Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1525128
MD5:feb3d620cdd56c7fbe1c54ae29328327
SHA1:938774fde226ba51c661ecc5a45200081b0c5d5a
SHA256:30e8732cac1a2ab649d3aad8a297889cad6eb13754e4607d641a4a610f86ef27
Tags:exeuser-Bitsight
Infos:

Detection

Credential Flusher
Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Credential Flusher
AI detected suspicious sample
Binary is likely a compiled AutoIt script file
Found API chain indicative of sandbox detection
Machine Learning detection for sample
Contains functionality for read data from the clipboard
Contains functionality to block mouse and keyboard input (often used to hinder debugging)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to execute programs as a different user
Contains functionality to launch a process as a different user
Contains functionality to launch a program with higher privileges
Contains functionality to modify clipboard data
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality to simulate keystroke presses
Contains functionality to simulate mouse events
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
OS version to string mapping found (often used in BOTs)
Potential key logger detected (key state polling based)
Sample execution stops while process was sleeping (likely an evasion)
Sleep loop found (likely to delay execution)
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses taskkill to terminate processes

Classification

  • System is w10x64
  • file.exe (PID: 7144 cmdline: "C:\Users\user\Desktop\file.exe" MD5: FEB3D620CDD56C7FBE1C54AE29328327)
    • taskkill.exe (PID: 6236 cmdline: taskkill /F /IM chrome.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 6188 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskkill.exe (PID: 4548 cmdline: taskkill /F /IM msedge.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 4416 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskkill.exe (PID: 4632 cmdline: taskkill /F /IM firefox.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 1700 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskkill.exe (PID: 1284 cmdline: taskkill /F /IM opera.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 1072 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskkill.exe (PID: 5596 cmdline: taskkill /F /IM brave.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 2200 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • chrome.exe (PID: 6500 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobars MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 6884 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 7928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5084 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 7936 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5576 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Process Memory Space: file.exe PID: 7144JoeSecurity_CredentialFlusherYara detected Credential FlusherJoe Security
    No Sigma rule has matched
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: Submited SampleIntegrated Neural Analysis Model: Matched 98.4% probability
    Source: file.exeJoe Sandbox ML: detected
    Source: file.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
    Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.4:49769 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49784 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.4:49809 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49838 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49966 version: TLS 1.2
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081DBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose,0_2_0081DBBE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008268EE FindFirstFileW,FindClose,0_2_008268EE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime,0_2_0082698F
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081D076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose,0_2_0081D076
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081D3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose,0_2_0081D3A9
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00829642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose,0_2_00829642
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose,0_2_0082979D
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00829B2B FindFirstFileW,Sleep,FindNextFileW,FindClose,0_2_00829B2B
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00825C97 FindFirstFileW,FindNextFileW,FindClose,0_2_00825C97
    Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
    Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
    Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 172.202.163.200
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082CE44 InternetReadFile,SetEvent,GetLastError,SetEvent,0_2_0082CE44
    Source: global trafficHTTP traffic detected: GET /account?=https://accounts.google.com/v3/signin/challenge/pwd HTTP/1.1Host: youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /account?=https%3A%2F%2Faccounts.google.com%2Fv3%2Fsignin%2Fchallenge%2Fpwd HTTP/1.1Host: www.youtube.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
    Source: global trafficHTTP traffic detected: GET /accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1075052270&timestamp=1727972180607 HTTP/1.1Host: accounts.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-full-version: "117.0.5938.132"sec-ch-ua-arch: "x86"sec-ch-ua-platform: "Windows"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-model: ""sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://accounts.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "117.0.5938.132"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-wow64: ?0sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://accounts.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=UMfhhdA2rltUCLe&MD=zTzhemOD HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
    Source: global trafficHTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120600v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120608v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120609v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120402v21s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule224902v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120612v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120610v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120611v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120613v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120614v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120615v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120618v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120617v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120616v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120619v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120621v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120620v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120623v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120624v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120622v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120625v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120626v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120627v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120628v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120629v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=UMfhhdA2rltUCLe&MD=zTzhemOD HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
    Source: global trafficHTTP traffic detected: GET /rules/rule120633v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120630v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120634v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120635v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120636v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120632v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120631v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120637v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120639v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120638v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120641v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120640v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120642v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120643v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120644v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120645v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120646v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120647v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120648v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120649v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120652v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120653v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120654v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120655v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120656v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120657v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120658v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120659v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120660v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120661v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120662v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120663v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120664v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120665v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120666v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120668v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120667v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120669v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120670v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120671v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120673v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120672v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120674v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