 30 30 31 37 30 30 30 30 30 31 31 33 33 30 30 33 30 30 30 34 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 31 37 32 41 31 33 33 30 30 33 30 30 30 34 30 30 30 30 30 30
                      Data Ascii: 20000172A000000120000142A0000000330080004000000000000000000172A411C0000000000007B0000002B030000A603000039000000170000010330080004000000000000000000172A411C0000000000004A0000007B010000C501000039000000170000011330030004000000000000000000172A1330030004000000
                      2024-09-26 07:23:21 UTC1369INData Raw: 41 32 46 46 46 46 46 46 32 36 32 30 30 30 30 30 30 30 30 30 33 38 39 37 46 46 46 46 46 46 31 32 30 30 30 30 31 37 32 41 30 30 30 30 30 30 31 32 30 30 30 30 31 34 32 41 30 30 30 30 30 30 31 33 33 30 30 34 30 30 38 31 30 45 30 30 30 30 30 31 30 30 30 30 31 31 32 38 39 32 30 33 30 30 30 36 32 30 31 42 30 30 30 30 30 30 46 45 30 45 30 30 30 30 33 38 30 30 30 30 30 30 30 30 46 45 30 43 30 30 30 30 34 35 32 36 30 30 30 30 30 30 42 41 30 32 30 30 30 30 42 32 30 41 30 30 30 30 35 32 30 34 30 30 30 30 44 41 30 42 30 30 30 30 43 38 30 30 30 30 30 30 34 34 30 43 30 30 30 30 37 38 30 39 30 30 30 30 34 42 30 32 30 30 30 30 45 37 30 39 30 30 30 30 45 42 30 31 30 30 30 30 37 33 30 44 30 30 30 30 32 46 30 33 30 30 30 30 32 42 30 38 30 30 30 30 33 43 30 41 30 30 30 30 31
                      Data Ascii: A2FFFFFF2620000000003897FFFFFF120000172A000000120000142A00000013300400810E0000010000112892030006201B000000FE0E00003800000000FE0C00004526000000BA020000B20A000052040000DA0B0000C8000000440C0000780900004B020000E7090000EB010000730D00002F0300002B0800003C0A00001
                      2024-09-26 07:23:21 UTC1369INData Raw: 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 38 30 36 30 30 30 30 32 42 38 30 34 30 30 30 30 30 30 34 32 30 31 37 30 30 30 30 30 30 33 38 37 38 46 44 46 46 46 46 32 30 42 39 32 46 43 39 33 30 32 30 30 33 30 30 30 30 30 30 36 32 32 30 46 31 38 39 34 36 46 41 36 31 37 45 35 39 30 32 30 30 30 34 37 42 35 37 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 30 42 35 30 38 37 46 32 43 32 30 43 30 35 32 37 36 34 38 36 31 32 30 33 39 46 37 31 42 37 36 36 31 37 45 35 39 30 32 30 30 30 34 37 42 37 33 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 38 30 37 30 30 30 30 32 42 38 30 32 42 30 30 30 30 30 34 32 30 31 38 30 30 30 30 30 30 33 38 31 38 46 44 46 46 46 46 32 30 37 39
                      Data Ascii: EBA020004285A090006280600002B804000000420170000003878FDFFFF20B92FC93020030000006220F18946FA617E590200047B57020004617EBA020004285A09000620B5087F2C20C0527648612039F71B76617E590200047B73020004617EBA020004285A090006280700002B802B00000420180000003818FDFFFF2079
                      2024-09-26 07:23:21 UTC1369INData Raw: 32 38 39 34 41 35 32 30 44 36 46 35 35 38 43 31 36 31 37 45 35 39 30 32 30 30 30 34 37 42 36 35 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 38 30 44 30 30 30 30 32 42 38 30 33 38 30 30 30 30 30 34 32 30 30 30 30 30 30 30 30 30 37 45 35 39 30 32 30 30 30 34 37 42 36 39 30 32 30 30 30 34 33 41 41 44 46 41 46 46 46 46 32 36 32 30 30 30 30 30 30 30 30 30 33 38 41 32 46 41 46 46 46 46 32 30 31 34 30 32 37 37 41 34 32 30 31 32 43 34 38 43 38 30 36 31 37 45 35 39 30 32 30 30 30 34 37 42 35 30 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 30 33 37 37 42 42 38 36 44 32 30 45 46 37 37 35 38 37 36 36 31 37 45 35 39 30 32 30 30 30 34 37 42 36 39 30 32 30 30 30 34 36 31 37 45 42 41 30
                      Data Ascii: 2894A520D6F558C1617E590200047B65020004617EBA020004285A090006280D00002B803800000420000000007E590200047B690200043AADFAFFFF26200000000038A2FAFFFF20140277A42012C48C80617E590200047B50020004617EBA020004285A09000620377BB86D20EF775876617E590200047B69020004617EBA0
                      2024-09-26 07:23:21 UTC1369INData Raw: 46 46 46 32 36 32 30 30 38 30 30 30 30 30 30 33 38 33 30 46 38 46 46 46 46 32 30 41 38 35 42 37 44 46 33 32 30 38 42 33 37 44 31 42 42 36 31 37 45 35 39 30 32 30 30 30 34 37 42 33 34 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 30 32 44 31 32 35 41 39 45 32 30 46 30 35 31 45 45 31 44 36 31 32 30 34 41 31 42 46 39 41 34 36 31 37 45 35 39 30 32 30 30 30 34 37 42 34 45 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 38 31 34 30 30 30 30 32 42 38 30 33 42 30 30 30 30 30 34 32 30 30 33 30 30 30 30 30 30 37 45 35 39 30 32 30 30 30 34 37 42 36 37 30 32 30 30 30 34 33 41 43 43 46 37 46 46 46 46 32 36 32 30 30 35 30 30 30 30 30 30 33 38 43 31 46 37 46 46 46 46 37 45 39 35 30 32 30 30
                      Data Ascii: FFF2620080000003830F8FFFF20A85B7DF3208B37D1BB617E590200047B34020004617EBA020004285A090006202D125A9E20F051EE1D61204A1BF9A4617E590200047B4E020004617EBA020004285A090006281400002B803B00000420030000007E590200047B670200043ACCF7FFFF26200500000038C1F7FFFF7E950200
                      2024-09-26 07:23:21 UTC1369INData Raw: 37 31 30 32 30 30 30 34 33 41 38 37 46 35 46 46 46 46 32 36 32 30 31 39 30 30 30 30 30 30 33 38 37 43 46 35 46 46 46 46 32 30 39 45 43 44 43 39 32 36 36 36 32 30 30 42 31 38 46 45 39 44 36 31 37 45 35 39 30 32 30 30 30 34 37 42 38 41 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 30 44 36 32 36 43 41 46 33 32 30 41 44 32 34 32 38 43 34 36 31 37 45 35 39 30 32 30 30 30 34 37 42 32 43 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 38 31 41 30 30 30 30 32 42 38 30 32 44 30 30 30 30 30 34 32 30 30 34 30 30 30 30 30 30 33 38 32 37 46 35 46 46 46 46 32 41 32 30 38 41 32 38 44 31 45 30 32 30 41 38 38 37 37 41 45 30 35 39 32 30 45 35 46 41 31 42 32 37 36 31 37 45 35 39 30 32 30 30 30
                      Data Ascii: 710200043A87F5FFFF262019000000387CF5FFFF209ECDC92666200B18FE9D617E590200047B8A020004617EBA020004285A09000620D626CAF320AD2428C4617E590200047B2C020004617EBA020004285A090006281A00002B802D00000420040000003827F5FFFF2A208A28D1E020A8877AE05920E5FA1B27617E5902000
                      2024-09-26 07:23:21 UTC1369INData Raw: 38 35 41 30 39 30 30 30 36 32 38 32 30 30 30 30 30 32 42 38 30 33 43 30 30 30 30 30 34 32 30 31 44 30 30 30 30 30 30 46 45 30 45 30 30 30 30 33 38 43 33 46 32 46 46 46 46 32 30 41 36 42 45 31 31 46 34 32 30 30 41 38 45 41 34 41 37 36 31 37 45 35 39 30 32 30 30 30 34 37 42 38 35 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 30 45 37 39 33 30 35 34 41 32 30 44 30 31 30 34 46 35 43 36 31 37 45 35 39 30 32 30 30 30 34 37 42 36 43 30 32 30 30 30 34 36 31 37 45 42 41 30 32 30 30 30 34 32 38 35 41 30 39 30 30 30 36 32 38 32 31 30 30 30 30 32 42 38 30 33 46 30 30 30 30 30 34 32 30 32 30 30 30 30 30 30 30 37 45 35 39 30 32 30 30 30 34 37 42 32 46 30 32 30 30 30 34 33 41 36 39 46 32 46 46 46 46 32 36 32 30 31 37 30 30 30 30
                      Data Ascii: 85A090006282000002B803C000004201D000000FE0E000038C3F2FFFF20A6BE11F4200A8EA4A7617E590200047B85020004617EBA020004285A09000620E793054A20D0104F5C617E590200047B6C020004617EBA020004285A090006282100002B803F00000420200000007E590200047B2F0200043A69F2FFFF2620170000


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.649722188.114.96.34435792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:24:08 UTC84OUTGET /xml/8.46.123.33 HTTP/1.1
                      Host: reallyfreegeoip.org
                      Connection: Keep-Alive
                      2024-09-26 07:24:08 UTC704INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:08 GMT
                      Content-Type: application/xml
                      Transfer-Encoding: chunked
                      Connection: close
                      access-control-allow-origin: *
                      vary: Accept-Encoding
                      Cache-Control: max-age=86400
                      CF-Cache-Status: HIT
                      Age: 280
                      Last-Modified: Thu, 26 Sep 2024 07:19:28 GMT
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=aXloarF3RbMQilrS%2FImJp6bp8eDY1cXbIegED1lQv5S30ypeF3ZjR5BfKjq1D5Wt%2FcpE35ZIHyoVsRAxGG6BFV3Pc04XtguDoqaxq89vsoWygzXTFqXq%2FiGzm0ryVJbPiI7TynzT"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c91833a59590f6b-EWR
                      alt-svc: h3=":443"; ma=86400
                      2024-09-26 07:24:08 UTC340INData Raw: 31 34 64 0d 0a 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 37 2e 37 35
                      Data Ascii: 14d<Response><IP>8.46.123.33</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode></RegionCode><RegionName></RegionName><City></City><ZipCode></ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>37.75
                      2024-09-26 07:24:08 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      3192.168.2.649723188.114.96.34435792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:24:09 UTC60OUTGET /xml/8.46.123.33 HTTP/1.1
                      Host: reallyfreegeoip.org
                      2024-09-26 07:24:09 UTC680INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:09 GMT
                      Content-Type: application/xml
                      Transfer-Encoding: chunked
                      Connection: close
                      access-control-allow-origin: *
                      vary: Accept-Encoding
                      Cache-Control: max-age=86400
                      CF-Cache-Status: HIT
                      Age: 281
                      Last-Modified: Thu, 26 Sep 2024 07:19:28 GMT
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=waryFBPtQICSGKEwv6lHxy1GaM5J3Qq5B7cppgMfvL7YVBzGHpvx6XcoeLH5qYal%2F93Dh%2BsZFvjGmEHpMkyp7s0Co2jmbbvukkEVGI4%2BePI%2BQRwq%2Bxe3VwGF2Sri%2BLpLPJRrK7kU"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c91833f1a960f37-EWR
                      2024-09-26 07:24:09 UTC340INData Raw: 31 34 64 0d 0a 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 37 2e 37 35
                      Data Ascii: 14d<Response><IP>8.46.123.33</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode></RegionCode><RegionName></RegionName><City></City><ZipCode></ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>37.75
                      2024-09-26 07:24:09 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      4192.168.2.649725188.114.96.34435792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:24:10 UTC84OUTGET /xml/8.46.123.33 HTTP/1.1
                      Host: reallyfreegeoip.org
                      Connection: Keep-Alive
                      2024-09-26 07:24:10 UTC672INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:10 GMT
                      Content-Type: application/xml
                      Transfer-Encoding: chunked
                      Connection: close
                      access-control-allow-origin: *
                      vary: Accept-Encoding
                      Cache-Control: max-age=86400
                      CF-Cache-Status: HIT
                      Age: 282
                      Last-Modified: Thu, 26 Sep 2024 07:19:28 GMT
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=B7G4FM61WjR0vqhzY62bLuhqQXsbSrfXgKAG%2FuIF8jJsTZRW14HM8rNAEDHipHNQ2pc0yrtcWiBqlFHWxOUz5s2ieMMPXiQMSqxT6exnELXYiKkobbX%2BECTOEQpbRWWhYOg4Bl0Z"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c9183464bf88c17-EWR
                      2024-09-26 07:24:10 UTC340INData Raw: 31 34 64 0d 0a 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 37 2e 37 35
                      Data Ascii: 14d<Response><IP>8.46.123.33</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode></RegionCode><RegionName></RegionName><City></City><ZipCode></ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>37.75
                      2024-09-26 07:24:10 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      5192.168.2.649728188.114.96.34435792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:24:11 UTC84OUTGET /xml/8.46.123.33 HTTP/1.1
                      Host: reallyfreegeoip.org
                      Connection: Keep-Alive
                      2024-09-26 07:24:11 UTC680INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:11 GMT
                      Content-Type: application/xml
                      Transfer-Encoding: chunked
                      Connection: close
                      access-control-allow-origin: *
                      vary: Accept-Encoding
                      Cache-Control: max-age=86400
                      CF-Cache-Status: HIT
                      Age: 283
                      Last-Modified: Thu, 26 Sep 2024 07:19:28 GMT
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=bbqbNPsDSZGP80Hk5x3yoEujg%2Bd6YntGzhztKNdNQXfdPH%2FZcUNDZs%2FthBWKBilznSo7c%2BS8C1eGSujT5UEVSw9J6Wir71c%2BcPsIsNZ9HpFfGMReE6sfwFAEkR6ck1sXf%2BaWHI4K"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c91834d0c3b0cc4-EWR
                      2024-09-26 07:24:11 UTC340INData Raw: 31 34 64 0d 0a 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 37 2e 37 35
                      Data Ascii: 14d<Response><IP>8.46.123.33</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode></RegionCode><RegionName></RegionName><City></City><ZipCode></ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>37.75
                      2024-09-26 07:24:11 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      6192.168.2.649730188.114.96.34435792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:24:12 UTC60OUTGET /xml/8.46.123.33 HTTP/1.1
                      Host: reallyfreegeoip.org
                      2024-09-26 07:24:12 UTC678INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:12 GMT
                      Content-Type: application/xml
                      Transfer-Encoding: chunked
                      Connection: close
                      access-control-allow-origin: *
                      vary: Accept-Encoding
                      Cache-Control: max-age=86400
                      CF-Cache-Status: HIT
                      Age: 284
                      Last-Modified: Thu, 26 Sep 2024 07:19:28 GMT
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XFdRDiRzzrRestbKxGeSSVnUa4w39bao6SwK%2B1Qe0fYJu1EzAEQEKv%2BLwEQHXpYo7KE62BcCj%2B6FCxttkUi1GOIbXNBHixLUct3YnlT%2FjJAL5HxBDvBd%2BqSuKCKrtQLnqU7nDsGF"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c918353e90115cb-EWR
                      2024-09-26 07:24:12 UTC340INData Raw: 31 34 64 0d 0a 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 37 2e 37 35
                      Data Ascii: 14d<Response><IP>8.46.123.33</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode></RegionCode><RegionName></RegionName><City></City><ZipCode></ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>37.75
                      2024-09-26 07:24:12 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      7192.168.2.649732188.114.96.34435792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:24:13 UTC60OUTGET /xml/8.46.123.33 HTTP/1.1
                      Host: reallyfreegeoip.org
                      2024-09-26 07:24:14 UTC680INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:13 GMT
                      Content-Type: application/xml
                      Transfer-Encoding: chunked
                      Connection: close
                      access-control-allow-origin: *
                      vary: Accept-Encoding
                      Cache-Control: max-age=86400
                      CF-Cache-Status: HIT
                      Age: 285
                      Last-Modified: Thu, 26 Sep 2024 07:19:28 GMT
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=RYe1QC%2BzfK%2BekJCUnshOdNRdHl8oBxmOK4BeevMlBngE0haHOmQmDmnvDRlxooG%2BeMKHVFD7L03y%2FRO3bTx1c31g%2FQBcJh6twOjJrCLvwMmiCAboS83cdYE1iMTCAxySMOC%2BiIcR"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c91835b39650caa-EWR
                      2024-09-26 07:24:14 UTC340INData Raw: 31 34 64 0d 0a 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 37 2e 37 35
                      Data Ascii: 14d<Response><IP>8.46.123.33</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode></RegionCode><RegionName></RegionName><City></City><ZipCode></ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>37.75
                      2024-09-26 07:24:14 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      8192.168.2.649734188.114.96.34435792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:24:15 UTC84OUTGET /xml/8.46.123.33 HTTP/1.1
                      Host: reallyfreegeoip.org
                      Connection: Keep-Alive
                      2024-09-26 07:24:15 UTC672INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:15 GMT
                      Content-Type: application/xml
                      Transfer-Encoding: chunked
                      Connection: close
                      access-control-allow-origin: *
                      vary: Accept-Encoding
                      Cache-Control: max-age=86400
                      CF-Cache-Status: HIT
                      Age: 287
                      Last-Modified: Thu, 26 Sep 2024 07:19:28 GMT
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=93BOAGbpHIaQsldSp2neInXwgEVdmEuNSYDGljkyK2lb6aFSpMR6JqM6lXBTdBC8XUX4%2FspwUFBDqOimphAx9NfawhubYrTABf4jBUL9k7AKzIKs%2B99DdnmEiWna4baWJh3ZIXNa"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c9183625a08431c-EWR
                      2024-09-26 07:24:15 UTC340INData Raw: 31 34 64 0d 0a 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 37 2e 37 35
                      Data Ascii: 14d<Response><IP>8.46.123.33</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode></RegionCode><RegionName></RegionName><City></City><ZipCode></ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>37.75
                      2024-09-26 07:24:15 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      9192.168.2.649736188.114.96.34435792C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      TimestampBytes transferredDirectionData
                      2024-09-26 07:24:16 UTC84OUTGET /xml/8.46.123.33 HTTP/1.1
                      Host: reallyfreegeoip.org
                      Connection: Keep-Alive
                      2024-09-26 07:24:16 UTC690INHTTP/1.1 200 OK
                      Date: Thu, 26 Sep 2024 07:24:16 GMT
                      Content-Type: application/xml
                      Transfer-Encoding: chunked
                      Connection: close
                      access-control-allow-origin: *
                      vary: Accept-Encoding
                      Cache-Control: max-age=86400
                      CF-Cache-Status: HIT
                      Age: 288
                      Last-Modified: Thu, 26 Sep 2024 07:19:28 GMT
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=wl13hnLw5Qo%2FiwYv%2BaCG%2B3VJ7RBA7EJ2nXIclZ%2Ff8vMuOYZ%2Bj%2FwT6yRMV%2F2K20dHRtxys%2Bs8MNy6kHZTO3ly9%2FW%2B8vSL17y7GnLasArrpfPov4BxJV1NKObgEHY%2FsQAv76Mvyc0h"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8c91836bbe4e437f-EWR
                      2024-09-26 07:24:16 UTC340INData Raw: 31 34 64 0d 0a 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 38 2e 34 36 2e 31 32 33 2e 33 33 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 37 2e 37 35
                      Data Ascii: 14d<Response><IP>8.46.123.33</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode></RegionCode><RegionName></RegionName><City></City><ZipCode></ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>37.75
                      2024-09-26 07:24:16 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Click to jump to process

