Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-54h] |
19_2_01032132 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-18h] |
19_2_0103D134 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-18h] |
19_2_0103D0CE |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx edx, byte ptr [ecx+eax] |
19_2_010211B2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_0102600C |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_01026013 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp word ptr [ebp+edi+02h], 0000h |
19_2_01038312 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_0102539E |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_0105B3B2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 0633C81Dh |
19_2_010563F2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_01044215 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_01044215 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 1B788DCFh |
19_2_01055272 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx ebx, byte ptr [edx] |
19_2_0104C282 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_0104429B |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_0104429B |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_0105C2B2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_010582BB |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_010512FC |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 77A9E0C4h |
19_2_010512FC |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_0103F577 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov word ptr [eax], cx |
19_2_01038582 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-54h] |
19_2_010325AE |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+00000744h] |
19_2_010445CB |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [edi], al |
19_2_010445CB |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_010445CB |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-54h] |
19_2_01032403 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx ebp, word ptr [edi] |
19_2_01050432 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, 0000000Bh |
19_2_010454B5 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+10h] |
19_2_0101F4B2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp byte ptr [edi], 00000000h |
19_2_010274E1 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+ebx] |
19_2_01017712 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-14h] |
19_2_0104076F |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-14h] |
19_2_0104076F |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov word ptr [eax], cx |
19_2_0105B612 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], CECD21FDh |
19_2_0103D652 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], CECD21FDh |
19_2_0103D652 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_0103A692 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+edi] |
19_2_010166B2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp word ptr [ecx+eax+02h], 0000h |
19_2_0102F6C4 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-10h] |
19_2_01022911 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov dword ptr [esp], 00000000h |
19_2_0102C952 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_010259AB |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+28h] |
19_2_010259AB |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then push ebx |
19_2_0102F835 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_01059832 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 54CA534Eh |
19_2_01059832 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov edi, ecx |
19_2_010258A8 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx eax, word ptr [esi+ecx] |
19_2_01052B02 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [edi], al |
19_2_01044B4C |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then jmp ecx |
19_2_01050B62 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov edi, eax |
19_2_01018B72 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp word ptr [ebx+eax+02h], 0000h |
19_2_01030B95 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov word ptr [esi], ax |
19_2_01030B95 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 7E28BDA7h |
19_2_0105BBE2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then jmp eax |
19_2_01027BF4 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp byte ptr [edi], 00000000h |
19_2_01027AF3 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_01058D52 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 7E28BDA7h |
19_2_0105BD62 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-34h] |
19_2_01035D92 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-10h] |
19_2_01039DA7 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov ebx, dword ptr [edi+04h] |
19_2_01041DB2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+08h] |
19_2_01024DDD |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+20h] |
19_2_01043F33 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+20h] |
19_2_01043EB7 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_0105BFE2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-14h] |
19_2_01040E11 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [edi], al |
19_2_01044E18 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_01054E22 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [edi], al |
19_2_01044E2D |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov edi, dword ptr [ebp-3Ch] |
19_2_0103FEC1 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+20h] |
19_2_01043ED2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebp+edx*8+00h], 81105F7Ah |
19_2_0105BED2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, ebp |
19_2_0101BEE2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, ebp |
19_2_0101BEE2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+04h] |
19_2_01050EF0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx edx, byte ptr [ecx+eax] |
19_2_05A3F7B0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 7E28BDA7h |
19_2_05A7A1E0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+20h] |
19_2_05A624B5 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A7A5E0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+20h] |
19_2_05A62531 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, ebp |
19_2_05A3A4E0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, ebp |
19_2_05A3A4E0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+04h] |
19_2_05A6F4EE |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov edi, dword ptr [ebp-3Ch] |
19_2_05A5E4C2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+20h] |
19_2_05A624D0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebp+edx*8+00h], 81105F7Ah |
19_2_05A7A4D0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A73420 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [edi], al |
19_2_05A6342B |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-14h] |
19_2_05A5F40F |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [edi], al |
19_2_05A63419 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-54h] |
19_2_05A50730 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-18h] |
19_2_05A5B732 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-18h] |
19_2_05A5B6CC |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_05A4460A |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_05A44611 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp word ptr [ebx+eax+02h], 0000h |
19_2_05A4F193 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov word ptr [esi], ax |
19_2_05A4F193 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then jmp eax |
19_2_05A461F2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx eax, word ptr [esi+ecx] |
19_2_05A71100 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then jmp ecx |