120675v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120676v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120678v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120677v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120679v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120680v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120681v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120682v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120602v10s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120601v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule224901v11s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule90401v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700401v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700400v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703901v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703900v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703351v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703350v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703500v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703501v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703400v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703401v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703600v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703601v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703850v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703851v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703801v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703800v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703701v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703700v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703751v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703750v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704051v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704050v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700601v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703950v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700600v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703951v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701401v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700000v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700001v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701400v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703051v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703050v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703550v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703551v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704001v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704000v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702401v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702400v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702601v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702600v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703301v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703300v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120128v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230104v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230157v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230162v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230158v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230165v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230164v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230167v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230166v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230168v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230170v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230171v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230169v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230172v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230173v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230174v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120119v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule224900v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704101v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704100v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704200v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704151v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704201v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704150v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule226009v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: chromecache_89.13.drString found in binary or memory: _.iq(p)+"/familylink/privacy/notice/embedded?langCountry="+_.iq(p);break;case "PuZJUb":a+="https://www.youtube.com/t/terms?chromeless=1&hl="+_.iq(m);break;case "fxTQxb":a+="https://youtube.com/t/terms?gl="+_.iq(_.rq(c))+"&hl="+_.iq(d)+"&override_hl=1"+(f?"&linkless=1":"");break;case "prAmvd":a+="https://www.google.com/intl/"+_.iq(m)+"/chromebook/termsofservice.html?languageCode="+_.iq(d)+"&regionCode="+_.iq(c);break;case "NfnTze":a+="https://policies.google.com/privacy/google-partners"+(f?"/embedded": equals www.youtube.com (Youtube)
    Source: global trafficDNS traffic detected: DNS query: youtube.com
    Source: global trafficDNS traffic detected: DNS query: www.youtube.com
    Source: global trafficDNS traffic detected: DNS query: www.google.com
    Source: global trafficDNS traffic detected: DNS query: accounts.youtube.com
    Source: global trafficDNS traffic detected: DNS query: play.google.com
    Source: chromecache_89.13.drString found in binary or memory: https://accounts.google.com
    Source: chromecache_89.13.drString found in binary or memory: https://accounts.google.com/TOS?loc=
    Source: file.exe, 00000000.00000003.2995170633.000000000173F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2995806750.0000000001742000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://accounts.google.com/v3/signin/challenge/pwd
    Source: chromecache_85.13.drString found in binary or memory: https://apis.google.com/js/api.js
    Source: chromecache_89.13.drString found in binary or memory: https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessage
    Source: chromecache_89.13.drString found in binary or memory: https://families.google.com/intl/
    Source: chromecache_85.13.drString found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/drive_2020q4/v10/192px.svg
    Source: chromecache_85.13.drString found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/gmail_2020q4/v10/web-48dp/logo_gmail_2020q4_color_2x_web_
    Source: chromecache_85.13.drString found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/maps/v7/192px.svg
    Source: chromecache_89.13.drString found in binary or memory: https://g.co/recover
    Source: chromecache_89.13.drString found in binary or memory: https://play.google.com/log?format=json&hasfast=true
    Source: chromecache_89.13.drString found in binary or memory: https://play.google.com/work/enroll?identifier=
    Source: chromecache_89.13.drString found in binary or memory: https://play.google/intl/
    Source: chromecache_89.13.drString found in binary or memory: https://policies.google.com/privacy
    Source: chromecache_89.13.drString found in binary or memory: https://policies.google.com/privacy/additional
    Source: chromecache_89.13.drString found in binary or memory: https://policies.google.com/privacy/google-partners
    Source: chromecache_89.13.drString found in binary or memory: https://policies.google.com/technologies/cookies
    Source: chromecache_89.13.drString found in binary or memory: https://policies.google.com/technologies/location-data
    Source: chromecache_89.13.drString found in binary or memory: https://policies.google.com/terms
    Source: chromecache_89.13.drString found in binary or memory: https://policies.google.com/terms/location
    Source: chromecache_89.13.drString found in binary or memory: https://policies.google.com/terms/service-specific
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-email-pin.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-password.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-sms-or-voice-pin.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-sms-pin.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-stop-go-landing-page_1x.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/animation/
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/ble_device.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/ble_pin.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync_1x.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync_2x.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync_darkmode_1x.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/continue_on_your_phone.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_phone_number_verification.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_prompt_silent_tap_yes_darkmode.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_prompt_tap_yes.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_prompt_tap_yes_darkmode.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kid_success.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kid_success_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_dark_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_updated.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_updated_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_not_ready.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_stick_around_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_stick_around_dark_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_account_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_account_darkmode_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_privacy_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_privacy_darkmode_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_created.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_double_device.