                      Click to jump to process

                      Click to dive into process behavior distribution

                      Click to jump to process

                      Target ID:0
                      Start time:03:23:15
                      Start date:26/09/2024
                      Path:C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe"
                      Imagebase:0x28acc6c0000
                      File size:361'472 bytes
                      MD5 hash:631691DCA7ABC573A0CC911B2DDCA40E
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: Windows_Trojan_Donutloader_f40e3759, Description: unknown, Source: 00000000.00000002.2646867703.0000028ACEA50000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.2665435188.0000028AE6E50000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_Donutloader_f40e3759, Description: unknown, Source: 00000000.00000002.2653955478.0000028ADE5A0000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.2646867703.0000028ACE51D000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.2653955478.0000028ADF002000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      Reputation:low
                      Has exited:true

                      Target ID:5
                      Start time:03:24:06
                      Start date:26/09/2024
                      Path:C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe"
                      Imagebase:0x22933f90000
                      File size:55'824 bytes
                      MD5 hash:DF5419B32657D2896514B6A1D041FE08
                      Has elevated privileges:false
                      Has administrator privileges:false
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, Author: unknown
                      • Rule: MAL_Envrial_Jan18_1, Description: Detects Encrial credential stealer malware, Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, Author: Florian Roth
                      • Rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook, Description: Detects executables with potential process hoocking, Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, Author: ditekSHen
                      • Rule: MALWARE_Win_SnakeKeylogger, Description: Detects Snake Keylogger, Source: 00000005.00000002.3401415580.0000022934340000.00000004.08000000.00040000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000005.00000002.3402009366.0000022935F56000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: MALWARE_Win_SnakeKeylogger, Description: Detects Snake Keylogger, Source: 00000005.00000002.3404892860.0000022945D19000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: Windows_Trojan_Donutloader_f40e3759, Description: unknown, Source: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                      • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000005.00000002.3402009366.0000022935D11000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      Reputation:moderate
                      Has exited:false

                      Target ID:6
                      Start time:03:24:06
                      Start date:26/09/2024
                      Path:C:\Windows\System32\conhost.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Imagebase:0x7ff66e660000
                      File size:862'208 bytes
                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                      Has elevated privileges:false
                      Has administrator privileges:false
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Reset < >

                        Execution Graph

                        Execution Coverage:5.1%
                        Dynamic/Decrypted Code Coverage:33.3%
                        Signature Coverage:0%
                        Total number of Nodes:3
                        Total number of Limit Nodes:0
                        execution_graph 22333 7ffd34964fc5 22334 7ffd34964fdf SleepEx 22333->22334 22336 7ffd349650cc 22334->22336

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 0 7ffd349504ca-7ffd34950549 7 7ffd3495058a-7ffd3495059e 0->7 8 7ffd3495054b-7ffd3495059e 0->8 9 7ffd349505a5-7ffd349506d9 7->9 8->9 40 7ffd349506db-7ffd349506f1 9->40 41 7ffd34950718-7ffd349507c6 9->41 52 7ffd349507c7-7ffd349507d1 41->52 53 7ffd3495080f-7ffd34950819 52->53 54 7ffd3495081e-7ffd34950820 53->54 55 7ffd34950822 54->55 56 7ffd349507dc-7ffd349507f9 54->56 57 7ffd34950831 55->57 56->57 63 7ffd349507fb-7ffd34950801 56->63 57->52 58 7ffd34950833-7ffd34950870 57->58 67 7ffd34950807-7ffd3495080a 58->67 69 7ffd34950873-7ffd34950889 58->69 63->67 67->53 69->54 71 7ffd3495088b-7ffd349508c6 69->71 74 7ffd349508cb-7ffd349508dd 71->74 75 7ffd349508c8-7ffd349508c9 71->75 77 7ffd3495092d-7ffd3495093d 74->77 78 7ffd349508df-7ffd349508e7 74->78 75->74 84 7ffd3495093f-7ffd34950954 77->84 85 7ffd34950958-7ffd3495095e 77->85 79 7ffd34950922-7ffd34950928 78->79 80 7ffd349508e9-7ffd349508ec 78->80 83 7ffd34950e33-7ffd34950e45 79->83 80->79 82 7ffd349508ee-7ffd349508f9 80->82 87 7ffd349508fb-7ffd34950916 82->87 86 7ffd34950e46-7ffd34950e59 83->86 84->85 88 7ffd34950964-7ffd34950978 85->88 89 7ffd34950c99-7ffd34950ca0 85->89 98 7ffd3495091d 87->98 88->89 90 7ffd34950ca2-7ffd34950ca5 89->90 91 7ffd34950ca7-7ffd34950cb3 call 7ffd34950200 89->91 93 7ffd34950cb5-7ffd34950cb8 90->93 91->93 96 7ffd34950cba-7ffd34950cc0 93->96 97 7ffd34950cc5-7ffd34950ccd 93->97 96->86 99 7ffd34950cd3-7ffd34950cf0 97->99 100 7ffd34950e2d 97->100 98->86 102 7ffd34950cf2-7ffd34950d02 99->102 103 7ffd34950d17-7ffd34950d22 99->103 100->83 102->103 110 7ffd34950d04-7ffd34950d12 102->110 104 7ffd34950de2-7ffd34950de5 103->104 105 7ffd34950d28-7ffd34950d2d 103->105 104->100 109 7ffd34950de7-7ffd34950ded 104->109 107 7ffd34950d34-7ffd34950d37 105->107 108 7ffd34950d2f 105->108 111 7ffd34950d39-7ffd34950d43 107->111 112 7ffd34950d47-7ffd34950d4a 107->112 108->107 113 7ffd34950def-7ffd34950df4 109->113 114 7ffd34950df6 109->114 110->103 111->112 116 7ffd34950d9a-7ffd34950d9d 112->116 117 7ffd34950d4c-7ffd34950d4f 112->117 115 7ffd34950dfb-7ffd34950e2b 113->115 114->115 115->86 119 7ffd34950d9f-7ffd34950da8 116->119 120 7ffd34950daa-7ffd34950daf 116->120 121 7ffd34950d71-7ffd34950d74 117->121 122 7ffd34950d51-7ffd34950d6b 117->122 125 7ffd34950db3-7ffd34950de0 call 7ffd349501b8 119->125 120->125 123 7ffd34950d84-7ffd34950d8a 121->123 124 7ffd34950d76-7ffd34950d7c 121->124 122->121 131 7ffd34950e5a-7ffd34950e8b 122->131 123->116 128 7ffd34950d8c-7ffd34950d96 123->128 124->123 126 7ffd34950d7e-7ffd34950d81 124->126 125->86 126->123 128->116 136 7ffd34950e8d-7ffd34950ea5 131->136 137 7ffd34950ea7-7ffd34950ed0 131->137 140 7ffd34950ed2-7ffd34950f44 136->140 137->140 145 7ffd34950f49-7ffd34950fab 140->145 146 7ffd34950f46-7ffd34950f48 140->146 150 7ffd34950fb2-7ffd34950fcd 145->150 146->145 151 7ffd34950fd4-7ffd34950ff6 150->151
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2670862828.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34950000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: 1_^$1_^$>1_^$@
                        • API String ID: 0-1515930842
                        • Opcode ID: bc96bb313c3826fedb7a51c940ebf95068f4f74381a969ab651b1ef431c7a085
                        • Instruction ID: d87d408442d39b4fd117c885a5a1b7640e7d59622b153e0c6af50b218bea004f
                        • Opcode Fuzzy Hash: bc96bb313c3826fedb7a51c940ebf95068f4f74381a969ab651b1ef431c7a085
                        • Instruction Fuzzy Hash: C5424B32B0C7465FE351AB6894A62FA3BD0EF43314F2901BED58DC7193DE2CA8468791
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2670862828.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34950000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: $ 1_H
                        • API String ID: 0-1116767729
                        • Opcode ID: 968a7e3f37a2b205bd1ec0301ce3de9f551efce5b4ac30d511b2201994422ab2
                        • Instruction ID: 05e09c612212830feec02fb3e072b5b1e8d486bec4e99bd60896fb509eb9a90c
                        • Opcode Fuzzy Hash: 968a7e3f37a2b205bd1ec0301ce3de9f551efce5b4ac30d511b2201994422ab2
                        • Instruction Fuzzy Hash: A472F631B08A494FEBA5EB2CC4A6A6437D1FF5A300B2401FED54DCB2A6DE2CEC459751

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1909 7ffd34958f08-7ffd34958f23 1911 7ffd34958f35-7ffd34958f39 1909->1911 1912 7ffd34958f25-7ffd34958f2e 1909->1912 1913 7ffd34958f3b-7ffd34958f46 1911->1913 1914 7ffd34958f47-7ffd34958f54 1911->1914 1912->1911 1915 7ffd34958f5a-7ffd34958f69 1914->1915 1916 7ffd34959218-7ffd3495925a 1914->1916 1917 7ffd34958f6b-7ffd34958f77 1915->1917 1918 7ffd34958f78-7ffd34958f81 1915->1918 1927 7ffd3495925c-7ffd34959274 1916->1927 1928 7ffd34959276-7ffd3495927f 1916->1928 1919 7ffd34959131-7ffd34959158 1918->1919 1920 7ffd34958f87-7ffd34958f93 1918->1920 1930 7ffd3495915f-7ffd34959168 1919->1930 1920->1916 1923 7ffd34958f99-7ffd34958fae 1920->1923 1925 7ffd34958fbd-7ffd34958fc1 1923->1925 1926 7ffd34958fb0-7ffd34958fbc 1923->1926 1925->1930 1931 7ffd34958fc7-7ffd34958fd3 1925->1931 1933 7ffd3495929b-7ffd349592b6 1927->1933 1932 7ffd34959281-7ffd34959298 1928->1932 1928->1933 1951 7ffd3495918d-7ffd349591b4 1930->1951 1931->1916 1935 7ffd34958fd9-7ffd34958fee 1931->1935 1932->1933 1937 7ffd349592de-7ffd349592e0 1933->1937 1938 7ffd349592b8-7ffd349592bf 1933->1938 1943 7ffd34958ff0-7ffd34958ff5 1935->1943 1944 7ffd34958ffa-7ffd34958ffe 1935->1944 1940 7ffd349592e2-7ffd349592e5 1937->1940 1941 7ffd34959303-7ffd34959305 1937->1941 1938->1937 1939 7ffd349592c1-7ffd349592c5 1938->1939 1939->1937 1940->1941 1946 7ffd349592e7-7ffd34959301 1940->1946 1947 7ffd3495930b-7ffd34959315 1941->1947 1948 7ffd34959307-7ffd34959309 1941->1948 1949 7ffd34959129-7ffd34959130 1943->1949 1950 7ffd34959004-7ffd34959010 1944->1950 1944->1951 1946->1941 1962 7ffd349592c7-7ffd349592d5 1946->1962 1948->1947 1952 7ffd34959316-7ffd34959355 1948->1952 1950->1916 1953 7ffd34959016-7ffd3495902b 1950->1953 1961 7ffd349591bb-7ffd349591e2 1951->1961 1979 7ffd34959359-7ffd3495937f 1952->1979 1980 7ffd34959357 1952->1980 1957 7ffd3495902d-7ffd34959032 1953->1957 1958 7ffd34959037-7ffd3495903b 1953->1958 1957->1949 1960 7ffd34959041-7ffd34959048 1958->1960 1958->1961 1960->1916 1963 7ffd3495904e-7ffd34959065 1960->1963 1971 7ffd349591e9-7ffd34959217 1961->1971 1962->1937 1964 7ffd349592d7-7ffd349592db 1962->1964 1968 7ffd34959071-7ffd34959073 1963->1968 1969 7ffd34959067-7ffd3495906c 1963->1969 1964->1937 1968->1971 1972 7ffd34959079-7ffd3495907f 1968->1972 1969->1949 1971->1916 1972->1971 1974 7ffd34959085-7ffd34959089 1972->1974 1974->1971 1977 7ffd3495908f-7ffd3495909f 1974->1977 1977->1916 1981 7ffd349590a5-7ffd349590ae 1977->1981 1988 7ffd3495939a-7ffd349593b3 1979->1988 1990 7ffd34959381-7ffd34959397 1979->1990 1980->1979 1983 7ffd34959399 1980->1983 1981->1971 1985 7ffd349590b4-7ffd349590bc 1981->1985 1983->1988 1985->1916 1989 7ffd349590c2-7ffd349590cb 1985->1989 1991 7ffd34959451-7ffd34959471 1988->1991 1992 7ffd349593b9-7ffd349593c6 1988->1992 1989->1971 1993 7ffd349590d1-7ffd349590d9 1989->1993 1990->1983 2001 7ffd34959495-7ffd349594ad 1991->2001 2002 7ffd349593e4-7ffd349593e7 1992->2002 2003 7ffd349593c8-7ffd349593d9 1992->2003 1993->1916 1997 7ffd349590df-7ffd349590e8 1993->1997 1997->1971 2000 7ffd349590ee-7ffd349590f6 1997->2000 2000->1916 2004 7ffd349590fc-7ffd34959105 2000->2004 2012 7ffd349594b0-7ffd349594cc 2001->2012 2013 7ffd349594af 2001->2013 2002->2001 2005 7ffd349593ed-7ffd34959435 2002->2005 2007 7ffd349593de-7ffd349593e2 2003->2007 2004->1971 2006 7ffd3495910b-7ffd34959110 2004->2006 2005->2001 2010 7ffd34959437-7ffd3495943b 2005->2010 2006->1916 2008 7ffd34959116-7ffd3495911e 2006->2008 2007->2010 2008->1971 2011 7ffd34959124 2008->2011 2016 7ffd34959442-7ffd34959450 2010->2016 2011->1949 2017 7ffd349594d2-7ffd349594d8 2012->2017 2018 7ffd34959569-7ffd3495959c 2012->2018 2013->2012 2020 7ffd349594da-7ffd349594dd 2017->2020 2021 7ffd349594f8-7ffd34959506 2017->2021 2027 7ffd349595a3-7ffd349595cd 2018->2027 2023 7ffd349594df-7ffd349594f7 2020->2023 2024 7ffd34959525-7ffd34959530 2020->2024 2021->2027 2028 7ffd3495950c-7ffd34959524 2021->2028 2024->2018 2033 7ffd349595cf-7ffd349595e6 2027->2033 2034 7ffd349595ed-7ffd349595ef 2033->2034 2035 7ffd349595f1-7ffd34959609 2034->2035 2036 7ffd3495960a-7ffd34959615 2034->2036
                        Memory Dump Source
                        • Source File: 00000000.00000002.2670862828.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34950000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: eb54aaf4173b675efb964f224ca0111025bbede65dfb4b4f1d0e6b38ff0a6cc9
                        • Instruction ID: a6e1664c1d11e6b2e4091fa24f87e4f6fb381ca4b130a722624020a680017fbb
                        • Opcode Fuzzy Hash: eb54aaf4173b675efb964f224ca0111025bbede65dfb4b4f1d0e6b38ff0a6cc9
                        • Instruction Fuzzy Hash: 03222731B0CB8A4FF7689B2C94A41B577D1FF56314F2406BED58AC72D6DE2CA8429B40