19_2_05A6F160 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov edi, eax |
19_2_05A37170 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [edi], al |
19_2_05A6314A |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp byte ptr [edi], 00000000h |
19_2_05A460F1 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-10h] |
19_2_05A583A5 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov ebx, dword ptr [edi+04h] |
19_2_05A603B0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-34h] |
19_2_05A54390 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+08h] |
19_2_05A433DB |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 7E28BDA7h |
19_2_05A7A360 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A77350 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+ebx] |
19_2_05A35D10 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-14h] |
19_2_05A5ED6D |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-14h] |
19_2_05A5ED6D |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+edi] |
19_2_05A34CB0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A58C90 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp word ptr [ecx+eax+02h], 0000h |
19_2_05A4DCC2 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov word ptr [eax], cx |
19_2_05A79C10 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], CECD21FDh |
19_2_05A5BC50 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], CECD21FDh |
19_2_05A5BC50 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_05A43FA9 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+28h] |
19_2_05A43FA9 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-10h] |
19_2_05A40F0F |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov dword ptr [esp], 00000000h |
19_2_05A4AF50 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov edi, ecx |
19_2_05A43EA6 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A77E30 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 54CA534Eh |
19_2_05A77E30 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then push ebx |
19_2_05A4DE33 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A799B0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_05A4399C |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 0633C81Dh |
19_2_05A749F0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp word ptr [ebp+edi+02h], 0000h |
19_2_05A56910 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A7A8B0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
19_2_05A768B9 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx ebx, byte ptr [edx] |
19_2_05A6A880 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_05A62899 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_05A62899 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A6F8FA |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 77A9E0C4h |
19_2_05A6F8FA |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_05A62813 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_05A62813 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp dword ptr [ebx+edx*8], 1B788DCFh |
19_2_05A73870 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-54h] |
19_2_05A50BAC |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov word ptr [eax], cx |
19_2_05A56B80 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esi+00000744h] |
19_2_05A62BC9 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [edi], al |
19_2_05A62BC9 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov byte ptr [ebx], al |
19_2_05A62BC9 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
19_2_05A5DB75 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [esp+10h] |
19_2_05A3DAB0 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, 0000000Bh |
19_2_05A63AB3 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then cmp byte ptr [edi], 00000000h |
19_2_05A45ADF |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then movzx ebp, word ptr [edi] |
19_2_05A6EA30 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_il222.zip\PrivacyDrive.exe |
Code function: 4x nop then mov eax, dword ptr [ebp-54h] |
19_2_05A50A01 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.175.87.197 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.13 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.13 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.13 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.13 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.13 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.13 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: global traffic |
HTTP traffic detected: GET /uploads/il2.txt HTTP/1.1Host: finalstepgo.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: finalstepgo.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://finalstepgo.com/uploads/il2.txtAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=2bKyk+phhzcxLy4&MD=VEcd6h4b HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com |
Source: global traffic |
HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com |
Source: global traffic |
HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIkqHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /async/ddljson?async=ntp:2 HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIkqHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /uploads/il222.zip HTTP/1.1Host: finalstepgo.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.gapi.en.SpvAvsXfWWo.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AACA/rs=AHpOoo-MoqWi0fF1M09Ccs-6QfulXvxfdg/cb=gapi.loaded_0 HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIkqHLAQiFoM0BCLnKzQEIitPNAQjB1M0BCLrYzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=2bKyk+phhzcxLy4&MD=VEcd6h4b HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com |
Source: global traffic |
HTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br |
Source: global traffic |
HTTP traffic detected: GET /client/config?cc=CH&setlang=en-CH HTTP/1.1X-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateAccept-Encoding: gzip, deflateX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-UserAgeClass: UnknownX-BM-Market: CHX-BM-DateFormat: dd/MM/yyyyX-Device-OSSKU: 48X-BM-DTZ: -240X-DeviceID: 01000A41090080B6X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Search-TimeZone: Bias=300; DaylightBias=-60; TimeZoneKeyName=Eastern Standard TimeX-BM-Theme: 000000;0078d7X-Search-RPSToken: t%3DEwDoAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAAc3b2YHaGqVpvDt5fQD5WqyWe6yFx0NJba5UkXc18NyzzO727EJpRxajMi/a9VJGG3IbazdVCfGYDhgWix1bEZvF%2Bdi6BQDemUJPwGpTbVYCsJTXlSnyGJ9pvzXtUVpRc7a/IucKShQdkeIn8vjlkWQ7B633Nt88ruPHqsBG61WOzjNulLatGW7xuEYlrxV%2BAnUId2LPnjd3yXu39dIiVTHguri5j1XBxEHqhB/8RgSnKKM62AL1clVhb53mRWM362Q6dIqt85fZg5KeStaKPrIBled%2BkdJUzvKkym95jria/PiUdNMSRul6lJW3pVWndWcGee1xmuRa5Mb/7VE1NgkQZgAAEIjN2Vud26lqrpa0nLDGu7mwATElC8QCEnO8xLw8TUG3E9an0zcpJWgBIfsWEMqk4oxdn3M93RNPyGW1AjlXb6Gn06SvkSvESnWEl8Wy3kp9o6ejpwFdKJjdrk7hP6ZPSOLYmQiiYo1%2B1tZ5fAIOIIKQ44iMjdOSTkgtIdAxzwOu8gVhNL6PiW374UhLKIejrg9C1J/Pkmhmmiqj6pH/r/epLtFJWif%2BwQX13KWyyPTH7OXyukCnKh%2B/FnJjMl/%2B/KRwLRgllZnqiDw8TNu6i7WVri08tW6uWwioHgIeW6KGw7y3T/GADdXA0p1jxGHBBTIX1HgpKfBxb9XY6ZjIGxtXtUiDCkGR97GpPTGKxse8/Zhyul1ICKaK6Xxc3jXPpqlUivMvW6hV/TZTk7RXJEhnAlKYwqAHpQ7BO77iekqC5o1BgoDVu1sSh12WSziYoXkSEDemQjLyNIGzZsnoVDCfuP7EFUhDMUH5GmAdL7YqGiLffNCrogzj9okNNDGCflw7%2BG3/zT5pAGW11JKD3TdgQy0PuP/OfzJ5yAYJClx168oHYvHzegIaXl4V%2BwcCy5LQhl7RxmWmRyj4M4UARQg64NcB%26p%3DX-Agent-DeviceId: 01000A41090080B6X-BM-CBT: 1727365298User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045X-Device-isOptin: falseAccept-language: en-GB, en, en-USX-Device-Touch: falseX-Device-ClientSession: 2814152BF41F4137A196F50A19FC20E3X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIHost: www.bing.comConnection: Keep-AliveCookie: SRCHUID=V=2&GUID=C4EAB6C130004333A34B5668AE4E4D10&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=en; MUID=4 |