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_double_device_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_full_house.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_link_accounts_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_link_accounts_darkmode_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_app_decision.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_app_decision_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_supervision_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_supervision_darkmode_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_respect_others_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_respect_others_darkmode_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_single_device.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_single_device_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_stop.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/personalization_reminders.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/phone_number_sign_in_2x.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/return_to_desktop.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/return_to_desktop_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_ios_center.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_laptop.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_nfc_discovered.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_nfc_discovered_darkmode.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_phone.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_googleapp_ios.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_googleapp_pulldown.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_tapyes.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/smart_lock_2x.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/usb_key.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/web_and_app_activity.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/who_will_be_using_this_device.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/you_tube_history.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/feature_not_available.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/feature_not_available_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/gmail_ios_authzen.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/paaskey.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_challenge.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_challenge_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_cross_device.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_cross_device_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_error.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_error_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_reauth.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_reauth_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_success.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_success_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkeyerror.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkeyerror_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/red_globe_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/red_globe_light.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/screenlock.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_ipad.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone_nfc.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone_usb.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_phone.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_keys.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/success_checkmark_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/success_checkmark_2_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/ui/loading_spinner_gm.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/ui/progress_spinner_color_20dp_4x.gif
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/ui/success-gm-default_2x.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/apps/signup/resources/custom-email-address.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/images/hpp/shield_security_checkup_green_2x_web_96dp.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/account_setup_chapter_dark_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/account_setup_chapter_v1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/device_setup_chapter_dark_v1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/device_setup_chapter_v1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/parental_control_chapter_dark_v1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/parental_control_chapter_v1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_accountslinked.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_accountslinked_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_childneedshelp.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_childneedshelp_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_nextstepsforparents.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_nextstepsforparents_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_allset.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_allset_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_apps_devices.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_apps_devices_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_areyousurekid.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_areyousurekid_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_birthdayemail.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_birthdayemail_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_choose_apps.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_choose_apps_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_confirmation.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_exploremore.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_exploremore_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_intro.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_intro_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacy_terms_a18.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacy_terms_a18_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacyterms.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacyterms_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_review_settings.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_review_settings_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_safe_search.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_safe_search_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_success_unchanged_a18.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_success_unchanged_a18_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_success_update_a18.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_success_update_a18_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice_a18.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice_a18_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervisiongrad.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervisiongrad_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/guardianlinking/linking_complete_0.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/guardianlinking/linking_complete_dark_0.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/ads_personalization.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/ads_personalization_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/confirmation.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/confirmation_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/eligibility_error.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/eligibility_error_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/fork.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/fork_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/intro.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/intro_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/personal_results.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/personal_results_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/safe_search.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/safe_search_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/check_notifications.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/check_notifications_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_installing_family_link_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_installing_family_link_dark_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_location_sharing_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_location_sharing_dark_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_parental_controls_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_parental_controls_dark_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_school_time_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_school_time_dark_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/location_sharing_enabled_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/location_sharing_enabled_dark_3.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/parent_sign_in_prologue_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/parent_sign_in_prologue_dark_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_complete_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_complete_dark_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_contacts_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_contacts_dark_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_family_link_boy_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_family_link_boy_dark_1.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_family_link_girl_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_family_link_girl_dark_2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/ulp_continue_without_gmail_dark_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/ulp_continue_without_gmail_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/all_set.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/all_set_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/are_you_sure_parent.