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2155 7ffd34954829-7ffd3495482d 2156 7ffd34954832-7ffd34954857 2155->2156 2157 7ffd3495482f-7ffd34954831 2155->2157 2159 7ffd34954859-7ffd34954875 2156->2159 2160 7ffd3495487a-7ffd3495487e 2156->2160 2157->2156 2165 7ffd34954986-7ffd34954988 2159->2165 2161 7ffd34954880-7ffd349548e5 call 7ffd34951d70 call 7ffd34951540 2160->2161 2162 7ffd349548ea-7ffd349548f7 2160->2162 2161->2165 2168 7ffd3495491d-7ffd34954984 call 7ffd34951d70 call 7ffd34951540 2162->2168 2169 7ffd349548f9-7ffd349548fd 2162->2169 2170 7ffd349549ed-7ffd349549f2 2165->2170 2171 7ffd3495498a-7ffd349549e8 call 7ffd34952a60 call 7ffd34951540 2165->2171 2168->2165 2169->2168 2173 7ffd349548ff-7ffd34954914 2169->2173 2175 7ffd349549f4-7ffd349549fe 2170->2175 2176 7ffd34954a36-7ffd34954a3d 2170->2176 2171->2170 2181 7ffd3495491b 2173->2181 2175->2176 2180 7ffd34954a00-7ffd34954a07 2175->2180 2184 7ffd34954a3e-7ffd34954a4f 2180->2184 2185 7ffd34954a09-7ffd34954a34 2180->2185 2181->2165 2193 7ffd34954a91-7ffd34954a99 2184->2193 2194 7ffd34954a51-7ffd34954a69 2184->2194 2185->2176 2185->2180 2205 7ffd34954af2-7ffd34954b02 2193->2205 2206 7ffd34954a9b-7ffd34954a9f 2193->2206 2199 7ffd34954ab3-7ffd34954ab8 2194->2199 2200 7ffd34954a6b-7ffd34954a8e 2194->2200 2208 7ffd34954b29-7ffd34954b2c 2199->2208 2209 7ffd34954aba-7ffd34954abc 2199->2209 2200->2193 2213 7ffd34954b04-7ffd34954b10 2205->2213 2206->2205 2215 7ffd34954aa1-7ffd34954ab2 2206->2215 2212 7ffd34954b2e-7ffd34954b34 2208->2212 2210 7ffd34954abe 2209->2210 2211 7ffd34954b38-7ffd34954b43 2209->2211 2210->2213 2216 7ffd34954ac0-7ffd34954ac4 2210->2216 2221 7ffd34954b45-7ffd34954b87 2211->2221 2217 7ffd34954b35-7ffd34954b37 2212->2217 2224 7ffd34954b11-7ffd34954b12 2213->2224 2215->2199 2216->2217 2220 7ffd34954ac6-7ffd34954ac9 2216->2220 2217->2211 2220->2221 2223 7ffd34954acb 2220->2223 2234 7ffd34954bc9-7ffd34954bf1 call 7ffd349516c0 2221->2234 2235 7ffd34954b89-7ffd34954b98 2221->2235 2223->2224 2225 7ffd34954acd-7ffd34954af1 2223->2225 2227 7ffd34954b14-7ffd34954b24 2224->2227 2228 7ffd34954b25-7ffd34954b26 2224->2228 2228->2208 2240 7ffd34954bf2-7ffd34954bf5 2234->2240 2242 7ffd34954c62-7ffd34954c6d 2234->2242 2235->2212 2237 7ffd34954b99-7ffd34954ba8 2235->2237 2237->2240 2241 7ffd34954baa-7ffd34954bc6 2237->2241 2245 7ffd34954c71 2240->2245 2246 7ffd34954bf7 2240->2246 2243 7ffd34954c2b-7ffd34954c3b 2241->2243 2244 7ffd34954bc8 2241->2244 2247 7ffd34954c6e 2242->2247 2248 7ffd34954c3d-7ffd34954c49 2243->2248 2244->2234 2250 7ffd34954c72 2245->2250 2251 7ffd34954c73-7ffd34954c7d 2245->2251 2246->2248 2249 7ffd34954bf9-7ffd34954bfd 2246->2249 2247->2245 2253 7ffd34954c4a 2248->2253 2254 7ffd34954c4b-7ffd34954c5e 2248->2254 2249->2247 2255 7ffd34954bff-7ffd34954c02 2249->2255 2250->2251 2256 7ffd34954c7e 2251->2256 2257 7ffd34954c7f-7ffd34954c8b 2251->2257 2253->2254 2254->2242 2255->2256 2258 7ffd34954c04 2255->2258 2256->2257 2258->2253 2260 7ffd34954c06-7ffd34954c2a 2258->2260
                        Memory Dump Source
                        • Source File: 00000000.00000002.2670862828.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34950000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: baa84753f79a25ff16eeb22c89a17eeae1cc514fc879bd228ac0324685c79d6f
                        • Instruction ID: 3ec87b00d3d14d8e1a6567a52ec5a95783d190927402fc31ecf61f282c5206a9
                        • Opcode Fuzzy Hash: baa84753f79a25ff16eeb22c89a17eeae1cc514fc879bd228ac0324685c79d6f
                        • Instruction Fuzzy Hash: 43020531B0CA4A8FE7A5DB2C84A576977E1EF9A300B1401FED14DCB296DE2CEC429751

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 844 7ffd348b153b-7ffd348b1541 845 7ffd348b14cd-7ffd348b1519 844->845 846 7ffd348b1543-7ffd348b15b7 844->846 851 7ffd348b15b9 846->851 852 7ffd348b15be-7ffd348b15d6 846->852 851->852 854 7ffd348b1c28-7ffd348b1c2c 852->854 855 7ffd348b1c33-7ffd348b1c40 854->855 856 7ffd348b1c46-7ffd348b1c4b 855->856 857 7ffd348b15db-7ffd348b15df 855->857 860 7ffd348b1c8a-7ffd348b1c99 856->860 861 7ffd348b1c4d-7ffd348b1c87 856->861 858 7ffd348b15e7-7ffd348b15ec 857->858 859 7ffd348b15e1-7ffd348b16ac 857->859 864 7ffd348b165b-7ffd348b1680 858->864 865 7ffd348b15ee-7ffd348b15fd 858->865 871 7ffd348b16ae-7ffd348b177c 859->871 872 7ffd348b16b4-7ffd348b16b9 859->872 867 7ffd348b1cbb-7ffd348b1cd2 860->867 868 7ffd348b1c9b-7ffd348b1ca5 860->868 861->860 881 7ffd348b1684-7ffd348b169a 864->881 877 7ffd348b1625-7ffd348b1636 865->877 878 7ffd348b15ff-7ffd348b1604 865->878 882 7ffd348b177e-7ffd348b184c 871->882 883 7ffd348b1784-7ffd348b1789 871->883 875 7ffd348b1728-7ffd348b174d 872->875 876 7ffd348b16bb-7ffd348b16c0 872->876 886 7ffd348b1751-7ffd348b176f 875->886 880 7ffd348b16c2-7ffd348b16d1 876->880 877->881 896 7ffd348b1637-7ffd348b1658 877->896 878->864 884 7ffd348b1606-7ffd348b1623 878->884 880->875 914 7ffd348b16d3-7ffd348b1701 880->914 881->880 897 7ffd348b169c-7ffd348b16a3 881->897 894 7ffd348b184e-7ffd348b191c 882->894 895 7ffd348b1854-7ffd348b1859 882->895 891 7ffd348b17f8-7ffd348b1843 883->891 892 7ffd348b178b-7ffd348b179a 883->892 884->877 938 7ffd348b1771 886->938 891->854 900 7ffd348b179c-7ffd348b17a1 892->900 901 7ffd348b17c0-7ffd348b17f5 892->901 910 7ffd348b191e-7ffd348b1a08 894->910 911 7ffd348b1924-7ffd348b1929 894->911 904 7ffd348b18c8-7ffd348b1913 895->904 905 7ffd348b185b-7ffd348b1871 895->905 896->864 897->854 900->891 909 7ffd348b17a3-7ffd348b17ae 900->909 901->891 904->854 905->904 920 7ffd348b1873-7ffd348b18c5 905->920 927 7ffd348b17b0-7ffd348b17b7 909->927 928 7ffd348b17bd-7ffd348b17bf 909->928 931 7ffd348b1a0a-7ffd348b1af4 910->931 932 7ffd348b1a10-7ffd348b1a15 910->932 921 7ffd348b192f-7ffd348b1945 911->921 922 7ffd348b19ae-7ffd348b19ff 911->922 947 7ffd348b1703 914->947 920->904 921->922 937 7ffd348b1947-7ffd348b19ab 921->937 922->854 927->928 928->901 951 7ffd348b1af6-7ffd348b1bde 931->951 952 7ffd348b1afc-7ffd348b1b01 931->952 940 7ffd348b1a1b-7ffd348b1a31 932->940 941 7ffd348b1a9a-7ffd348b1ab5 932->941 937->922 938->947 948 7ffd348b1772-7ffd348b1773 938->948 940->941 956 7ffd348b1a33-7ffd348b1a92 940->956 954 7ffd348b1ab6-7ffd348b1aeb 941->954 947->886 957 7ffd348b1704-7ffd348b1727 947->957 948->854 962 7ffd348b1be0-7ffd348b1c1a 951->962 963 7ffd348b1c1d-7ffd348b1c21 951->963 959 7ffd348b1b07-7ffd348b1b1d 952->959 960 7ffd348b1b86-7ffd348b1b95 952->960 954->854 956->954 992 7ffd348b1a94-7ffd348b1a97 956->992 957->875 957->938 959->960 968 7ffd348b1b1f-7ffd348b1b83 959->968 971 7ffd348b1b97-7ffd348b1bb6 960->971 972 7ffd348b1bb8-7ffd348b1bd7 960->972 962->963 963->854 968->960 971->972 972->854 992->941
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2668081571.00007FFD348B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD348B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd348b0000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: &;_H
                        • API String ID: 0-3372723638
                        • Opcode ID: 27a368a76e762ae5f9030d160468eb44e4838556f31ebb56856323f29a208b65
                        • Instruction ID: bff32cbc16e509220d323d083b9778cb6b993d31771ed431de6d66c9d15d1f93
                        • Opcode Fuzzy Hash: 27a368a76e762ae5f9030d160468eb44e4838556f31ebb56856323f29a208b65
                        • Instruction Fuzzy Hash: ED527F71E08A5E8FEB90DB18C8E56A977F1FF5A340F140276C54DE7291DE38B8859B80

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 995 7ffd34964fc5-7ffd349650ca SleepEx 1000 7ffd349650d2-7ffd34965126 995->1000 1001 7ffd349650cc 995->1001 1001->1000
                        APIs
                        Memory Dump Source
                        • Source File: 00000000.00000002.2670862828.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34950000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID: Sleep
                        • String ID:
                        • API String ID: 3472027048-0
                        • Opcode ID: b45c97005f38a20ddfb3cf00d2d4ff399a13c9cf44a76364a930df64937ba7eb
                        • Instruction ID: b5cae4f15db915e5c2ce65bd8b4873feedc605ee21d628569047dc43d7ebd1db
                        • Opcode Fuzzy Hash: b45c97005f38a20ddfb3cf00d2d4ff399a13c9cf44a76364a930df64937ba7eb
                        • Instruction Fuzzy Hash: 9E412A70908A1D8FDB94DF98D885BEDBBF1FB69310F10826AD04DE3255DB35A895CB40

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1004 7ffd34798bd3-7ffd34798bd8 1005 7ffd34798c35-7ffd34798cdf 1004->1005 1006 7ffd34798bda-7ffd34798bf1 1004->1006 1014 7ffd34798ce6 call 7ffd34794298 1005->1014 1015 7ffd34798ce1 1005->1015 1006->1005 1017 7ffd34798ceb-7ffd34798cf8 1014->1017 1015->1014 1019 7ffd34798cfb-7ffd34798cff 1017->1019 1020 7ffd34798d1c-7ffd34798df1 call 7ffd34798b78 1019->1020 1021 7ffd34798d01-7ffd34798d5a call 7ffd34798b70 1019->1021 1020->1019 1031 7ffd34798df7-7ffd34798dfc 1020->1031 1021->1019 1033 7ffd34798d5c-7ffd34798d61 1021->1033 1031->1019 1033->1019
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: L_^
                        • API String ID: 0-925995230
                        • Opcode ID: ff3bb8df321d1acf440a88675cc070097b6c9cef5c76b27bdd2642adcba73d97
                        • Instruction ID: 9bce86cd7971e2d155114a6b0b62a0a084bcbfb2d1a3932dc579bbc496ed2a0d
                        • Opcode Fuzzy Hash: ff3bb8df321d1acf440a88675cc070097b6c9cef5c76b27bdd2642adcba73d97
                        • Instruction Fuzzy Hash: 5C41B972A1D6868FE7029B6888A51ED7BA0AF17304F0A01F6D598DB193DB3C7509DBC1

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1050 7ffd34798c25-7ffd34798cdf 1059 7ffd34798ce6 call 7ffd34794298 1050->1059 1060 7ffd34798ce1 1050->1060 1062 7ffd34798ceb-7ffd34798cf8 1059->1062 1060->1059 1064 7ffd34798cfb-7ffd34798cff 1062->1064 1065 7ffd34798d1c-7ffd34798df1 call 7ffd34798b78 1064->1065 1066 7ffd34798d01-7ffd34798d5a call 7ffd34798b70 1064->1066 1065->1064 1076 7ffd34798df7-7ffd34798dfc 1065->1076 1066->1064 1078 7ffd34798d5c-7ffd34798d61 1066->1078 1076->1064 1078->1064
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: L_^
                        • API String ID: 0-925995230
                        • Opcode ID: c9d35934cd28762d7c7db93f51426ee162bf55988191fa991a7858ef914f1c9d
                        • Instruction ID: e642b94fdfad9f3093e616b1bfa39b229e99d92440b4eafe6177b714cb6cb0df
                        • Opcode Fuzzy Hash: c9d35934cd28762d7c7db93f51426ee162bf55988191fa991a7858ef914f1c9d
                        • Instruction Fuzzy Hash: 1E31A672A1D6868FE3039B68D8651E97BB1EF17314F0A01F6D594CB1A3EE2C6509CBC1

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1079 7ffd3479bf9d-7ffd3479bfbd call 7ffd34794038 call 7ffd34794040 1083 7ffd3479bfc2-7ffd3479bfcf 1079->1083 1084 7ffd3479bfd5-7ffd3479bfdf 1083->1084 1085 7ffd3479aa0f-7ffd3479aa4c call 7ffd34794048 call 7ffd347941a8 1083->1085 1086 7ffd34799664-7ffd3479966e 1084->1086 1085->1086 1100 7ffd3479aa52-7ffd3479aa5c 1085->1100 1089 7ffd3479968e-7ffd3479d529 1086->1089 1090 7ffd34799670-7ffd3479acf4 1086->1090 1093 7ffd3479d52b 1089->1093 1094 7ffd3479d530-7ffd3479d562 call 7ffd347941a8 1089->1094 1097 7ffd3479acf6 1090->1097 1098 7ffd3479acfb-7ffd3479ad2d call 7ffd347941a8 1090->1098 1093->1094 1094->1086 1103 7ffd3479d568-7ffd3479d572 1094->1103 1097->1098 1098->1086 1105 7ffd3479ad33-7ffd3479ad3d 1098->1105 1100->1086 1103->1086 1105->1086
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: R
                        • API String ID: 0-1466425173
                        • Opcode ID: 8f8c4304d05e43290a78128a1f0e37e829c54dd2f57fc143179a2430ce7f2622
                        • Instruction ID: be7636f4b5ea866211b6fd4afefa5c7b6a084b4d6368ecb7b81d1ab129b5ef68
                        • Opcode Fuzzy Hash: 8f8c4304d05e43290a78128a1f0e37e829c54dd2f57fc143179a2430ce7f2622
                        • Instruction Fuzzy Hash: 6D11ECB1E08659CFEB60DB14C8987A8B7B1EF56315F1006FAD10DE7291DE782AC49F41