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/are_you_sure_parent_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/content_restriction.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/content_restriction_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/error.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/error_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/how_controls_work.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/how_controls_work_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/next_steps.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/next_steps_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/setup_controls.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/setup_controls_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_parent.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_parent_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_teen.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_teen_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teentoadultgraduation/supervision_choice.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teentoadultgraduation/supervision_choice_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/kid_setup_parent_escalation.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/kid_setup_parent_escalation_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/send_email_confirmation.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/send_email_confirmation_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/success_sent_email.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/success_sent_email_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulpupgrade/kidprofileupgrade_all_set.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulpupgrade/kidprofileupgrade_all_set_darkmode.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/all_set.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/all_set_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/almost_done_kids_space_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/almost_done_kids_space_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_tablet_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_tablet_v2_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_v2_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/emailinstallfamilylink.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/emailinstallfamilylink_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/familylinkinstalling.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/familylinkinstalling_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/hand_over_device_dark_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/hand_over_device_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/linking_accounts_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/linking_accounts_v2_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/locationsetup.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/locationsetup_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_email.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_email_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_email_v2_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_v2_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/open_family_link_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/open_family_link_v2_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/parents_help.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/parents_help_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/set_up_kids_space.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/set_up_kids_space_dark.png
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setupcontrol.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setupcontrol_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuplocation.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuplocation_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuptimelimits.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuptimelimits_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/supervision_ready_v2.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/supervision_ready_v2_dark.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/youtubeaccess.svg
    Source: chromecache_85.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/youtubeaccess_dark.svg
    Source: chromecache_89.13.drString found in binary or memory: https://support.google.com/accounts?hl=
    Source: chromecache_89.13.drString found in binary or memory: https://support.google.com/accounts?p=new-si-ui
    Source: chromecache_89.13.drString found in binary or memory: https://support.google.com/websearch/answer/4358949?hl=ko&ref_topic=3285072
    Source: chromecache_85.13.drString found in binary or memory: https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
    Source: chromecache_89.13.drString found in binary or memory: https://www.google.com
    Source: chromecache_89.13.drString found in binary or memory: https://www.google.com/intl/
    Source: chromecache_85.13.drString found in binary or memory: https://www.gstatic.com/accounts/speedbump/authzen_optin_illustration.gif
    Source: chromecache_85.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/chrome_48dp.png
    Source: chromecache_85.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/googleg_48dp.png
    Source: chromecache_85.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/gsa_48dp.png
    Source: chromecache_85.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/play_prism_48dp.png
    Source: chromecache_85.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/youtube_48dp.png
    Source: chromecache_89.13.drString found in binary or memory: https://www.gstatic.com/images/branding/productlogos/googleg/v6/36px.svg
    Source: chromecache_89.13.drString found in binary or memory: https://www.youtube.com/t/terms?chromeless=1&hl=
    Source: file.exe, 00000000.00000003.1764536815.0000000000FE4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd
    Source: chromecache_89.13.drString found in binary or memory: https://youtube.com/t/terms?gl=
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49986
    Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49985
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49984
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49983
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49982
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49981
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49980
    Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49990 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49979
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49978
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49977
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49976
    Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49975
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49974
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49973
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49972
    Source: unknownNetwork traffic detected: HTTP traffic on port 50039 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49971
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49970
    Source: unknownNetwork traffic detected: HTTP traffic on port 49967 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50004 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49943 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49969
    Source: unknownNetwork traffic detected: HTTP traffic on port 49978 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
    Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49968
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49967
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49966
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49965
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49964
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49963
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49961
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
    Source: unknownNetwork traffic detected: HTTP traffic on port 50015 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50040 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49966 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49989 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49933 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50028 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49959
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49958
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
    Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49956
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49955
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
    Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49954
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
    Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
    Source: unknownNetwork traffic detected: HTTP traffic on port 49944 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50051 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49955 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49944
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49943
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
    Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
    Source: unknownNetwork traffic detected: HTTP traffic on port 49945 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50017 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49968 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50049 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50026 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49980 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49895
    Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
    Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49911 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49957 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49991 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
    Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
    Source: unknownNetwork traffic detected: HTTP traffic on port 50038 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49882
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
    Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
    Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50050 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49956 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50005 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49979 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49999
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49998
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49997
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49996
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49995
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
    Source: unknownNetwork traffic detected: HTTP traffic on port 49923 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49994
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49993
    Source: unknownNetwork traffic detected: HTTP traffic on port 50016 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49991
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49990
    Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50027 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49989
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49988
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49987
    Source: unknownNetwork traffic detected: HTTP traffic on port 50013 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50036 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49906 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49975 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50025 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49964 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49999 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50001 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49986 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49963 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50007
    Source: unknownNetwork traffic detected: HTTP traffic on port 50037 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50006
    Source: unknownNetwork traffic detected: HTTP traffic on port 50012 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50009
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50008
    Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
    Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50001
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50000
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50003
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50002
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50005
    Source: unknownNetwork traffic detected: HTTP traffic on port 49895 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50004
    Source: unknownNetwork traffic detected: HTTP traffic on port 50048 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49907 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49941 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
    Source: unknownNetwork traffic detected: HTTP traffic on port 49997 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50003 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49965 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49977 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50035 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49919 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49988 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50046 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49976 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49953 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50047 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49908 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50024 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49998 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49931 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50002 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49987 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50054
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50053
    Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50056
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50055
    Source: unknownNetwork traffic detected: HTTP traffic on port 49961 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49984 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50022 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50045 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49950 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49996 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50010 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50056 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49915 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50034 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49972 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49927 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49983 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50023 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50017
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50019
    Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49974 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50032 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50010
    Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50012
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50011
    Source: unknownNetwork traffic detected: HTTP traffic on port 50055 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50014
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50013
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50016
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50015
    Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50029
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50028
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50021
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50020
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50023
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50022
    Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50025
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50024
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50027
    Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50026
    Source: unknownNetwork traffic detected: HTTP traffic on port 49985 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50000 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50021 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50030
    Source: unknownNetwork traffic detected: HTTP traffic on port 49905 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50039
    Source: unknownNetwork traffic detected: HTTP traffic on port 49995 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50011 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50032
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50031
    Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50034
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50033
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50036
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50035
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50038
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50037
    Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49940 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50041
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50040
    Source: unknownNetwork traffic detected: HTTP traffic on port 49973 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50033 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50043
    Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49917 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50042
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50045
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50044
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50047
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50046
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50049
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50048
    Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50050
    Source: unknownNetwork traffic detected: HTTP traffic on port 49962 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50052
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50051
    Source: unknownNetwork traffic detected: HTTP traffic on port 50044 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49970 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50042 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50007 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49912 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49935 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49958 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50053 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49981 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49924 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49947 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50031 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49992 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50043 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49969 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49994 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50020 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50054 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49913 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50006 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
    Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
    Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49941
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49940
    Source: unknownNetwork traffic detected: HTTP traffic on port 50052 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49938
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
    Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49937
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
    Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49934
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49933
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49932
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49931
    Source: unknownNetwork traffic detected: HTTP traffic on port 49925 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50008 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49971 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49936 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49876 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49960 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49928
    Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.4:49769 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49784 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.4:49809 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49838 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49966 version: TLS 1.2
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082EAFF OpenClipboard,IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetClipboardData,CloseClipboard,GlobalLock,CloseClipboard,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,DragQueryFileW,DragQueryFileW,DragQueryFileW,GlobalUnlock,CountClipboardFormats,CloseClipboard,0_2_0082EAFF
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082ED6A OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,OpenClipboard,EmptyClipboard,SetClipboardData,CloseClipboard,0_2_0082ED6A
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082EAFF OpenClipboard,IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetClipboardData,CloseClipboard,GlobalLock,CloseClipboard,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,DragQueryFileW,DragQueryFileW,DragQueryFileW,GlobalUnlock,CountClipboardFormats,CloseClipboard,0_2_0082EAFF
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081AA57 GetKeyboardState,SetKeyboardState,PostMessageW,SendInput,0_2_0081AA57
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00849576 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW,0_2_00849576

    System Summary

    barindex
    Source: file.exeString found in binary or memory: This is a third-party compiled AutoIt script.
    Source: file.exe, 00000000.00000000.1743226618.0000000000872000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: This is a third-party compiled AutoIt script.memstr_1fca566c-f
    Source: file.exe, 00000000.00000000.1743226618.0000000000872000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: AnyArabicArmenianAvestanBalineseBamumBassa_VahBatakBengaliBopomofoBrahmiBrailleBugineseBuhidCCanadian_AboriginalCarianCaucasian_AlbanianCcCfChakmaChamCherokeeCnCoCommonCopticCsCuneiformCypriotCyrillicDeseretDevanagariDuployanEgyptian_HieroglyphsElbasanEthiopicGeorgianGlagoliticGothicGranthaGreekGujaratiGurmukhiHanHangulHanunooHebrewHiraganaImperial_AramaicInheritedInscriptional_PahlaviInscriptional_ParthianJavaneseKaithiKannadaKatakanaKayah_LiKharoshthiKhmerKhojkiKhudawadiLL&LaoLatinLepchaLimbuLinear_ALinear_BLisuLlLmLoLtLuLycianLydianMMahajaniMalayalamMandaicManichaeanMcMeMeetei_MayekMende_KikakuiMeroitic_CursiveMeroitic_HieroglyphsMiaoMnModiMongolianMroMyanmarNNabataeanNdNew_Tai_LueNkoNlNoOghamOl_ChikiOld_ItalicOld_North_ArabianOld_PermicOld_PersianOld_South_ArabianOld_TurkicOriyaOsmanyaPPahawh_HmongPalmyrenePau_Cin_HauPcPdPePfPhags_PaPhoenicianPiPoPsPsalter_PahlaviRejangRunicSSamaritanSaurashtraScSharadaShavianSiddhamSinhalaSkSmSoSora_SompengSundaneseSyloti_NagriSyriacTagalogTagbanwaTai_LeTai_ThamTai_VietTakriTamilTeluguThaanaThaiTibetanTifinaghTirhutaUgariticVaiWarang_CitiXanXpsXspXucXwdYiZZlZpZsSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBoxSHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainermemstr_5affe1b3-1
    Source: file.exeString found in binary or memory: This is a third-party compiled AutoIt script.memstr_27d4e204-7
    Source: file.exeString found in binary or memory: AnyArabicArmenianAvestanBalineseBamumBassa_VahBatakBengaliBopomofoBrahmiBrailleBugineseBuhidCCanadian_AboriginalCarianCaucasian_AlbanianCcCfChakmaChamCherokeeCnCoCommonCopticCsCuneiformCypriotCyrillicDeseretDevanagariDuployanEgyptian_HieroglyphsElbasanEthiopicGeorgianGlagoliticGothicGranthaGreekGujaratiGurmukhiHanHangulHanunooHebrewHiraganaImperial_AramaicInheritedInscriptional_PahlaviInscriptional_ParthianJavaneseKaithiKannadaKatakanaKayah_LiKharoshthiKhmerKhojkiKhudawadiLL&LaoLatinLepchaLimbuLinear_ALinear_BLisuLlLmLoLtLuLycianLydianMMahajaniMalayalamMandaicManichaeanMcMeMeetei_MayekMende_KikakuiMeroitic_CursiveMeroitic_HieroglyphsMiaoMnModiMongolianMroMyanmarNNabataeanNdNew_Tai_LueNkoNlNoOghamOl_ChikiOld_ItalicOld_North_ArabianOld_PermicOld_PersianOld_South_ArabianOld_TurkicOriyaOsmanyaPPahawh_HmongPalmyrenePau_Cin_HauPcPdPePfPhags_PaPhoenicianPiPoPsPsalter_PahlaviRejangRunicSSamaritanSaurashtraScSharadaShavianSiddhamSinhalaSkSmSoSora_SompengSundaneseSyloti_NagriSyriacTagalogTagbanwaTai_LeTai_ThamTai_VietTakriTamilTeluguThaanaThaiTibetanTifinaghTirhutaUgariticVaiWarang_CitiXanXpsXspXucXwdYiZZlZpZsSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBoxSHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainermemstr_c92dadb3-4
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081D5EB: CreateFileW,DeviceIoControl,CloseHandle,0_2_0081D5EB
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00811201 LogonUserW,DuplicateTokenEx,CloseHandle,OpenWindowStationW,GetProcessWindowStation,SetProcessWindowStation,OpenDesktopW,_wcslen,LoadUserProfileW,CreateEnvironmentBlock,CreateProcessAsUserW,UnloadUserProfile,GetProcessHeap,HeapFree,CloseWindowStation,CloseDesktop,SetProcessWindowStation,CloseHandle,DestroyEnvironmentBlock,0_2_00811201
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081E8F6 ExitWindowsEx,InitiateSystemShutdownExW,SetSystemPowerState,0_2_0081E8F6
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007B80600_2_007B8060
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008220460_2_00822046
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008182980_2_00818298
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007EE4FF0_2_007EE4FF
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007E676B0_2_007E676B
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008448730_2_00844873
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007BCAF00_2_007BCAF0
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007DCAA00_2_007DCAA0
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007CCC390_2_007CCC39
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007E6DD90_2_007E6DD9
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007CB1190_2_007CB119
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007B91C00_2_007B91C0
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D13940_2_007D1394
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D17060_2_007D1706
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D781B0_2_007D781B
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007C997D0_2_007C997D
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007B79200_2_007B7920
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D19B00_2_007D19B0
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D7A4A0_2_007D7A4A
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D1C770_2_007D1C77
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D7CA70_2_007D7CA7
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007E9EEE0_2_007E9EEE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0083BE440_2_0083BE44
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D1F320_2_007D1F32
    Source: C:\Users\user\Desktop\file.exeCode function: String function: 007CF9F2 appears 31 times
    Source: C:\Users\user\Desktop\file.exeCode function: String function: 007D0A30 appears 46 times
    Source: file.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
    Source: classification engineClassification label: mal64.troj.evad.winEXE@46/30@12/7
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008237B5 GetLastError,FormatMessageW,0_2_008237B5
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008110BF AdjustTokenPrivileges,CloseHandle,0_2_008110BF
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008116C3 LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,0_2_008116C3
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008251CD SetErrorMode,GetDiskFreeSpaceExW,SetErrorMode,0_2_008251CD
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0083A67C CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,0_2_0083A67C
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082648E _wcslen,CoInitialize,CoCreateInstance,CoUninitialize,0_2_0082648E
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007B42A2 CreateStreamOnHGlobal,FindResourceExW,LoadResource,SizeofResource,LockResource,0_2_007B42A2
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4416:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2200:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1700:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1072:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6188:120:WilError_03
    Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: unknownProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobars
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5084 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5576 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobarsJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5084 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5576 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: wsock32.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: version.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: winmm.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007B42DE GetVersionExW,GetCurrentProcess,IsWow64Process,LoadLibraryA,GetProcAddress,GetNativeSystemInfo,FreeLibrary,GetSystemInfo,GetSystemInfo,0_2_007B42DE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D0A76 push ecx; ret 0_2_007D0A89
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007CF98E GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,0_2_007CF98E