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2038 7ffd348b200d-7ffd348b20a7 2039 7ffd348b20a9 2038->2039 2040 7ffd348b20ae-7ffd348b20c6 2038->2040 2039->2040 2042 7ffd348b257c-7ffd348b2594 2040->2042 2044 7ffd348b20cb-7ffd348b20cf 2042->2044 2045 7ffd348b259a-7ffd348b259f 2042->2045 2048 7ffd348b20d4-7ffd348b20d9 2044->2048 2049 7ffd348b20d1-7ffd348b213e 2044->2049 2046 7ffd348b25de-7ffd348b25f9 2045->2046 2047 7ffd348b25a1-7ffd348b25db 2045->2047 2047->2046 2052 7ffd348b20db-7ffd348b2109 2048->2052 2053 7ffd348b210c-7ffd348b2110 2048->2053 2055 7ffd348b2140-7ffd348b21c3 2049->2055 2056 7ffd348b2143-7ffd348b2148 2049->2056 2052->2053 2058 7ffd348b2117-7ffd348b2135 2053->2058 2063 7ffd348b21c8-7ffd348b21cd 2055->2063 2064 7ffd348b21c5-7ffd348b2232 2055->2064 2060 7ffd348b217b-7ffd348b217f 2056->2060 2061 7ffd348b214a-7ffd348b2178 2056->2061 2058->2042 2067 7ffd348b2186-7ffd348b218f 2060->2067 2061->2060 2070 7ffd348b21cf-7ffd348b21fd 2063->2070 2071 7ffd348b2200-7ffd348b2229 2063->2071 2074 7ffd348b2237-7ffd348b223c 2064->2074 2075 7ffd348b2234-7ffd348b229b 2064->2075 2079 7ffd348b2197-7ffd348b21a8 2067->2079 2070->2071 2071->2042 2081 7ffd348b226f-7ffd348b2273 2074->2081 2082 7ffd348b223e-7ffd348b2249 2074->2082 2085 7ffd348b229d-7ffd348b2324 2075->2085 2086 7ffd348b22a3-7ffd348b22a8 2075->2086 2083 7ffd348b21b9-7ffd348b21ba 2079->2083 2084 7ffd348b21aa-7ffd348b21b2 2079->2084 2090 7ffd348b227a-7ffd348b2292 2081->2090 2095 7ffd348b224b 2082->2095 2096 7ffd348b224d-7ffd348b226c 2082->2096 2083->2042 2084->2083 2098 7ffd348b2326-7ffd348b23ad 2085->2098 2099 7ffd348b232c-7ffd348b2331 2085->2099 2093 7ffd348b22e7-7ffd348b2309 2086->2093 2094 7ffd348b22aa-7ffd348b22b5 2086->2094 2090->2042 2109 7ffd348b230b-7ffd348b2313 2093->2109 2110 7ffd348b231a-7ffd348b231b 2093->2110 2106 7ffd348b22b7 2094->2106 2107 7ffd348b22b9-7ffd348b22e4 2094->2107 2095->2096 2096->2081 2111 7ffd348b23b5-7ffd348b23ba 2098->2111 2112 7ffd348b23af-7ffd348b2436 2098->2112 2104 7ffd348b2370-7ffd348b2392 2099->2104 2105 7ffd348b2333-7ffd348b236d 2099->2105 2120 7ffd348b23a3-7ffd348b23a4 2104->2120 2121 7ffd348b2394-7ffd348b239c 2104->2121 2105->2104 2106->2107 2107->2093 2109->2110 2110->2042 2117 7ffd348b23bc-7ffd348b23f6 2111->2117 2118 7ffd348b23f9-7ffd348b241b 2111->2118 2122 7ffd348b2438-7ffd348b24bf 2112->2122 2123 7ffd348b243e-7ffd348b2443 2112->2123 2117->2118 2131 7ffd348b242c-7ffd348b242d 2118->2131 2132 7ffd348b241d-7ffd348b2425 2118->2132 2120->2042 2121->2120 2133 7ffd348b24c4-7ffd348b24c9 2122->2133 2134 7ffd348b24c1-7ffd348b2532 2122->2134 2129 7ffd348b2445-7ffd348b247f 2123->2129 2130 7ffd348b2482-7ffd348b24a4 2123->2130 2129->2130 2142 7ffd348b24b5-7ffd348b24b6 2130->2142 2143 7ffd348b24a6-7ffd348b24ae 2130->2143 2131->2042 2132->2131 2140 7ffd348b2508-7ffd348b252b 2133->2140 2141 7ffd348b24cb-7ffd348b2505 2133->2141 2144 7ffd348b2534-7ffd348b253f 2134->2144 2145 7ffd348b2571-7ffd348b2575 2134->2145 2140->2042 2141->2140 2142->2042 2143->2142 2144->2145 2145->2042
                        Memory Dump Source
                        • Source File: 00000000.00000002.2668081571.00007FFD348B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD348B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd348b0000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 18379e8f2e917ffb03d686e323891c07e2fafed740818017c8d098715b6c6b97
                        • Instruction ID: bd48410eafc170ef6c6cb1402ffd04b883bd962a36449658449840b08b56ae53
                        • Opcode Fuzzy Hash: 18379e8f2e917ffb03d686e323891c07e2fafed740818017c8d098715b6c6b97
                        • Instruction Fuzzy Hash: ED22F870E0961E8FEBA4EB58C4A97AD77B1FF5A301F5001B9D509E3295CF786881DB80
                        Memory Dump Source
                        • Source File: 00000000.00000002.2668081571.00007FFD348B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD348B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd348b0000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f92228e4c328847883cd66545bc33969f9157af4fc1b660a2b917da5e2fdd783
                        • Instruction ID: 494e0461d9289459f838660eb0df281aa9e804abcaf758c93f66b5117514c136
                        • Opcode Fuzzy Hash: f92228e4c328847883cd66545bc33969f9157af4fc1b660a2b917da5e2fdd783
                        • Instruction Fuzzy Hash: 3CB16C70E08A5E8FEB94DB68C8A56ED7BB1FF5A340F140179D509E7292CF786841DB80
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6279cff456929fb492b040f0751098209da866c65d3a52012cb9cc973fcac026
                        • Instruction ID: 9f27661ebe3828baac497bb0d71ce909da9ae77821aec23e9b4f226549b4111f
                        • Opcode Fuzzy Hash: 6279cff456929fb492b040f0751098209da866c65d3a52012cb9cc973fcac026
                        • Instruction Fuzzy Hash: 41912AB3B0855A9BD751FBACE8A76FE77A0EF0231CF0402B2D148D7183ED1864558785
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4dd23dde1f0efaf6d25463e81968fa77fcb6c38fa3edba324b35955a2da911bc
                        • Instruction ID: c1a324055ca684613c487a6ac01eb9426f18b718932aa4c9bcbc012b42e90502
                        • Opcode Fuzzy Hash: 4dd23dde1f0efaf6d25463e81968fa77fcb6c38fa3edba324b35955a2da911bc
                        • Instruction Fuzzy Hash: 96915D57A0D5A76BE721B7F8B8B75FE3B54CF0323DB0842B7E1CC990939D1820958295
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7da9c53d6cd42dcd12980134b9622e2d8fe39b9d5a428646b9d5084d4fd572f5
                        • Instruction ID: 628a7ed89a6c766895adb90a6b649f82587b4724158e2f4304cb0046894f6d09
                        • Opcode Fuzzy Hash: 7da9c53d6cd42dcd12980134b9622e2d8fe39b9d5a428646b9d5084d4fd572f5
                        • Instruction Fuzzy Hash: E3412832B0C55A8FD700EBA8D4A26FE7BA1EF87355F080176C64DD7282CA296545C7E1
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 25a56dcd77e0704188a2cc849b2a2b2c0fa08ce08cab7d0d7a8c666ae3a1eef8
                        • Instruction ID: 52278fbb8ad19c9f6279f6e6265058da6205319b9b71ac33ee678c9491f45c26
                        • Opcode Fuzzy Hash: 25a56dcd77e0704188a2cc849b2a2b2c0fa08ce08cab7d0d7a8c666ae3a1eef8
                        • Instruction Fuzzy Hash: 68417E57A0D5976BEB2277F864B61FE7FA4DF03228B0C42B3E0CC98093DD1864998285
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6bfcd0c24800ef0e2603d1ca53a6e6421666f98531e756f5442bedea12764804
                        • Instruction ID: aa12201fc59bdd3ce4c689425c5f9b4b7fa0d2fed8a185dbfc10dde75e03ec7f
                        • Opcode Fuzzy Hash: 6bfcd0c24800ef0e2603d1ca53a6e6421666f98531e756f5442bedea12764804
                        • Instruction Fuzzy Hash: 48414F70A1895DCFDB84EF58C494AEDBBF1FF59310F1440AAD159E7292CB39A841CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4dfe673a33bde214d90a0a8e855b9d99e8bcf1398e12f9dda8a07ba47662289f
                        • Instruction ID: c8b2492c69692c2c7cf71b5a141a19b0548119a9026b7d70a8ffb77efe4f7e0f
                        • Opcode Fuzzy Hash: 4dfe673a33bde214d90a0a8e855b9d99e8bcf1398e12f9dda8a07ba47662289f
                        • Instruction Fuzzy Hash: 39414E70A1894D8FDB95EF98C4A4AEDBBF1FF59300F14017AD449E7391CA34A881CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ff46e3f3e2168626316dc31d4278f5e30024a0f4c8caf60d798c430cf3cb8d85
                        • Instruction ID: 5203baa1ed8b5297aa45ae58e03323c39b8beae0f56abaa258a98f52670d4427
                        • Opcode Fuzzy Hash: ff46e3f3e2168626316dc31d4278f5e30024a0f4c8caf60d798c430cf3cb8d85
                        • Instruction Fuzzy Hash: D8417F71B1894D8FEB94EBA8C4657EE77E1FF59300F040575E50DE7292CE38A8418790
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1d2de1999f069cd6c7367fdea193416687f64891d2217b7e0f28cf6f93e94797
                        • Instruction ID: 484f6710c8d908664fe06dcfb01bb05f0bb8d7e192308e93ec9722dd64c54e0f
                        • Opcode Fuzzy Hash: 1d2de1999f069cd6c7367fdea193416687f64891d2217b7e0f28cf6f93e94797
                        • Instruction Fuzzy Hash: AF418371A1854D8FEB95EB68C8656EEB7F1FF45300F0405B6E449E7292CE28AC40C791
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d858e80d11fea40c31e1a981c235f2037bb93f197020a512c5ffda20478602cd
                        • Instruction ID: 1e3e023f0991a9922c09fe12d1ef0212b5922eccd244ae9643655187ac4a8d83
                        • Opcode Fuzzy Hash: d858e80d11fea40c31e1a981c235f2037bb93f197020a512c5ffda20478602cd
                        • Instruction Fuzzy Hash: 7A11AF71B0C54A8FDB54DB68C4A16FFBBA1EF87311F0401BAD149E6682CA38689497D1
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: de1dede56137b9fc27aac7be28356ff63fe8d445b10c2e0e70c678b074c7779e
                        • Instruction ID: f4b96b108944f1195363eea9603d1542b5b33b84a9e58c51a66b395aa9bbce2e
                        • Opcode Fuzzy Hash: de1dede56137b9fc27aac7be28356ff63fe8d445b10c2e0e70c678b074c7779e
                        • Instruction Fuzzy Hash: D9119A72A18A4D8FDF80EF5CC899AEE37F0FF6A315F000066E409D3251DA34A444CB80
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1e0cce0088c1b51e14d58c60df0693d8bf0b64a7121767002442c86903104d27
                        • Instruction ID: 8a70b659ea4f0dfa3e1b37a3f2d3d46b57a49d131deaa855b8d9a582d5f79e0e
                        • Opcode Fuzzy Hash: 1e0cce0088c1b51e14d58c60df0693d8bf0b64a7121767002442c86903104d27
                        • Instruction Fuzzy Hash: 51118231A0855DCFDB54EF99D4556FF77B4EB85311F04053AE509E2290CA38A994DBC0
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 850b9cb466d677ff00d8b55372f21189bc731a9e522cac9c840b57d9a4461268
                        • Instruction ID: 41a3db7b2d81fc7934e9f5d4512edfa3b6c0abef53c932c14181cd73cf942682
                        • Opcode Fuzzy Hash: 850b9cb466d677ff00d8b55372f21189bc731a9e522cac9c840b57d9a4461268
                        • Instruction Fuzzy Hash: D301D670A195DA8FDB81DF2848616EA7BE0EF57240B0505EBD55CC7292CB28790187C1
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 556c9d7d27351a80f5fff514cf2d701f223dc9d7f2af82f6d54b1352b6712d02
                        • Instruction ID: 7f777b7c768f8cc842f155ad04e93955da29ba78bffe5f9e07b672104a2a975a
                        • Opcode Fuzzy Hash: 556c9d7d27351a80f5fff514cf2d701f223dc9d7f2af82f6d54b1352b6712d02
                        • Instruction Fuzzy Hash: E5110A76A0D6CA9FD7129B285CA55ED7F60EF03208F0505F7E548C71C3DA28A149D791
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 48d27ec5788015657a5744f03fc33b2238ef51b8624475ea5a3796cabd1d6188
                        • Instruction ID: 6dfb4d9adfbb1fb00dbff3d9d1cf016b1c667ab0b540c0ccb339fdd7d6266c64
                        • Opcode Fuzzy Hash: 48d27ec5788015657a5744f03fc33b2238ef51b8624475ea5a3796cabd1d6188
                        • Instruction Fuzzy Hash: 8901F730B5DA8A4FE745A77844296A877D1EF5A350B4800F9C54CCB2A3DD1CE8818380
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: bb8d3512bc7a342c509fc15014b01702715eba656e3d93817049987bba731678
                        • Instruction ID: 4502a1e70d6effe50f09d18c6c68e3d2b242b75a6b02f1e47aec07da320a6662
                        • Opcode Fuzzy Hash: bb8d3512bc7a342c509fc15014b01702715eba656e3d93817049987bba731678
                        • Instruction Fuzzy Hash: 8601AD32A0894D8FDB44EF58D495AF937A0FF56319F0400A6D508D6151CA35A955CBC1
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: afa1ef85062576c421860ba0ef99806624fb1d70f06f023d1148daf7f2177442
                        • Instruction ID: 964435096174375365705e6f2279fc5a06849d6627ce97944ad624a6b8e05ca4
                        • Opcode Fuzzy Hash: afa1ef85062576c421860ba0ef99806624fb1d70f06f023d1148daf7f2177442
                        • Instruction Fuzzy Hash: 4A11E5B290D78A5FD712AB7858A56FE3F64EF03218F0801F6E448D61C3DA28A059C391
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 581a05922a0a02d024dee43a0801dd9456f89077314bb496b253cda8487beb0c
                        • Instruction ID: d2a35f6fd7567a8259a228c3444d25ca8b209a40528656e88a9d61678568bf86
                        • Opcode Fuzzy Hash: 581a05922a0a02d024dee43a0801dd9456f89077314bb496b253cda8487beb0c
                        • Instruction Fuzzy Hash: 5921BEB1E4872ACEDB64DF15C854BF8B7B1AB16319F4040F9D10DD2591CB786A84DF41
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 771f07a931163d9964edaa5fa41cdede70410a2e609925baba983b6fa88797c3
                        • Instruction ID: ce100b8c3e4c916a97621f6af8e2893cffcc3d4d508f365caab6b66db86e873c
                        • Opcode Fuzzy Hash: 771f07a931163d9964edaa5fa41cdede70410a2e609925baba983b6fa88797c3
                        • Instruction Fuzzy Hash: AE110DB1A0851ACBEB64EB54C898BECB3B1FB55304F1041F9C60DE2290CE786AC4CF85
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6483d6daf2e872014167a3e4301f97e88fec0c2fbde6ea8e7ff40b5954665a0e
                        • Instruction ID: 9f4a18b504d834c9d2699cf31c0355fc92a5fdaf6caf424e136a144fa7e2fc0b
                        • Opcode Fuzzy Hash: 6483d6daf2e872014167a3e4301f97e88fec0c2fbde6ea8e7ff40b5954665a0e
                        • Instruction Fuzzy Hash: EB012870A08A4CDFDF84EF58C899AE97BE0FF69315F10056AE40DD3290DB75A954CB81
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4c378991e6a55022d93ca4615501aa439161d4843d164d2fb4675d061a32a6e7
                        • Instruction ID: c0ec287050fddf58ef50044595880f76391827a345c262a9a9d79b166556207f
                        • Opcode Fuzzy Hash: 4c378991e6a55022d93ca4615501aa439161d4843d164d2fb4675d061a32a6e7
                        • Instruction Fuzzy Hash: B101317091990DDFDF94EF58C4A5AF97BB0FF2A305F10446AE40DD3195CA35A594CB80
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e1a9224369046f2404d67f64e7bee72411f2b3b82159ef0aa65d5ae9e93f6852
                        • Instruction ID: db66026095b00b9f581fac06ffa0ea9a42e577825cdf60c06bdadf03545612f2
                        • Opcode Fuzzy Hash: e1a9224369046f2404d67f64e7bee72411f2b3b82159ef0aa65d5ae9e93f6852
                        • Instruction Fuzzy Hash: D6F01D70A0860DDBDB90EF58D4996EE77A0FB55300F114476E508D2250DA3865A0D780
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: dc0d641a7216868803916785b9e043f00ec0706aaca36d89821aa9ba6bfdf88e
                        • Instruction ID: 48d5adda7c5fefedb2021b2cb4f9720acb980557edc4585b5984e92739005064
                        • Opcode Fuzzy Hash: dc0d641a7216868803916785b9e043f00ec0706aaca36d89821aa9ba6bfdf88e
                        • Instruction Fuzzy Hash: D7F01C70918A0DDFDB94EF68D8897EA7BE0FF59304F004466E81CD2250DA34A6A0CB80
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fffa468a39d10d9507f10512f40b5e910d2266cb1572c558ad182a5f683af9fb
                        • Instruction ID: 656399a18f1a46d89506f69edc9993bcb058af290afb9dcf9b8113483e5bdab2
                        • Opcode Fuzzy Hash: fffa468a39d10d9507f10512f40b5e910d2266cb1572c558ad182a5f683af9fb
                        • Instruction Fuzzy Hash: FEF0307092464DDFDB90EF6484486E977A0FF05305F40047AF418C2291DA38B1A0CB81
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9061582af2275cd3459d5ee13dbb211f1cd395c8ee5ffb55b37bf87a69394a98
                        • Instruction ID: 7656622cc499e19749c0b56e5b66fafe8edcfd553c75dfa4093f3f05ae8d047e
                        • Opcode Fuzzy Hash: 9061582af2275cd3459d5ee13dbb211f1cd395c8ee5ffb55b37bf87a69394a98
                        • Instruction Fuzzy Hash: 36E01A70928A4DDFDB94EF6484547EEB7A0FF05304F4004BAE41DD2281EB38B6A4DB82
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6b4868d323642bc687528715fdc8b5e090f9fb06eae5602662149ff43b402034
                        • Instruction ID: fafdeb5c7eea46b91d1d0b113334c1315e1f5abf4e172cf746fbafe5fbc6a333
                        • Opcode Fuzzy Hash: 6b4868d323642bc687528715fdc8b5e090f9fb06eae5602662149ff43b402034
                        • Instruction Fuzzy Hash: 5DA00245DA784E42984831BE1DD749475505B8B614FD51174E918C0197E88E25E912E3
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2670862828.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34950000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: 0_^$4
                        • API String ID: 0-1108559558
                        • Opcode ID: 5935a952109181cd3857cc5974f1e8287f00d6f13ada5e530b276d15ef1c5213
                        • Instruction ID: 6976647a250a1f8b43a2a26541e02caca104942259c95b688b765946decc7a57
                        • Opcode Fuzzy Hash: 5935a952109181cd3857cc5974f1e8287f00d6f13ada5e530b276d15ef1c5213
                        • Instruction Fuzzy Hash: DBC13D6298E3C22FE313873458B64E57FA49E4323871E01EBC5D4CB4A3DA1D265AD372
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2670862828.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34950000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: 1_^$>1_^
                        • API String ID: 0-2142292170
                        • Opcode ID: 6444a3cb1b1b7e47b77bfd30b7ba778ddcc8cbf571c0c022d2bf13441396a37e
                        • Instruction ID: 6d8a8a9ae0035cc7a5584df5f203ab5e72dcdd2a351134cc6bfbd46ca7d53c68
                        • Opcode Fuzzy Hash: 6444a3cb1b1b7e47b77bfd30b7ba778ddcc8cbf571c0c022d2bf13441396a37e
                        • Instruction Fuzzy Hash: 9971996390D6537BE321BBB8E8A30EA7B94EF0332C719417AD588D9063DE2C75568690
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2670862828.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34950000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: 0_^$4
                        • API String ID: 0-1108559558
                        • Opcode ID: c195759604c5ab9e10f44cacdad4e258b8b689411ef3162efb774aa8cfe5f5a0
                        • Instruction ID: d7b0966da81d4843914b06442a8a64baadbaf9b00addcbdb943274a27b7c762b
                        • Opcode Fuzzy Hash: c195759604c5ab9e10f44cacdad4e258b8b689411ef3162efb774aa8cfe5f5a0
                        • Instruction Fuzzy Hash: 09513D4294E7C32AE353963898B50A97FA49F53134B1E01FFC5D4DB093DA0C751AE362
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: ;K
                        • API String ID: 0-1937776222
                        • Opcode ID: bc014dc8e4a840899d288b2b3ee1a099aa6f6fb2ab50acb20a202eb230dd553d
                        • Instruction ID: 8672537c893152a0ed185c05875ace5ccd82667c00f85b0c4a9d69afb38a67e7
                        • Opcode Fuzzy Hash: bc014dc8e4a840899d288b2b3ee1a099aa6f6fb2ab50acb20a202eb230dd553d
                        • Instruction Fuzzy Hash: B431808BB0CD3756D22175FDB8531FE7344DBC23BAB045677D28CD8047881994AB82E6
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.2667005161.00007FFD34790000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34790000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_7ffd34790000_QUOTATION_SEPQTRA071244#U00faPDF.jbxd
                        Similarity
                        • API ID:
                        • String ID: L_^$L_^$L_^$L_^
                        • API String ID: 0-2357752022
                        • Opcode ID: f0adf3d57fd462e7359899514e878eb8b528a5185729e0b0d4703531faeefa38
                        • Instruction ID: 6a2f68295ac26a8fafe029d2f6cb5d6bb5d215e1b838365886e482b025a0c56d
                        • Opcode Fuzzy Hash: f0adf3d57fd462e7359899514e878eb8b528a5185729e0b0d4703531faeefa38
                        • Instruction Fuzzy Hash: 4841C677A1D6925BD3126B9DE8A30ED3B90FF0322D70D00F2D688CE153EA14645A86D2

                        Execution Graph

                        Execution Coverage:26.3%
                        Dynamic/Decrypted Code Coverage:0%
                        Signature Coverage:0%
                        Total number of Nodes:88
                        Total number of Limit Nodes:5
                        execution_graph 7314 22934032b9c 7340 22934034644 7314->7340 7317 22934034644 LoadLibraryA 7318 22934032bd8 7317->7318 7319 22934034644 LoadLibraryA 7318->7319 7320 22934032bee 7319->7320 7321 22934032c19 7320->7321 7322 22934032c00 VirtualAlloc 7320->7322 7322->7321 7323 22934032c45 7322->7323 7323->7321 7324 22934034644 LoadLibraryA 7323->7324 7325 22934032cb9 7324->7325 7325->7321 7326 22934032d10 7325->7326 7328 229340343b4 LoadLibraryA 7325->7328 7326->7321 7327 22934034644 LoadLibraryA 7326->7327 7329 22934032d50 7326->7329 7327->7326 7328->7325 7329->7321 7339 22934032dd8 7329->7339 7360 22934031b04 7329->7360 7331 22934032dae 7334 22934032db2 7331->7334 7344 22934031c30 7331->7344 7332 22934032ee9 7374 229340333a8 7332->7374 7333 22934032e99 7333->7321 7353 22934032928 7333->7353 7334->7321 7334->7331 7339->7321 7339->7332 7339->7333 7341 2293403467b 7340->7341 7342 22934032bc5 7341->7342 7384 22934032150 7341->7384 7342->7317 7345 229340343b4 LoadLibraryA 7344->7345 7346 22934031c4e 7345->7346 7347 2293403449c LoadLibraryA 7346->7347 7348 22934031c63 7347->7348 7349 22934031c6b VirtualProtect 7348->7349 7350 22934031cad 7348->7350 7349->7350 7351 22934031c85 7349->7351 7350->7321 7350->7339 7352 22934031c97 VirtualProtect 7351->7352 7352->7350 7354 22934032965 CLRCreateInstance 7353->7354 7356 2293403297e 7353->7356 7354->7356 7355 22934032a2d 7355->7321 7356->7355 7357 22934032a8b SysAllocString 7356->7357 7358 22934032a5f 7356->7358 7357->7358 7358->7355 7359 22934032b71 SafeArrayDestroy 7358->7359 7359->7355 7361 229340343b4 LoadLibraryA 7360->7361 7362 22934031b23 7361->7362 7363 22934031b2b 7362->7363 7364 2293403449c LoadLibraryA 7362->7364 7363->7331 7365 22934031b4a 7364->7365 7365->7363 7366 22934031b6d VirtualProtect 7365->7366 7366->7363 7367 22934031b8b 7366->7367 7368 22934031b99 VirtualProtect 7367->7368 7369 2293403449c LoadLibraryA 7368->7369 7370 22934031bc1 7369->7370 7370->7363 7371 22934031bdc VirtualProtect 7370->7371 7371->7363 7372 22934031bf5 7371->7372 7373 22934031c03 VirtualProtect 7372->7373 7373->7363 7377 229340333fc 7374->7377 7375 229340343b4 LoadLibraryA 7375->7377 7376 229340343b4 LoadLibraryA 7378 22934033859 7376->7378 7377->7375 7377->7378 7379 2293403449c LoadLibraryA 7377->7379 7383 22934033c30 7377->7383 7378->7376 7380 2293403449c LoadLibraryA 7378->7380 7381 229340338f8 7378->7381 7379->7377 7380->7378 7381->7383 7388 22934034158 7381->7388 7383->7321 7386 22934032190 7384->7386 7387 22934032227 7384->7387 7385 22934032308 LoadLibraryA 7385->7387 7386->7385 7386->7387 7387->7341 7391 22934034194 7388->7391 7389 22934034390 7389->7383 7390 2293403449c LoadLibraryA 7390->7391 7391->7389 7391->7390 7291 22934031b73 VirtualProtect 7292 22934031b8b 7291->7292 7299 22934031b2b 7291->7299 7293 22934031b99 VirtualProtect 7292->7293 7300 2293403449c 7293->7300 7296 22934031bdc VirtualProtect 7297 22934031bf5 7296->7297 7296->7299 7298 22934031c03 VirtualProtect 7297->7298 7298->7299 7301 22934031bc1 7300->7301 7302 229340344d2 7300->7302 7301->7296 7301->7299 7302->7301 7304 22934032308 7302->7304 7306 2293403234b 7304->7306 7309 22934032374 7304->7309 7305 22934032384 7305->7301 7306->7305 7308 2293403449c LoadLibraryA 7306->7308 7306->7309 7308->7306 7309->7305 7310 229340343b4 7309->7310 7312 229340343d2 7310->7312 7311 2293403447d LoadLibraryA 7313 22934034485 7311->7313 7312->7311 7312->7313 7313->7305

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 312 22934032b9c-22934032bf4 call 22934034644 * 3 319 22934032c26 312->319 320 22934032bf6-22934032bf9 312->320 321 22934032c29-22934032c44 319->321 320->319 322 22934032bfb-22934032bfe 320->322 322->319 323 22934032c00-22934032c17 VirtualAlloc 322->323 324 22934032c19-22934032c20 323->324 325 22934032c45-22934032c6e call 22934034bc4 call 22934034be4 323->325 324->319 327 22934032c22 324->327 331 22934032caa-22934032cc0 call 22934034644 325->331 332 22934032c70-22934032ca4 call 229340347f8 call 229340346b8 325->332 327->319 331->319 338 22934032cc6-22934032cc7 331->338 332->331 343 22934032eff-22934032f00 332->343 340 22934032ccd-22934032cd3 338->340 341 22934032d10-22934032d1b 340->341 342 22934032cd5 340->342 346 22934032d50-22934032d59 341->346 347 22934032d1d-22934032d37 call 22934034644 341->347 344 22934032cd7-22934032cd9 342->344 345 22934032f05-22934032f16 343->345 348 22934032cdb-22934032ce1 344->348 349 22934032cf2-22934032cf4 344->349 350 22934032f49-22934032f6a call 22934034be4 345->350 351 22934032f18-22934032f22 345->351 353 22934032d5b-22934032d6b call 22934031cc0 346->353 354 22934032d7a-22934032d83 346->354 368 22934032d39-22934032d40 347->368 369 22934032d46-22934032d4e 347->369 348->349 356 22934032ce3-22934032cf0 348->356 349->341 359 22934032cf6-22934032d0e call 229340343b4 349->359 381 22934032f6c 350->381 382 22934032f70-22934032f72 350->382 351->350 357 22934032f24-22934032f42 call 22934034be4 351->357 353->345 370 22934032d71-22934032d78 353->370 354->345 358 22934032d89-22934032d93 354->358 356->344 356->349 357->350 364 22934032d9d-22934032da4 358->364 365 22934032d95-22934032d96 358->365 359->340 372 22934032dd8-22934032ddc 364->372 373 22934032da6-22934032da7 364->373 365->364 368->343 368->369 369->346 369->347 370->364 375 22934032e8f-22934032e97 372->375 376 22934032de2-22934032e0b 372->376 377 22934032da9 call 22934031b04 373->377 383 22934032ee9-22934032eef call 229340333a8 375->383 384 22934032e99-22934032e9f 375->384 376->345 393 22934032e11-22934032e2b call 22934034bc4 376->393 380 22934032dae-22934032db0 377->380 388 22934032dbf-22934032dc2 call 22934031c30 380->388 389 22934032db2-22934032db9 380->389 381->382 382->321 392 22934032ef4-22934032efb 383->392 385 22934032ea1-22934032ea7 384->385 386 22934032eb6-22934032ec8 call 22934032928 384->386 391 22934032ea9-22934032eb4 call 22934033e5c 385->391 385->392 403 22934032eda-22934032ee7 call 229340323b8 386->403 404 22934032eca-22934032ed5 call 22934032f78 386->404 399 22934032dc7-22934032dc9 388->399 389->345 389->388 391->392 392->345 400 22934032efd 392->400 406 22934032e2d-22934032e30 393->406 407 22934032e47-22934032e8a 393->407 399->372 405 22934032dcb-22934032dd2 399->405 400->400 403->392 404->403 405->345 405->372 406->375 410 22934032e32-22934032e45 call 22934034948 406->410 407->345 415 22934032e8c-22934032e8d 407->415 410->415 415->375
                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022934010000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_22934010000_aspnet_compiler.jbxd
                        Yara matches
                        Similarity
                        • API ID: AllocVirtual
                        • String ID:
                        • API String ID: 4275171209-0
                        • Opcode ID: 08c3b473a1f7362871bcf2729fe2c144e163769adb635b581bed10db9dac86c4
                        • Instruction ID: f9ed3105f6f1298210f0f308ad0321d091a8f73e61f2298b3331ce37ab2f2199
                        • Opcode Fuzzy Hash: 08c3b473a1f7362871bcf2729fe2c144e163769adb635b581bed10db9dac86c4
                        • Instruction Fuzzy Hash: 1EC1D730314A056FEB59EA68C4C97B9B7D1FB9A300F1651ADD44AD72C6DB30E882CF81

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 438 7ffd3485720a-7ffd34857211 439 7ffd34857213 438->439 440 7ffd34857214-7ffd3485727f 438->440 439->440 441 7ffd34857281 440->441 442 7ffd34857286-7ffd348572c4 440->442 441->442 444 7ffd3485730f-7ffd34857329 442->444 445 7ffd3485732b-7ffd34857364 444->445 446 7ffd348572c6-7ffd348572d4 444->446 452 7ffd3485736b-7ffd34857395 445->452 447 7ffd348572db-7ffd34857305 call 7ffd348530a0 446->447 448 7ffd348572d6 446->448 456 7ffd3485730c 447->456 457 7ffd34857307 447->457 448->447 454 7ffd3485742b-7ffd3485742c 452->454 455 7ffd3485739b-7ffd348573f3 452->455 458 7ffd3485742d-7ffd348574f9 454->458 463 7ffd34857425-7ffd34857426 455->463 464 7ffd348573f5-7ffd34857423 455->464 456->444 457->456 470 7ffd348574ff-7ffd34857527 458->470 471 7ffd34857f58-7ffd34857ffe 458->471 465 7ffd34857427-7ffd34857429 463->465 464->465 465->458 475 7ffd34857f31-7ffd34857f51 470->475 476 7ffd3485752c-7ffd3485753a 475->476 477 7ffd34857f57 475->477 479 7ffd34857541-7ffd348575bf 476->479 480 7ffd3485753c 476->480 477->471 486 7ffd348575c1 479->486 487 7ffd348575c6-7ffd34857681 479->487 480->479 486->487 493 7ffd34857683 487->493 494 7ffd34857688-7ffd3485768f 487->494 493->494 495 7ffd34857691 494->495 496 7ffd34857696-7ffd3485769f 494->496 495->496 497 7ffd348576a1 496->497 498 7ffd348576a6-7ffd348576a9 496->498 497->498 499 7ffd348576b0-7ffd34857727 498->499 500 7ffd348576ab 498->500 503 7ffd3485772e-7ffd3485774f 499->503 504 7ffd34857729 499->504 500->499 505 7ffd34857751-7ffd34857758 503->505 506 7ffd3485775a-7ffd34857762 503->506 504->503 507 7ffd34857763-7ffd34857769 505->507 506->507 508 7ffd34857770-7ffd34857779 507->508 509 7ffd3485776b 507->509 510 7ffd34857efb-7ffd34857f01 508->510 509->508 511 7ffd3485777e-7ffd3485778c 510->511 512 7ffd34857f07-7ffd34857f27 510->512 513 7ffd34857793-7ffd3485779e 511->513 514 7ffd3485778e 511->514 518 7ffd34857f2e 512->518 519 7ffd34857f29 512->519 515 7ffd348577f0-7ffd348577f2 513->515 516 7ffd348577a0-7ffd348577ae 513->516 514->513 520 7ffd348577f8-7ffd3485780e 515->520 521 7ffd348577b0 516->521 522 7ffd348577b5-7ffd348577c0 516->522 518->475 519->518 523 7ffd34857814-7ffd34857830 520->523 524 7ffd34857ed5-7ffd34857eea 520->524 521->522 522->515 525 7ffd348577c2-7ffd348577d0 522->525 528 7ffd34857832 523->528 529 7ffd34857837-7ffd348578dc 523->529 530 7ffd34857eeb-7ffd34857ef1 524->530 526 7ffd348577d2 525->526 527 7ffd348577d7-7ffd348577ee 525->527 526->527 527->520 528->529 537 7ffd348578de-7ffd3485790e 529->537 538 7ffd34857910 529->538 531 7ffd34857ef3 530->531 532 7ffd34857ef8 530->532 531->532 532->510 539 7ffd3485791a-7ffd34857930 537->539 538->539 541 7ffd34857a93-7ffd34857a98 539->541 542 7ffd34857936-7ffd3485793c 539->542 545 7ffd34857b11-7ffd34857b13 541->545 546 7ffd34857a9a-7ffd34857ac5 541->546 543 7ffd34857943-7ffd3485795d 542->543 544 7ffd3485793e 542->544 548 7ffd3485795f-7ffd34857965 543->548 549 7ffd34857970-7ffd34857972 543->549 544->543 547 7ffd34857b19-7ffd34857b2f 545->547 559 7ffd34857af9 546->559 560 7ffd34857ac7-7ffd34857af7 546->560 550 7ffd34857ecf-7ffd34857ed0 547->550 551 7ffd34857b35-7ffd34857b3b 547->551 553 7ffd3485796c-7ffd3485796f 548->553 554 7ffd34857967 548->554 555 7ffd34857a11-7ffd34857a1f 549->555 558 7ffd34857ed1-7ffd34857ed3 550->558 556 7ffd34857b42-7ffd34857b5c 551->556 557 7ffd34857b3d 551->557 553->549 554->553 561 7ffd34857a21 555->561 562 7ffd34857a26-7ffd34857a31 555->562 565 7ffd34857b5e-7ffd34857b64 556->565 566 7ffd34857b6f-7ffd34857b85 556->566 557->556 558->530 567 7ffd34857b03-7ffd34857b0f 559->567 560->567 561->562 563 7ffd34857a61-7ffd34857a63 562->563 564 7ffd34857a33-7ffd34857a41 562->564 570 7ffd34857a69-7ffd34857a79 563->570 568 7ffd34857a43 564->568 569 7ffd34857a48-7ffd34857a5f 564->569 571 7ffd34857b6b-7ffd34857b6e 565->571 572 7ffd34857b66 565->572 573 7ffd34857c24-7ffd34857c32 566->573 567->547 568->569 569->570 575 7ffd34857a7f-7ffd34857a8e 570->575 576 7ffd34857977-7ffd34857993 570->576 571->566 572->571 577 7ffd34857c34 573->577 578 7ffd34857c39-7ffd34857c44 573->578 575->558 579 7ffd3485799a-7ffd34857a06 576->579 580 7ffd34857995 576->580 577->578 581 7ffd34857c74-7ffd34857c76 578->581 582 7ffd34857c46-7ffd34857c54 578->582 599 7ffd34857a0d-7ffd34857a10 579->599 600 7ffd34857a08 579->600 580->579 583 7ffd34857c7c-7ffd34857c8c 581->583 584 7ffd34857c5b-7ffd34857c72 582->584 585 7ffd34857c56 582->585 586 7ffd34857c92-7ffd34857d11 583->586 587 7ffd34857b8a-7ffd34857ba6 583->587 584->583 585->584 597 7ffd34857d13-7ffd34857d15 586->597 598 7ffd34857d1a-7ffd34857ecb call 7ffd348550a8 586->598 589 7ffd34857bad-7ffd34857c19 587->589 590 7ffd34857ba8 587->590 604 7ffd34857c20-7ffd34857c23 589->604 605 7ffd34857c1b 589->605 590->589 601 7ffd34857ecc-7ffd34857ecd 597->601 598->601 599->555 600->599 601->512 604->573 605->604
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 469607204afa1f77822b62735bc803be76814639c8ae899a2c04548849919a04
                        • Instruction ID: 92836f3fa01c015325b9c1e91e49b8d89f64a31cdb7970e00d78264293b46327
                        • Opcode Fuzzy Hash: 469607204afa1f77822b62735bc803be76814639c8ae899a2c04548849919a04
                        • Instruction Fuzzy Hash: B8A2EC70E0861D8FDBA9DF64C8A4BA9B7B1FF5A301F5041E9D40DE7292CA395A81CF11

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 620 7ffd34858946-7ffd3485899f 622 7ffd348589a1 620->622 623 7ffd348589a6-7ffd34858a00 620->623 622->623 627 7ffd34858e1e-7ffd34858ecf 623->627 628 7ffd34858a06-7ffd34858a17 623->628 633 7ffd34858ed1 627->633 634 7ffd34858ed6-7ffd34858ed7 627->634 628->627 633->634 635 7ffd34858ed8-7ffd34858eda 634->635 636 7ffd34858ee1-7ffd34858f30 635->636 639 7ffd3485934e-7ffd348593ff 636->639 640 7ffd34858f36-7ffd34858f41 636->640 646 7ffd34859401 639->646 647 7ffd34859406-7ffd34859460 639->647 640->635 646->647 651 7ffd3485987e-7ffd3485992f 647->651 652 7ffd34859466-7ffd348594cc call 7ffd34858090 call 7ffd34858068 call 7ffd34858070 647->652 661 7ffd34859931 651->661 662 7ffd34859936-7ffd34859990 651->662 665 7ffd348594d3-7ffd348594df 652->665 666 7ffd348594ce 652->666 661->662 676 7ffd34859dae-7ffd34859e3c 662->676 677 7ffd34859996-7ffd348599a7 662->677 668 7ffd3485986f-7ffd34859877 665->668 666->665 670 7ffd348594e4-7ffd34859587 call 7ffd34858080 * 3 call 7ffd348550b0 668->670 671 7ffd3485987d 668->671 688 7ffd3485958d-7ffd3485960e call 7ffd348550b8 670->688 689 7ffd34859667-7ffd348596da call 7ffd34858080 call 7ffd34855208 670->689 671->651 690 7ffd34859e3e-7ffd34859e71 676->690 691 7ffd34859e86-7ffd34859f15 676->691 677->676 711 7ffd34859662-7ffd34859665 688->711 712 7ffd34859610-7ffd34859661 call 7ffd348550c0 688->712 713 7ffd348596db-7ffd34859737 689->713 693 7ffd34859e73 690->693 694 7ffd34859e78-7ffd34859e84 690->694 720 7ffd3485a19f-7ffd3485a229 691->720 721 7ffd34859f1b-7ffd34859f42 691->721 693->694 694->691 711->713 712->711 723 7ffd3485985e-7ffd34859865 713->723 724 7ffd3485973d-7ffd3485985d 713->724 731 7ffd3485a231-7ffd3485a239 720->731 732 7ffd3485a22b-7ffd3485a230 720->732 730 7ffd34859f4c-7ffd34859f6d 721->730 725 7ffd3485986c 723->725 726 7ffd34859867 723->726 724->723 725->668 726->725 737 7ffd34859f74-7ffd34859f7b 730->737 738 7ffd34859f6f 730->738 732->731 739 7ffd34859f82-7ffd34859fb4 737->739 740 7ffd34859f7d 737->740 738->737 744 7ffd34859fbb-7ffd34859feb 739->744 740->739 749 7ffd34859ff2-7ffd3485a057 744->749 750 7ffd34859fed 744->750 758 7ffd3485a062-7ffd3485a083 call 7ffd34858050 749->758 750->749 761 7ffd3485a088-7ffd3485a097 758->761 762 7ffd3485a09e-7ffd3485a0ef call 7ffd34858050 761->762 763 7ffd3485a099 761->763 766 7ffd3485a0f1-7ffd3485a0f4 762->766 767 7ffd3485a148-7ffd3485a14d 762->767 763->762 769 7ffd3485a0f6-7ffd3485a10a 766->769 770 7ffd3485a175-7ffd3485a17a 766->770 768 7ffd3485a158-7ffd3485a16c 767->768 771 7ffd3485a16e 768->771 772 7ffd3485a185-7ffd3485a18c 768->772 773 7ffd3485a17b-7ffd3485a182 769->773 777 7ffd3485a10c-7ffd3485a110 769->777 770->773 771->770 774 7ffd3485a191-7ffd3485a198 call 7ffd34858058 772->774 773->772 778 7ffd3485a19d-7ffd3485a19e 774->778 777->774 779 7ffd3485a112 777->779 778->720 779->767
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: bdf26843abd3df8e40ad5f1d9bfbccd62cbe3efcab44e4e9e1bd478b2a071903
                        • Instruction ID: 9419de0031310d8792e6bf7dff4f6abf5ddee101c109628f149ab697a5c5206a
                        • Opcode Fuzzy Hash: bdf26843abd3df8e40ad5f1d9bfbccd62cbe3efcab44e4e9e1bd478b2a071903
                        • Instruction Fuzzy Hash: 9F926F30A0864E8FDB95EF68C8A47E9B7F1FF5A310F0441AAD44DE7292CA385985CF51

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 914 7ffd348599ac-7ffd348599fc call 7ffd34858090 call 7ffd34858068 call 7ffd34858070 921 7ffd34859a03-7ffd34859a0f 914->921 922 7ffd348599fe 914->922 923 7ffd34859d9f-7ffd34859da7 921->923 922->921 924 7ffd34859a14-7ffd34859a2a call 7ffd34858080 923->924 925 7ffd34859dad-7ffd34859e3c 923->925 928 7ffd34859a2f-7ffd34859ab7 call 7ffd34858080 * 2 call 7ffd348550b0 924->928 938 7ffd34859e3e-7ffd34859e71 925->938 939 7ffd34859e86-7ffd34859f15 925->939 944 7ffd34859abd-7ffd34859b3e call 7ffd348550b8 928->944 945 7ffd34859b97-7ffd34859c0a call 7ffd34858080 call 7ffd34855208 928->945 941 7ffd34859e73 938->941 942 7ffd34859e78-7ffd34859e84 938->942 969 7ffd3485a19f-7ffd3485a229 939->969 970 7ffd34859f1b-7ffd34859f6d 939->970 941->942 942->939 963 7ffd34859b92-7ffd34859b95 944->963 964 7ffd34859b40-7ffd34859b91 call 7ffd348550c0 944->964 965 7ffd34859c0b-7ffd34859c67 945->965 963->965 964->963 978 7ffd34859d8e-7ffd34859d95 965->978 979 7ffd34859c6d-7ffd34859d8d 965->979 975 7ffd3485a231-7ffd3485a239 969->975 976 7ffd3485a22b-7ffd3485a230 969->976 986 7ffd34859f74-7ffd34859f7b 970->986 987 7ffd34859f6f 970->987 976->975 980 7ffd34859d9c 978->980 981 7ffd34859d97 978->981 979->978 980->923 981->980 989 7ffd34859f82-7ffd34859feb 986->989 990 7ffd34859f7d 986->990 987->986 999 7ffd34859ff2-7ffd3485a097 call 7ffd34858050 989->999 1000 7ffd34859fed 989->1000 990->989 1013 7ffd3485a09e-7ffd3485a0ef call 7ffd34858050 999->1013 1014 7ffd3485a099 999->1014 1000->999 1017 7ffd3485a0f1-7ffd3485a0f4 1013->1017 1018 7ffd3485a148-7ffd3485a14d 1013->1018 1014->1013 1020 7ffd3485a0f6-7ffd3485a10a 1017->1020 1021 7ffd3485a175-7ffd3485a17a 1017->1021 1019 7ffd3485a158-7ffd3485a16c 1018->1019 1022 7ffd3485a16e 1019->1022 1023 7ffd3485a185-7ffd3485a18c 1019->1023 1024 7ffd3485a17b-7ffd3485a182 1020->1024 1028 7ffd3485a10c-7ffd3485a110 1020->1028 1021->1024 1022->1021 1025 7ffd3485a191-7ffd3485a198 call 7ffd34858058 1023->1025 1024->1023 1029 7ffd3485a19d-7ffd3485a19e 1025->1029 1028->1025 1030 7ffd3485a112 1028->1030 1029->969 1030->1018
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6be7ad9f6a51b0a0dfc24b6d3aea0691cc6ab0a4a979b8553b8fc8565cca7bc9
                        • Instruction ID: 5317a1cbca73e9e77685f72f1ab1fe074448fb91ff9f7919adbca203012d484b
                        • Opcode Fuzzy Hash: 6be7ad9f6a51b0a0dfc24b6d3aea0691cc6ab0a4a979b8553b8fc8565cca7bc9
                        • Instruction Fuzzy Hash: CB422D70A08A1E8FDB95EF68C494BADB7F1FF59300F1041A9D40DE7292CA78A985CF51
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7d7cd1cbbc591438a11cca6d2adaefad69317709746501b8dc42b0184f87c669
                        • Instruction ID: c41a8677a20c422cde62be484b0249f6c724d6fd82308176e02b4411caf85775
                        • Opcode Fuzzy Hash: 7d7cd1cbbc591438a11cca6d2adaefad69317709746501b8dc42b0184f87c669
                        • Instruction Fuzzy Hash: 00022F30A0961E8FDB95EF68C494BA9B7F1FF5A300F5441EAD40DE7292CA389985CF11
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a33b7029665d4576d5576f67d5d19a37c358abd36923a04ba7711abb63ed2133
                        • Instruction ID: 5fb2a404e9c49483321ad4c9591304d14b7cc1cd653b06f708f0b1a2aaf55b75
                        • Opcode Fuzzy Hash: a33b7029665d4576d5576f67d5d19a37c358abd36923a04ba7711abb63ed2133
                        • Instruction Fuzzy Hash: 3F919830A0955D8FDBA4EF68D895BA9B7B1EF59301F5042E9D00DE7291CA39ADC1CF04
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a1472258e3ebae7921e48ab8fe40915d1adf6b997331c5044cf6a5697fdeadd0
                        • Instruction ID: 421f2c455a42ccc9c4ed50fd728e488f1060b15ef05604cc1798dfb63d145506
                        • Opcode Fuzzy Hash: a1472258e3ebae7921e48ab8fe40915d1adf6b997331c5044cf6a5697fdeadd0
                        • Instruction Fuzzy Hash: FC017430E0421E8AEB10EF95C4907FEB3B1EF86301F00817AC228A31C5CB796589CF80

                        Control-flow Graph

                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID: h|04$h|04$h|04$h|04$h|04$h|04$h|04$h|04$h|04
                        • API String ID: 0-4087857264
                        • Opcode ID: d5b1be702ab3c6363f8f49aebc366dff813dc8f8abff937bdb3f36453a0fa30d
                        • Instruction ID: def0d496c1c28831ee0005f3190d3c573da6cf1ad9b0e863fa5a202892b24a24
                        • Opcode Fuzzy Hash: d5b1be702ab3c6363f8f49aebc366dff813dc8f8abff937bdb3f36453a0fa30d
                        • Instruction Fuzzy Hash: D302D131A0DA8E9FDB56DF6488656E8BBF1FF46304F0401FBD409E7192DA2C6885C752

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022934010000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_22934010000_aspnet_compiler.jbxd
                        Yara matches
                        Similarity
                        • API ID: ProtectVirtual$LibraryLoad
                        • String ID:
                        • API String ID: 895956442-0
                        • Opcode ID: d24d4ce7223a552c1b01d238479d20a295a89e3d53a7350efd5ba8d12bfb46a0
                        • Instruction ID: 4c2917917616f9894a32f930cf8f8afbb2c423bcd394f971240325e3e721dc83
                        • Opcode Fuzzy Hash: d24d4ce7223a552c1b01d238479d20a295a89e3d53a7350efd5ba8d12bfb46a0
                        • Instruction Fuzzy Hash: 8D31C73131CA085BD758EE689C8936A77D5E7C9720F0112ADA84BD72C6DE70DD864BC1

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022934010000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_22934010000_aspnet_compiler.jbxd
                        Yara matches
                        Similarity
                        • API ID: ProtectVirtual
                        • String ID:
                        • API String ID: 544645111-0
                        • Opcode ID: f2b484dd179f3dd10506a7a62fe75bc60ed010a6cf5ae84582fe1852291c4020
                        • Instruction ID: d8ea51a619bf13c69b8db2cd61950d6b341d6956dc5ade9b43234aedcf70c0aa
                        • Opcode Fuzzy Hash: f2b484dd179f3dd10506a7a62fe75bc60ed010a6cf5ae84582fe1852291c4020
                        • Instruction Fuzzy Hash: A521A83131C6085BDB58E95CA89936977D1E7C8720F1111A9EC4BD72C6DE30DD8647C1

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 110 22934032928-2293403295f 111 229340329ff-22934032a06 110->111 112 22934032965-22934032978 CLRCreateInstance 110->112 115 22934032a29-22934032a2b 111->115 116 22934032a08-22934032a21 111->116 113 2293403297e-229340329ba 112->113 114 22934032a38-22934032a3b 112->114 125 229340329bc-229340329cf 113->125 126 229340329f8-229340329f9 113->126 114->116 117 22934032a3d-22934032a49 115->117 118 22934032a2d-22934032a33 115->118 116->115 123 22934032b7a-22934032b7b 117->123 124 22934032a4f-22934032a5d 117->124 120 22934032b7d-22934032b98 118->120 123->120 127 22934032a5f-22934032a6f 124->127 128 22934032a71-22934032aa9 SysAllocString 124->128 125->116 133 229340329d1-229340329d9 125->133 129 229340329fb-229340329fd 126->129 134 22934032ab9-22934032abc 127->134 137 22934032aad-22934032ab1 128->137 129->111 129->116 133->129 136 229340329db-229340329f1 133->136 134->123 135 22934032ac2-22934032ad7 134->135 135->123 140 22934032add-22934032b0e 135->140 139 229340329f6 136->139 137->134 139->129 140->123 142 22934032b10-22934032b1c 140->142 143 22934032b1e-22934032b31 142->143 144 22934032b33-22934032b59 142->144 143->143 143->144 146 22934032b5b-22934032b6f 144->146 147 22934032b71-22934032b74 SafeArrayDestroy 144->147 146->146 146->147 147->123
                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022934010000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_22934010000_aspnet_compiler.jbxd
                        Yara matches
                        Similarity
                        • API ID: AllocArrayCreateDestroyInstanceSafeString
                        • String ID:
                        • API String ID: 815377780-0
                        • Opcode ID: dae33ee218254d575b2f885f916d6963ffe40f3360d10ef8a927e24c671039fc
                        • Instruction ID: 7a60d8243bc9755817875281088f6ee5deed5c439dbffac0438a07ee39778c9a
                        • Opcode Fuzzy Hash: dae33ee218254d575b2f885f916d6963ffe40f3360d10ef8a927e24c671039fc
                        • Instruction Fuzzy Hash: AA814C30218E089FD768EF28D8897A6BBE0FF9A305F1146ADD49AC7151DB30E5458F82

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 148 229340343b4-229340343d0 149 229340343eb-229340343fa 148->149 150 229340343d2-229340343d6 148->150 152 229340343fc-22934034421 149->152 153 22934034426-22934034438 149->153 150->149 151 229340343d8-229340343e9 150->151 151->149 151->150 152->153 154 2293403443b-22934034442 153->154 155 2293403447d-22934034482 LoadLibraryA 154->155 156 22934034444-22934034453 154->156 157 22934034485-22934034494 155->157 158 22934034470-22934034476 156->158 159 22934034455-2293403446e call 22934034c20 156->159 158->154 161 22934034478-2293403447b 158->161 159->158 163 22934034495-22934034498 159->163 161->155 161->157 163->157
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022934010000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_22934010000_aspnet_compiler.jbxd
                        Yara matches
                        Similarity
                        • API ID: LibraryLoad
                        • String ID: l
                        • API String ID: 1029625771-2517025534
                        • Opcode ID: 1385f4a438fc17bb376d03bd0145f1e19b120c532c3e81762a8c516170bfbca4
                        • Instruction ID: 32d504d45a7d1a745f7e6d5b8270f2b962a192c847e03d8b7d604c92f20983aa
                        • Opcode Fuzzy Hash: 1385f4a438fc17bb376d03bd0145f1e19b120c532c3e81762a8c516170bfbca4
                        • Instruction Fuzzy Hash: 3531942061CA855FE795DB68C048726BFD5FBAA308F2556FCC0DAC7152D730D8868B01

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.3400141664.0000022934010000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022934010000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_22934010000_aspnet_compiler.jbxd
                        Yara matches
                        Similarity
                        • API ID: ProtectVirtual$LibraryLoad
                        • String ID:
                        • API String ID: 895956442-0
                        • Opcode ID: b17c4479f7010fd41cbad95f9fb04bd4be79ef02ed8fc175b75ead6b9ebb131e
                        • Instruction ID: 6f5ab1c0fd9e7ab4cc248ea5819121a12231d218d6713ae1326da7ea8d5ae72a
                        • Opcode Fuzzy Hash: b17c4479f7010fd41cbad95f9fb04bd4be79ef02ed8fc175b75ead6b9ebb131e
                        • Instruction Fuzzy Hash: 2C11C830728A085BDB95EB68D8C976A77E5FBDD700F0015B9AC4AD7285DE30DD818B81

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 175 7ffd348564ae-7ffd3485650f 176 7ffd34856511 175->176 177 7ffd34856516-7ffd348570eb 175->177 176->177 199 7ffd348570f3-7ffd3485710b 177->199
                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID: U$t
                        • API String ID: 0-1612724633
                        • Opcode ID: d9624b0c150e1109a2fb89e6379ea7b3cb498cf62579b340a7c8dd133e7eef3d
                        • Instruction ID: 28760845f05ca31fba17cdbf00d657217252f47a302be6e43cfc1c92b333d795
                        • Opcode Fuzzy Hash: d9624b0c150e1109a2fb89e6379ea7b3cb498cf62579b340a7c8dd133e7eef3d
                        • Instruction Fuzzy Hash: 8DA14D70A08A5E8FDB99DF68C865BD8B7F1EF5A300F5401EAD44DD7292CA3869C1CB11

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 201 7ffd3485d47a-7ffd3485d47e 202 7ffd3485d480-7ffd3485d483 201->202 203 7ffd3485d4ff 201->203 202->203 204 7ffd3485d50a-7ffd3485d538 call 7ffd3485a370 203->204 207 7ffd3485d591-7ffd3485d596 204->207 208 7ffd3485d53a-7ffd3485d53d 204->208 209 7ffd3485d5be-7ffd3485d5fe 208->209 210 7ffd3485d53f-7ffd3485d542 208->210 212 7ffd3485db11-7ffd3485db1d 209->212 213 7ffd3485d603-7ffd3485d613 212->213 214 7ffd3485db23 212->214 215 7ffd3485d66c-7ffd3485d66d 213->215 216 7ffd3485d615-7ffd3485d61d 213->216 217 7ffd3485db27-7ffd3485db32 214->217 215->212 216->215 219 7ffd3485db33 217->219 220 7ffd3485dbac 217->220 222 7ffd3485db34-7ffd3485db38 219->222 223 7ffd3485db8c-7ffd3485db96 219->223 221 7ffd3485dbb9-7ffd3485dbd6 220->221 236 7ffd3485dbda-7ffd3485dbdc 221->236 222->221 226 7ffd3485db3a-7ffd3485db59 222->226 224 7ffd3485db98-7ffd3485dba0 223->224 225 7ffd3485dc07-7ffd3485dc1e call 7ffd3485a370 223->225 224->217 231 7ffd3485dba2 224->231 234 7ffd3485dc20-7ffd3485dc23 225->234 235 7ffd3485dc77-7ffd3485dc7a 225->235 226->236 242 7ffd3485db5b-7ffd3485db64 226->242 231->220 238 7ffd3485dca4-7ffd3485dcc7 234->238 239 7ffd3485dc25-7ffd3485dc28 234->239 235->238 240 7ffd3485dbde 236->240 241 7ffd3485dc58-7ffd3485dc70 236->241 247 7ffd3485dcc9 238->247 248 7ffd3485dd38-7ffd3485dddb 238->248 239->241 243 7ffd3485dbe0-7ffd3485dbf7 240->243 244 7ffd3485db65-7ffd3485db87 240->244 252 7ffd3485dcec 241->252 254 7ffd3485dc72 241->254 242->244 255 7ffd3485dbf9-7ffd3485dc04 243->255 244->223 247->252 256 7ffd3485dde3-7ffd3485ddf5 248->256 257 7ffd3485dddd-7ffd3485dde2 248->257 252->248 254->255 258 7ffd3485dc74 254->258 255->225 259 7ffd3485de3f-7ffd3485de55 256->259 260 7ffd3485ddf7-7ffd3485de3c 256->260 257->256 258->235 263 7ffd3485de9f-7ffd3485defc 259->263 264 7ffd3485de57-7ffd3485de9a 259->264 260->259 265 7ffd3485defe-7ffd3485df05 263->265 266 7ffd3485df07-7ffd3485df0c 263->266 265->266 268 7ffd3485df0e-7ffd3485df13 266->268 269 7ffd3485df19-7ffd3485df4c 266->269 268->269 270 7ffd3485df4e-7ffd3485df52 269->270 271 7ffd3485df5d-7ffd3485dfbc 269->271 270->271 273 7ffd3485dfbe-7ffd3485dfc8 271->273 274 7ffd3485dfeb-7ffd3485dff0 271->274 275 7ffd3485dfca-7ffd3485dfe7 273->275 276 7ffd3485dff9-7ffd3485e011 273->276 275->274 277 7ffd3485e014-7ffd3485e021 276->277 278 7ffd3485e013 276->278 279 7ffd3485e024-7ffd3485e064 277->279 280 7ffd3485e023 277->280 278->277 282 7ffd3485e06b-7ffd3485e09c 279->282 283 7ffd3485e066 279->283 280->279 285 7ffd3485e09e-7ffd3485e0ab 282->285 286 7ffd3485e0b0-7ffd3485e0c3 282->286 283->282 287 7ffd3485e1a9-7ffd3485e229 285->287 288 7ffd3485e0ca-7ffd3485e0d4 286->288 289 7ffd3485e0c5 286->289 294 7ffd3485e231-7ffd3485e2d8 287->294 295 7ffd3485e22b-7ffd3485e230 287->295 290 7ffd3485e183-7ffd3485e189 288->290 289->288 292 7ffd3485e18f-7ffd3485e19c 290->292 293 7ffd3485e0d9-7ffd3485e0ee 290->293 297 7ffd3485e1a3-7ffd3485e1a7 292->297 298 7ffd3485e19e 292->298 299 7ffd3485e0f0 293->299 300 7ffd3485e0f5-7ffd3485e105 293->300 295->294 297->287 298->297 299->300 303 7ffd3485e11d-7ffd3485e133 300->303 304 7ffd3485e107-7ffd3485e114 300->304 305 7ffd3485e13a-7ffd3485e159 303->305 306 7ffd3485e135 303->306 304->287 307 7ffd3485e16c-7ffd3485e179 305->307 308 7ffd3485e15b-7ffd3485e169 305->308 306->305 310 7ffd3485e180 307->310 311 7ffd3485e17b 307->311 308->287 308->307 310->290 311->310
                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID: N
                        • API String ID: 0-1130791706
                        • Opcode ID: 96105c07e1173eb1120e2fcffa87b865f8ebdfea7311b79bcb2259dec24ca03b
                        • Instruction ID: c3bf024245a10453a7eeec1a56b2d33e55e25b24d51cd09ffd54041c1b6a7915
                        • Opcode Fuzzy Hash: 96105c07e1173eb1120e2fcffa87b865f8ebdfea7311b79bcb2259dec24ca03b
                        • Instruction Fuzzy Hash: 3622F37190D28A8FDB12DB2488656E97FF0EF13314F0542EBC449DB1E3DA385A49CB91

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 416 7ffd34856008-7ffd34856035 417 7ffd34856039 416->417 418 7ffd34856037 416->418 419 7ffd3485603a-7ffd34856081 417->419 418->417 418->419 421 7ffd34856083 419->421 422 7ffd34856088-7ffd348560cf 419->422 421->422 423 7ffd348560d1 422->423 424 7ffd348560d6-7ffd34856146 422->424 423->424 432 7ffd3485614d-7ffd34856168 424->432 433 7ffd34856148 424->433 435 7ffd34856172-7ffd348561c0 432->435 433->432
                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID: U
                        • API String ID: 0-3372436214
                        • Opcode ID: c61deb044dc1639665089ffabd052027acab14e3dbee64de58a9b44e43ebd154
                        • Instruction ID: 8298474837f1f3923348d32c94f07e6be69333a4d5b292abf3e2890f8630a0b5
                        • Opcode Fuzzy Hash: c61deb044dc1639665089ffabd052027acab14e3dbee64de58a9b44e43ebd154
                        • Instruction Fuzzy Hash: F951C031A4E78A4FD7539BA488746E9BFB1EF47210F4901E6D448DB1A3CA2C1989C762

                        Control-flow Graph

                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 46168616d60b09a6c863b1d1935de82f7e126866da5bc81385dac99ee39db090
                        • Instruction ID: 4ecbc1e444c1b60d57c269b2bc08ee7f41d77209ac463b4518e420921ae46f8f
                        • Opcode Fuzzy Hash: 46168616d60b09a6c863b1d1935de82f7e126866da5bc81385dac99ee39db090
                        • Instruction Fuzzy Hash: 58722D30A08A4A8FDB95EF78C968698BBF1FF5A340F0540E6C44DDB262DA785DC1CB11

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1031 7ffd3485ea75-7ffd3485eace 1032 7ffd3485ead0 1031->1032 1033 7ffd3485ead5-7ffd3485eb0d 1031->1033 1032->1033 1035 7ffd3485ebb5-7ffd3485ebbb 1033->1035 1036 7ffd3485eb12-7ffd3485eb28 1035->1036 1037 7ffd3485ebc1-7ffd3485ebd9 1035->1037 1038 7ffd3485eb2f-7ffd3485eb8a 1036->1038 1039 7ffd3485eb2a 1036->1039 1040 7ffd3485ebed-7ffd3485ec03 1037->1040 1041 7ffd3485ebdb-7ffd3485ebe8 1037->1041 1059 7ffd3485eb9d-7ffd3485ebab 1038->1059 1060 7ffd3485eb8c-7ffd3485eb9a 1038->1060 1039->1038 1043 7ffd3485ec0a-7ffd3485ec32 1040->1043 1044 7ffd3485ec05 1040->1044 1042 7ffd3485efd3-7ffd3485f05c 1041->1042 1049 7ffd3485f064-7ffd3485f117 1042->1049 1050 7ffd3485f05e-7ffd3485f063 1042->1050 1046 7ffd3485ec34 1043->1046 1047 7ffd3485ec39-7ffd3485ec68 1043->1047 1044->1043 1046->1047 1054 7ffd3485ec6f-7ffd3485ecac 1047->1054 1055 7ffd3485ec6a 1047->1055 1050->1049 1067 7ffd3485ecb3-7ffd3485ecf5 1054->1067 1068 7ffd3485ecae 1054->1068 1055->1054 1063 7ffd3485ebb2 1059->1063 1064 7ffd3485ebad 1059->1064 1060->1037 1063->1035 1064->1063 1070 7ffd3485ecfc-7ffd3485ef52 1067->1070 1071 7ffd3485ecf7 1067->1071 1068->1067 1073 7ffd3485ed0a-7ffd3485ed2d 1070->1073 1074 7ffd3485ef58-7ffd3485ef6e 1070->1074 1071->1070 1075 7ffd3485ed34-7ffd3485ed70 1073->1075 1076 7ffd3485ed2f 1073->1076 1077 7ffd3485ef70 1074->1077 1078 7ffd3485ef75-7ffd3485ef92 1074->1078 1089 7ffd3485ed72 1075->1089 1090 7ffd3485ed77-7ffd3485edb4 1075->1090 1076->1075 1077->1078 1079 7ffd3485ef94 1078->1079 1080 7ffd3485ef99-7ffd3485efa7 1078->1080 1079->1080 1082 7ffd3485efae-7ffd3485efb1 1080->1082 1083 7ffd3485efa9 1080->1083 1084 7ffd3485efb3 1082->1084 1085 7ffd3485efb8-7ffd3485efbc call 7ffd34858060 1082->1085 1083->1082 1084->1085 1088 7ffd3485efc1-7ffd3485efd1 1085->1088 1088->1042 1089->1090 1092 7ffd3485ee13-7ffd3485ee25 1090->1092 1093 7ffd3485edb6-7ffd3485edda 1090->1093 1096 7ffd3485ee2c-7ffd3485ee5c 1092->1096 1097 7ffd3485ee27 1092->1097 1094 7ffd3485ede1-7ffd3485ee08 1093->1094 1095 7ffd3485eddc 1093->1095 1094->1092 1095->1094 1100 7ffd3485ee5e-7ffd3485ee5f 1096->1100 1101 7ffd3485ee6b-7ffd3485eea7 1096->1101 1097->1096 1100->1074 1102 7ffd3485eeae-7ffd3485eeb9 1101->1102 1103 7ffd3485eea9 1101->1103 1103->1102
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8031e8d84d3471112c0cfc66663485bc52abb07d6d0966587e4eede2714bdc2d
                        • Instruction ID: 731a8085a25513fe0e6b2b25bb89bae2b6cd84d9131c37e46a31ee107fa8dbb3
                        • Opcode Fuzzy Hash: 8031e8d84d3471112c0cfc66663485bc52abb07d6d0966587e4eede2714bdc2d
                        • Instruction Fuzzy Hash: 6E124B31A1861D8FDB58EF68C8A47EDB7B1FF59304F2041A9D00DE7286CB39A985CB54
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c89ace391be62c25d3d20c870a62d459ec14d68a6dba04c3169c8958a034983c
                        • Instruction ID: 5864367fc1561dedb14dc52430506879acfd05d2294de983e2bf0e8038c275f0
                        • Opcode Fuzzy Hash: c89ace391be62c25d3d20c870a62d459ec14d68a6dba04c3169c8958a034983c
                        • Instruction Fuzzy Hash: 4CB1A93284E38D8FD7625B2489A52E97FB0FF47310F4901E6D945C60E3EB2D6518D742
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d061917d3aafc8b559b10247c323b95968b4644b909baa524a2822be34484298
                        • Instruction ID: d9e068565d952ce947963a35d8d08abe97a198497f4e6e2eb8f8c9bdaf281f21
                        • Opcode Fuzzy Hash: d061917d3aafc8b559b10247c323b95968b4644b909baa524a2822be34484298
                        • Instruction Fuzzy Hash: 3551F772E0D68D4FE761EB6898652F87BA0EF46320F4401FBC58CD7192DE285955C741
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d7b9d831aa21293ad639a98ea4292d5e083f580f2f809cf5a18d4826a00c5fd7
                        • Instruction ID: 29beff733ee680a2adc33cc9d9960b849443b05ad16d28476d1f5faa7f59f505
                        • Opcode Fuzzy Hash: d7b9d831aa21293ad639a98ea4292d5e083f580f2f809cf5a18d4826a00c5fd7
                        • Instruction Fuzzy Hash: 1FB12E70A08A5D9FDF95EF68C854BA9BBF1FF5A300F0401AAD44DE7252DB34A981CB41
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8bc910b203ada6b2a597a23fbd6e869409b370a4fb871124ce9d8574c64ab47f
                        • Instruction ID: c2b6623febc7f851187c7d2c9eeb5b1ecdff3c3e2c1e7f1813bd82b97dab2672
                        • Opcode Fuzzy Hash: 8bc910b203ada6b2a597a23fbd6e869409b370a4fb871124ce9d8574c64ab47f
                        • Instruction Fuzzy Hash: 22C17271A08A5D8FDB95EF68D8A47E87BF1FF59300F1401EAD04DE7292DA34A985CB01
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: bb267599817318000482de84e448fb4012400d68af4e6b16eec02325527c4f91
                        • Instruction ID: 448ac8e50b38cce6672de58a8c0c47cc4c91353bb01aed0e877c7ea2d09d9f10
                        • Opcode Fuzzy Hash: bb267599817318000482de84e448fb4012400d68af4e6b16eec02325527c4f91
                        • Instruction Fuzzy Hash: 1AB1FC70A08A5D8FDB95EF68C4A4BACB7F1FF59300F5441EAD04DE7292DA34A985CB01
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4c4c42e02981655de809f311612691866c64d636655aea8d0a94e36e17641d0c
                        • Instruction ID: 36ff57d6e9a35c821c6ce00fd6d2f9f248f99a07e27f2ae31de701bd9217e858
                        • Opcode Fuzzy Hash: 4c4c42e02981655de809f311612691866c64d636655aea8d0a94e36e17641d0c
                        • Instruction Fuzzy Hash: 65B1E970E08A4D8FDB95EFA8D494AACBBF1FF5A301F4501A6D40DE7252DB34A981CB01
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 50534c1e231a4815675ee809ce08641ede4a3a28c85a4a44fdbbf1f2a152acf4
                        • Instruction ID: a9574e3d99d809f6669e87eef1630ff9238bb83bc643d03088defc2b4c4c6aef
                        • Opcode Fuzzy Hash: 50534c1e231a4815675ee809ce08641ede4a3a28c85a4a44fdbbf1f2a152acf4
                        • Instruction Fuzzy Hash: F2A1DF31A4964E8FDB95DFA4C8A86ED7BB0FF47310F1001AAD009D7292DB3DA985CB51
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7ab568508f055cbaf4966edcba770a9971a9aa0a23783ad3a097bc80007ca93f
                        • Instruction ID: 1e7a5c004445e45162d3b357e03c6bcdae648f3da89c0a1aebcc812db5445bb1
                        • Opcode Fuzzy Hash: 7ab568508f055cbaf4966edcba770a9971a9aa0a23783ad3a097bc80007ca93f
                        • Instruction Fuzzy Hash: 9E616516BEF25B16E19237B864FB0FF2A549F43319F846DB2E25CC50DB8C4C30096295
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8de626d4d330db5dfced4b3dddf5cd2e764b92adf6af0dd989da3299907c7e85
                        • Instruction ID: cb62ecd5e3ec85fbfd1563ee76248c7e33dc0d53e3d17bdacf7230a0877925c9
                        • Opcode Fuzzy Hash: 8de626d4d330db5dfced4b3dddf5cd2e764b92adf6af0dd989da3299907c7e85
                        • Instruction Fuzzy Hash: FA91EA70A08A5DCFDB95EF6CD494A98BBF1FF5A300F5501AAD40DDB251DB34A981CB01
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e6ca2ee1294cc44207ec01a04e6e23ae11db8a88db7f7361ab5e280535755270
                        • Instruction ID: 6e3fe0283c9b4d77acb93df43a164021819e68a6a6933927cd571288977690d8
                        • Opcode Fuzzy Hash: e6ca2ee1294cc44207ec01a04e6e23ae11db8a88db7f7361ab5e280535755270
                        • Instruction Fuzzy Hash: 9E614516AEF25B19E292377864FB1FF2A549F43319F846DF6E25CC90DB8C4C31096291
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e8a72c494b56098513d2b5b47db696b139b5dbac62ba3cb83472ec8e78b91aad
                        • Instruction ID: bc685698ce760368ed71de4a32e49bfd82daebfc51ff4e9fb8098d2c7ba6afb6
                        • Opcode Fuzzy Hash: e8a72c494b56098513d2b5b47db696b139b5dbac62ba3cb83472ec8e78b91aad
                        • Instruction Fuzzy Hash: EE513416AEF29B19E292377864FA1FF2A54DF43319F846DF6E25CC60DB8C4C31096291
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1e5ebfccd4c5098ec6c0d74c53d948f94cb82b56cb4e4a215139e31bb6288bda
                        • Instruction ID: 6cc0f9873d15056231e5138d9f8e94a92ce67ade1ddee556b66058c78551b2ce
                        • Opcode Fuzzy Hash: 1e5ebfccd4c5098ec6c0d74c53d948f94cb82b56cb4e4a215139e31bb6288bda
                        • Instruction Fuzzy Hash: B7719470A08A1D9FDF94EF68C899BACB7F1FF69301F1001AAD40DE7251CA74A881CB40
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 34f7181c8efecebbd91a83dca9e7a062dd720c12aefb9b4dbdfcad41c47446e8
                        • Instruction ID: 3f9cef2a592a7b73afa8e1ff2cea3e9e066d5406aed6510b3c28898b52c30c93
                        • Opcode Fuzzy Hash: 34f7181c8efecebbd91a83dca9e7a062dd720c12aefb9b4dbdfcad41c47446e8
                        • Instruction Fuzzy Hash: 90816F31D0961E8FEBA5EB14C8E1AE9B7B5FF12301F0002F9D50DD7191DA386A89DB81
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f2e3d120e5499c4138221da5dd2c82c1b44294b6f1d6cb821a947b3c1f3f315d
                        • Instruction ID: c5ae680dddd3d43d2ec213276104b4917ce80dd3b10dcd2bb5a1087f1f73321a
                        • Opcode Fuzzy Hash: f2e3d120e5499c4138221da5dd2c82c1b44294b6f1d6cb821a947b3c1f3f315d
                        • Instruction Fuzzy Hash: 35510C16AEF24B19E2927B7454FA1FF2A50DF43309F856DF6E24CC60DB8C4D35086692
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5592a009f7a565714e2a3e2b69b277221eddeda1352d53aa186d4fc7b9fd3388
                        • Instruction ID: 8922859445fff2b7c223e7470cdc11f003edb9b095b526376899291d07eedecb
                        • Opcode Fuzzy Hash: 5592a009f7a565714e2a3e2b69b277221eddeda1352d53aa186d4fc7b9fd3388
                        • Instruction Fuzzy Hash: D7519E31A08A0E8FDB58EB58C8A06FDB7A5FF55314F1041BAD50DE3296DE38A945CB50
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 58ee3af9fa20f8e3dcde1176fb6c0062077963edc87cb22bfb220ae0f689c14e
                        • Instruction ID: 87b5a5f9811ee42966661a5d2f5a3f9e0f34056ff265e1346fad0dfa5594cc44
                        • Opcode Fuzzy Hash: 58ee3af9fa20f8e3dcde1176fb6c0062077963edc87cb22bfb220ae0f689c14e
                        • Instruction Fuzzy Hash: 9E41D416BEF19B19E292377864FA4FE2A54DF83329F846DF6E25CC50DB8C4C34056291
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b02bcdb1d990846b79b8e1b753bdad1d505de5c2177e4f148891e1b9f0c0cabd
                        • Instruction ID: 8050491208f472f9dd6870cc68b4c4c145a973660b3cfff519efa2c36ee17092
                        • Opcode Fuzzy Hash: b02bcdb1d990846b79b8e1b753bdad1d505de5c2177e4f148891e1b9f0c0cabd
                        • Instruction Fuzzy Hash: 9741B415AEF20B65E5923B3850FA5FB1990EF03709F906DF4E20C8549B5D9D32186692
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b77780ba86526c2675219bdef200883c6376c185d06aa7edcc499614b862c243
                        • Instruction ID: 55a9dac7612712a4d0b70f1fe0681a6dec732338ca1ac1bb53d9533a32c820b3
                        • Opcode Fuzzy Hash: b77780ba86526c2675219bdef200883c6376c185d06aa7edcc499614b862c243
                        • Instruction Fuzzy Hash: E251C131E4960A8FDBA5EF64C4A46BD7BB1FF06300F1001B9C109E7296DB396445CB11
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4bb77f77871a48d16be0216a685000762a3162c92a83818f087b4c6fe2d797b3
                        • Instruction ID: 9a001a05b00be75e64b2f952c29e051e2678b6999307a6411b67fb5736dab87b
                        • Opcode Fuzzy Hash: 4bb77f77871a48d16be0216a685000762a3162c92a83818f087b4c6fe2d797b3
                        • Instruction Fuzzy Hash: CA41DF31B0860E8BDB58EB58C8A06FDB7A4FF95311F1041BAD60DE7182DA38AA45CB50
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 56ea01d22c1ed270bd6491dc1d52a606d6bccba84e881564d8abfda1e4758189
                        • Instruction ID: a89dbda85cdb2f7b2ca5d3e1198ea339be1ac6d69b75b9947c030cfd22f97a31
                        • Opcode Fuzzy Hash: 56ea01d22c1ed270bd6491dc1d52a606d6bccba84e881564d8abfda1e4758189
                        • Instruction Fuzzy Hash: DD319372A09A4B5FE795AB7898A51EC7BE1EF47314F0500F6D548E7293CE2C28869701
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1fe34ff6d5d9d1d576c2f279c9e4f8a2849458f3e5d2432407fd111c2efda7b0
                        • Instruction ID: 90aaf863c54cd88b5c4488461c16388a2886461b3dd8a9d93e9c44cc140e2553
                        • Opcode Fuzzy Hash: 1fe34ff6d5d9d1d576c2f279c9e4f8a2849458f3e5d2432407fd111c2efda7b0
                        • Instruction Fuzzy Hash: 9631B272A09A4B5FE795AB7898A51EC7BE1EF47314F0500F6D548E7293CE2C2882D701
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 03e3a828c8e46987eb644ed64854e47adecf1799f4f80f909e3074509ccac260
                        • Instruction ID: 9e315a4c731a302edc32ad192418dd39288470e72344a3f8d378f0c7ad3ff7a9
                        • Opcode Fuzzy Hash: 03e3a828c8e46987eb644ed64854e47adecf1799f4f80f909e3074509ccac260
                        • Instruction Fuzzy Hash: 8D317C3188E7CA4FC7439BB08C646E67FB4EF17210B0A05E7E488CB1A3D66D5959C762
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fb311c1f237b13adbae6e5c1dd9cc40014a569404b2d6d85a09c775eb379109b
                        • Instruction ID: 6ace61cd6c55dd59a6b41ba77e0bf2dd76532a98c00d721030e6455c3f69ac97
                        • Opcode Fuzzy Hash: fb311c1f237b13adbae6e5c1dd9cc40014a569404b2d6d85a09c775eb379109b
                        • Instruction Fuzzy Hash: BC31A132A49A8B9FE795AB7898A55EC7BF1EF47314F4500F6D548E7293CE2C2881C701
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 40f0117daef7f21b322ffb5efeaff48b2c65a9763e02801d34bf281982fa2a66
                        • Instruction ID: 6706bc4b021e86e29f579bd2f9902054f50b1d9290f6c3db9a022ca3f0328ab8
                        • Opcode Fuzzy Hash: 40f0117daef7f21b322ffb5efeaff48b2c65a9763e02801d34bf281982fa2a66
                        • Instruction Fuzzy Hash: 0131D271E1862D8FDBA8DB58D4A4BEDB7B1FB59311F1041A9D10EE3291DB38A984DF00
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c20d83797b07905cdb45ec55636210c80c0764ab9822ebccb5c16f1a5c35af70
                        • Instruction ID: 4a84b27da7fee1403e0ec496aa71924210e22e2c2e389ecedfe86e50d8db26f0
                        • Opcode Fuzzy Hash: c20d83797b07905cdb45ec55636210c80c0764ab9822ebccb5c16f1a5c35af70
                        • Instruction Fuzzy Hash: 5F213630D1861E8FEB95DF95C890BEDB7B1FF45300F1082A9D109A3285DB786A86DF80
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cedd1797187bb5d576d491a3a249993eb520d970bee47b39012140ada7a86312
                        • Instruction ID: 7f08543e3b9d9850c820ef8515b33dd45f1adf98fe3f19433d646a9ec4ca2676
                        • Opcode Fuzzy Hash: cedd1797187bb5d576d491a3a249993eb520d970bee47b39012140ada7a86312
                        • Instruction Fuzzy Hash: 6711F871E0861D8EEB54EFA8C499AEDBBF1FF54301F10467AE049E7291DB386485DB40
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 418a095db2f8e661f19b8e17967ae83bb9d60bae348558266fa84979dc387b68
                        • Instruction ID: 49afca3345b69197915424bf8867d3a0576c37cbdc3cceb6d31dcfdefcb400a7
                        • Opcode Fuzzy Hash: 418a095db2f8e661f19b8e17967ae83bb9d60bae348558266fa84979dc387b68
                        • Instruction Fuzzy Hash: 59015E70E1861E8BEB99DF48C890BEDB7B1FF85304F1002A9D508E3290DB386A46DF40
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 742094a97631f4f54356b82a0b6e659c4bba7384ff6ec0dba89f0f6ed5c51033
                        • Instruction ID: b369b84c00ffb6718db84475a6d8738090e5539ae7d99f2d596d7996659d1160
                        • Opcode Fuzzy Hash: 742094a97631f4f54356b82a0b6e659c4bba7384ff6ec0dba89f0f6ed5c51033
                        • Instruction Fuzzy Hash: 2101DA70D1461D8FDBA9DF48C495BEDB7B5FF45304F1041A9D509E3290DB386A459B40
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3d1c13443941b8a7879bb4c8c78a74ddb121512364a22fe4d15db8a6aa0da6f3
                        • Instruction ID: 99d477329eee61e74dcfe7177eb2e5cfd386e7f812832039b713a4a51344dbd3
                        • Opcode Fuzzy Hash: 3d1c13443941b8a7879bb4c8c78a74ddb121512364a22fe4d15db8a6aa0da6f3
                        • Instruction Fuzzy Hash: 48F04F30D1860E8FEB99DF44C491BED73B0FF45300F1002A9D519E3290DA386A46DB40
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 013b74331ba42e573628efe77562e40c018317e1e93fceab5ac5d24e0a1112c0
                        • Instruction ID: 7760019048ece617cdbfd1d5650943d1c793d3e66517dce35ff44a0ec64d750c
                        • Opcode Fuzzy Hash: 013b74331ba42e573628efe77562e40c018317e1e93fceab5ac5d24e0a1112c0
                        • Instruction Fuzzy Hash: 5AE0C971D0552A8BEB68DB54C8A5BE8B3B0EF15304F0442FA941EE61D1EE342A89DE50
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 04abb71bb83205ca9c972773484773907a7787623d0778fef7459efb99bfd813
                        • Instruction ID: 62e0f302f398d286efacedb49e871dc63256e26921c77733fd9ac69b9eecff09
                        • Opcode Fuzzy Hash: 04abb71bb83205ca9c972773484773907a7787623d0778fef7459efb99bfd813
                        • Instruction Fuzzy Hash: C8A0025F74852235A12071DEB5124ED970DDAC33FB7144133E35DE40535944505A16A5
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8d06fc82bd91dd87f64410d4a1290a2197c08fe4e94cb62838a334a205274e7f
                        • Instruction ID: 757a3f532547c9725d908f9b6a70408f812b874a4ba037110021341bf7e49e9c
                        • Opcode Fuzzy Hash: 8d06fc82bd91dd87f64410d4a1290a2197c08fe4e94cb62838a334a205274e7f
                        • Instruction Fuzzy Hash:
                        Memory Dump Source
                        • Source File: 00000005.00000002.3407648749.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD34850000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_7ffd34850000_aspnet_compiler.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 559ca4c31145bd6c2b69452d308c1ba751ca7619bfe4cefa0c4f9cc619774586
                        • Instruction ID: d47069ebf618db5e60c13cb2cbad87cd67341911bcabf28aec9341aac7da6476
                        • Opcode Fuzzy Hash: 559ca4c31145bd6c2b69452d308c1ba751ca7619bfe4cefa0c4f9cc619774586
                        • Instruction Fuzzy Hash: B1E1EC70A08A1E8FDB94EF68C494BADB7F1FF59301F5041AAD40DE7291CA34A985CF11