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00841C41 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed,0_2_00841C41
    Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

    Malware Analysis System Evasion

    barindex
    Source: C:\Users\user\Desktop\file.exeSandbox detection routine: GetForegroundWindow, DecisionNode, Sleepgraph_0-95241
    Source: C:\Users\user\Desktop\file.exeWindow / User API: threadDelayed 7220Jump to behavior
    Source: C:\Users\user\Desktop\file.exeWindow / User API: foregroundWindowGot 1777Jump to behavior
    Source: C:\Users\user\Desktop\file.exeAPI coverage: 3.6 %
    Source: C:\Users\user\Desktop\file.exe TID: 7152Thread sleep time: -72200s >= -30000sJump to behavior
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Users\user\Desktop\file.exeThread sleep count: Count: 7220 delay: -10Jump to behavior
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081DBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose,0_2_0081DBBE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008268EE FindFirstFileW,FindClose,0_2_008268EE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime,0_2_0082698F
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081D076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose,0_2_0081D076
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081D3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose,0_2_0081D3A9
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00829642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose,0_2_00829642
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose,0_2_0082979D
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00829B2B FindFirstFileW,Sleep,FindNextFileW,FindClose,0_2_00829B2B
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00825C97 FindFirstFileW,FindNextFileW,FindClose,0_2_00825C97
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007B42DE GetVersionExW,GetCurrentProcess,IsWow64Process,LoadLibraryA,GetProcAddress,GetNativeSystemInfo,FreeLibrary,GetSystemInfo,GetSystemInfo,0_2_007B42DE
    Source: C:\Users\user\Desktop\file.exeProcess information queried: ProcessInformationJump to behavior
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0082EAA2 BlockInput,0_2_0082EAA2
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007E2622 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_007E2622
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007B42DE GetVersionExW,GetCurrentProcess,IsWow64Process,LoadLibraryA,GetProcAddress,GetNativeSystemInfo,FreeLibrary,GetSystemInfo,GetSystemInfo,0_2_007B42DE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D4CE8 mov eax, dword ptr fs:[00000030h]0_2_007D4CE8
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00810B62 GetSecurityDescriptorDacl,GetAclInformation,GetLengthSid,GetLengthSid,GetAce,AddAce,GetLengthSid,GetProcessHeap,HeapAlloc,GetLengthSid,CopySid,AddAce,SetSecurityDescriptorDacl,SetUserObjectSecurity,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,0_2_00810B62
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007E2622 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_007E2622
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D083F IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_007D083F
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D09D5 SetUnhandledExceptionFilter,0_2_007D09D5
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D0C21 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_007D0C21
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00811201 LogonUserW,DuplicateTokenEx,CloseHandle,OpenWindowStationW,GetProcessWindowStation,SetProcessWindowStation,OpenDesktopW,_wcslen,LoadUserProfileW,CreateEnvironmentBlock,CreateProcessAsUserW,UnloadUserProfile,GetProcessHeap,HeapFree,CloseWindowStation,CloseDesktop,SetProcessWindowStation,CloseHandle,DestroyEnvironmentBlock,0_2_00811201
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007F2BA5 KiUserCallbackDispatcher,SetCurrentDirectoryW,GetForegroundWindow,ShellExecuteW,0_2_007F2BA5
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0081B226 SendInput,keybd_event,0_2_0081B226
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_008322DA GetForegroundWindow,GetDesktopWindow,GetWindowRect,mouse_event,GetCursorPos,mouse_event,0_2_008322DA
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00810B62 GetSecurityDescriptorDacl,GetAclInformation,GetLengthSid,GetLengthSid,GetAce,AddAce,GetLengthSid,GetProcessHeap,HeapAlloc,GetLengthSid,CopySid,AddAce,SetSecurityDescriptorDacl,SetUserObjectSecurity,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,0_2_00810B62
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00811663 AllocateAndInitializeSid,CheckTokenMembership,FreeSid,0_2_00811663
    Source: file.exeBinary or memory string: Run Script:AutoIt script files (*.au3, *.a3x)*.au3;*.a3xAll files (*.*)*.*au3#include depth exceeded. Make sure there are no recursive includesError opening the file>>>AUTOIT SCRIPT<<<Bad directive syntax errorUnterminated stringCannot parse #includeUnterminated group of commentsONOFF0%d%dShell_TrayWndREMOVEKEYSEXISTSAPPENDblankinfoquestionstopwarning
    Source: file.exeBinary or memory string: Shell_TrayWnd
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007D0698 cpuid 0_2_007D0698
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00828195 GetLocalTime,SystemTimeToFileTime,LocalFileTimeToFileTime,GetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,0_2_00828195
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0080D27A GetUserNameW,0_2_0080D27A
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007EBB6F _free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,0_2_007EBB6F
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_007B42DE GetVersionExW,GetCurrentProcess,IsWow64Process,LoadLibraryA,GetProcAddress,GetNativeSystemInfo,FreeLibrary,GetSystemInfo,GetSystemInfo,0_2_007B42DE

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: Process Memory Space: file.exe PID: 7144, type: MEMORYSTR
    Source: file.exeBinary or memory string: WIN_81
    Source: file.exeBinary or memory string: WIN_XP
    Source: file.exeBinary or memory string: %.3d%S%M%H%m%Y%jX86IA64X64WIN32_NTWIN_11WIN_10WIN_2022WIN_2019WIN_2016WIN_81WIN_2012R2WIN_2012WIN_8WIN_2008R2WIN_7WIN_2008WIN_VISTAWIN_2003WIN_XPeWIN_XPInstallLanguageSYSTEM\CurrentControlSet\Control\Nls\LanguageSchemeLangIDControl Panel\AppearanceUSERPROFILEUSERDOMAINUSERDNSDOMAINGetSystemWow64DirectoryWSeDebugPrivilege:winapistdcallubyte64HKEY_LOCAL_MACHINEHKLMHKEY_CLASSES_ROOTHKCRHKEY_CURRENT_CONFIGHKCCHKEY_CURRENT_USERHKCUHKEY_USERSHKUREG_EXPAND_SZREG_SZREG_MULTI_SZREG_DWORDREG_QWORDREG_BINARYRegDeleteKeyExWadvapi32.dll+.-.\\[\\nrt]|%%|%[-+ 0#]?([0-9]*|\*)?(\.[0-9]*|\.\*)?[hlL]?[diouxXeEfgGs](*UCP)\XISVISIBLEISENABLEDTABLEFTTABRIGHTCURRENTTABSHOWDROPDOWNHIDEDROPDOWNADDSTRINGDELSTRINGFINDSTRINGGETCOUNTSETCURRENTSELECTIONGETCURRENTSELECTIONSELECTSTRINGISCHECKEDCHECKUNCHECKGETSELECTEDGETLINECOUNTGETCURRENTLINEGETCURRENTCOLEDITPASTEGETLINESENDCOMMANDIDGETITEMCOUNTGETSUBITEMCOUNTGETTEXTGETSELECTEDCOUNTISSELECTEDSELECTALLSELECTCLEARSELECTINVERTDESELECTFINDITEMVIEWCHANGEGETTOTALCOUNTCOLLAPSEEXPANDmsctls_statusbar321tooltips_class32%d/%02d/%02dbuttonComboboxListboxSysDateTimePick32SysMonthCal32.icl.exe.dllMsctls_Progress32msctls_trackbar32SysAnimate32msctls_updown32SysTabControl32SysTreeView32SysListView32-----@GUI_DRAGID@GUI_DROPID@GUI_DRAGFILEError text not found (please report)Q\EDEFINEUTF16)UTF)UCP)NO_AUTO_POSSESS)NO_START_OPT)LIMIT_MATCH=LIMIT_RECURSION=CR)LF)CRLF)ANY)ANYCRLF)BSR_ANYCRLF)BSR_UNICODE)argument is not a compiled regular expressionargument not compiled in 16 bit modeinternal error: opcode not recognizedinternal error: missing capturing bracketfailed to get memory
    Source: file.exeBinary or memory string: WIN_XPe
    Source: file.exeBinary or memory string: WIN_VISTA
    Source: file.exeBinary or memory string: WIN_7
    Source: file.exeBinary or memory string: WIN_8

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: Process Memory Space: file.exe PID: 7144, type: MEMORYSTR
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00831204 socket,WSAGetLastError,bind,WSAGetLastError,closesocket,listen,WSAGetLastError,closesocket,0_2_00831204
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00831806 socket,WSAGetLastError,bind,WSAGetLastError,closesocket,0_2_00831806
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire Infrastructure2
    Valid Accounts
    1
    Windows Management Instrumentation
    1
    DLL Side-Loading
    1
    Exploitation for Privilege Escalation
    2
    Disable or Modify Tools
    21
    Input Capture
    2
    System Time Discovery
    Remote Services1
    Archive Collected Data
    2
    Ingress Tool Transfer
    Exfiltration Over Other Network Medium1
    System Shutdown/Reboot
    CredentialsDomainsDefault Accounts1
    Native API
    2
    Valid Accounts
    1
    DLL Side-Loading
    1
    Deobfuscate/Decode Files or Information
    LSASS Memory1
    Account Discovery
    Remote Desktop Protocol21
    Input Capture
    11
    Encrypted Channel
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)2
    Valid Accounts
    2
    Obfuscated Files or Information
    Security Account Manager1
    File and Directory Discovery
    SMB/Windows Admin Shares3
    Clipboard Data
    2
    Non-Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook21
    Access Token Manipulation
    1
    DLL Side-Loading
    NTDS16
    System Information Discovery
    Distributed Component Object ModelInput Capture3
    Application Layer Protocol
    Traffic DuplicationData Destruction
    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script2
    Process Injection
    2
    Valid Accounts
    LSA Secrets12
    Security Software Discovery
    SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts12
    Virtualization/Sandbox Evasion
    Cached Domain Credentials12
    Virtualization/Sandbox Evasion
    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
    DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items21
    Access Token Manipulation
    DCSync3
    Process Discovery
    Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
    Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job2
    Process Injection
    Proc Filesystem11
    Application Window Discovery
    Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
    Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
    System Owner/User Discovery
    Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet
    behaviorgraph top1 signatures2 2 Behavior Graph ID: 1525128 Sample: file.exe Startdate: 03/10/2024 Architecture: WINDOWS Score: 64 48 Yara detected Credential Flusher 2->48 50 Binary is likely a compiled AutoIt script file 2->50 52 Machine Learning detection for sample 2->52 54 AI detected suspicious sample 2->54 7 file.exe 2->7         started        process3 signatures4 56 Binary is likely a compiled AutoIt script file 7->56 58 Found API chain indicative of sandbox detection 7->58 10 chrome.exe 1 7->10         started        13 taskkill.exe 1 7->13         started        15 taskkill.exe 1 7->15         started        17 3 other processes 7->17 process5 dnsIp6 42 192.168.2.16 unknown unknown 10->42 44 192.168.2.4, 138, 443, 49457 unknown unknown 10->44 46 239.255.255.250 unknown Reserved 10->46 19 chrome.exe 10->19         started        22 chrome.exe 10->22         started        24 chrome.exe 6 10->24         started        26 conhost.exe 13->26         started        28 conhost.exe 15->28         started        30 conhost.exe 17->30         started        32 conhost.exe 17->32         started        34 conhost.exe 17->34         started        process7 dnsIp8 36 www.google.com 142.250.185.132, 443, 49741, 49883 GOOGLEUS United States 19->36 38 youtube.com 142.250.185.238, 443, 49731 GOOGLEUS United States 19->38 40 5 other IPs or domains 19->40

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    file.exe100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    https://play.google/intl/0%URL Reputationsafe
    https://families.google.com/intl/0%URL Reputationsafe
    https://policies.google.com/technologies/location-data0%URL Reputationsafe
    https://apis.google.com/js/api.js0%URL Reputationsafe
    https://support.google.com/accounts?hl=0%URL Reputationsafe
    https://policies.google.com/privacy/google-partners0%URL Reputationsafe
    https://policies.google.com/terms/location0%URL Reputationsafe
    https://policies.google.com/terms/service-specific0%URL Reputationsafe
    https://g.co/recover0%URL Reputationsafe
    https://policies.google.com/privacy0%URL Reputationsafe
    https://policies.google.com/privacy/additional0%URL Reputationsafe
    https://support.google.com/websearch/answer/4358949?hl=ko&ref_topic=32850720%URL Reputationsafe
    https://policies.google.com/technologies/cookies0%URL Reputationsafe
    https://support.google.com/accounts?p=new-si-ui0%URL Reputationsafe
    https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessage0%URL Reputationsafe
    https://policies.google.com/terms0%URL Reputationsafe
    https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=0%URL Reputationsafe
    NameIPActiveMaliciousAntivirus DetectionReputation
    youtube-ui.l.google.com
    172.217.16.206
    truefalse
      unknown
      www3.l.google.com
      216.58.206.78
      truefalse
        unknown
        play.google.com
        142.250.181.238
        truefalse
          unknown
          www.google.com
          142.250.185.132
          truefalse
            unknown
            youtube.com
            142.250.185.238
            truefalse
              unknown
              accounts.youtube.com
              unknown
              unknownfalse
                unknown
                www.youtube.com
                unknown
                unknownfalse
                  unknown
                  NameMaliciousAntivirus DetectionReputation
                  https://www.google.com/favicon.icofalse
                    unknown
                    NameSourceMaliciousAntivirus DetectionReputation
                    https://www.google.comchromecache_89.13.drfalse
                      unknown
                      https://play.google.com/log?format=json&hasfast=truechromecache_89.13.drfalse
                        unknown
                        https://play.google/intl/chromecache_89.13.drfalse
                        • URL Reputation: safe
                        unknown
                        https://families.google.com/intl/chromecache_89.13.drfalse
                        • URL Reputation: safe
                        unknown
                        https://youtube.com/t/terms?gl=chromecache_89.13.drfalse
                          unknown
                          https://www.youtube.com/t/terms?chromeless=1&hl=chromecache_89.13.drfalse
                            unknown
                            https://policies.google.com/technologies/location-datachromecache_89.13.drfalse
                            • URL Reputation: safe
                            unknown
                            https://www.google.com/intl/chromecache_89.13.drfalse
                              unknown
                              https://apis.google.com/js/api.jschromecache_85.13.drfalse
                              • URL Reputation: safe
                              unknown
                              https://support.google.com/accounts?hl=chromecache_89.13.drfalse
                              • URL Reputation: safe
                              unknown
                              https://policies.google.com/privacy/google-partnerschromecache_89.13.drfalse
                              • URL Reputation: safe
                              unknown
                              https://policies.google.com/terms/locationchromecache_89.13.drfalse
                              • URL Reputation: safe
                              unknown
                              https://play.google.com/work/enroll?identifier=chromecache_89.13.drfalse
                                unknown
                                https://policies.google.com/terms/service-specificchromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://g.co/recoverchromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://policies.google.com/privacychromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://policies.google.com/privacy/additionalchromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://support.google.com/websearch/answer/4358949?hl=ko&ref_topic=3285072chromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://policies.google.com/technologies/cookieschromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://support.google.com/accounts?p=new-si-uichromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessagechromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://policies.google.com/termschromecache_89.13.drfalse
                                • URL Reputation: safe
                                unknown
                                https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=chromecache_85.13.drfalse
                                • URL Reputation: safe
                                unknown
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                172.217.16.206
                                youtube-ui.l.google.comUnited States
                                15169GOOGLEUSfalse
                                216.58.206.78
                                www3.l.google.comUnited States
                                15169GOOGLEUSfalse
                                142.250.185.132
                                www.google.comUnited States
                                15169GOOGLEUSfalse
                                142.250.185.238
                                youtube.comUnited States
                                15169GOOGLEUSfalse
                                239.255.255.250
                                unknownReserved
                                unknownunknownfalse
                                IP
                                192.168.2.16
                                192.168.2.4
                                Joe Sandbox version:41.0.0 Charoite
                                Analysis ID:1525128
                                Start date and time:2024-10-03 18:15:09 +02:00
                                Joe Sandbox product:CloudBasic
                                Overall analysis duration:0h 5m 16s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:default.jbs
                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                Number of analysed new started processes analysed:20
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Sample name:file.exe
                                Detection:MAL
                                Classification:mal64.troj.evad.winEXE@46/30@12/7
                                EGA Information:
                                • Successful, ratio: 100%
                                HCA Information:
                                • Successful, ratio: 95%
                                • Number of executed functions: 39
                                • Number of non-executed functions: 311
                                Cookbook Comments:
                                • Found application associated with file extension: .exe
                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                • Excluded IPs from analysis (whitelisted): 74.125.133.84, 142.250.181.238, 142.250.185.227, 34.104.35.123, 216.58.206.67, 142.250.185.170, 142.250.184.234, 172.217.23.106, 172.217.18.10, 142.250.186.138, 216.58.212.138, 142.250.185.74, 142.250.185.234, 142.250.186.74, 172.217.16.202, 172.217.18.106, 142.250.185.106, 216.58.206.74, 142.250.185.202, 142.250.185.138, 142.250.186.106, 142.250.186.42, 172.217.16.138, 216.58.206.42, 142.250.186.170, 142.250.181.234, 142.250.184.202, 216.58.212.170, 93.184.221.240, 192.229.221.95, 142.250.185.67, 64.233.184.84, 142.250.185.110
                                • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, otelrules.azureedge.net, fonts.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, update.googleapis.com, clients.l.google.com, www.gstatic.com, optimizationguide-pa.googleapis.com
                                • HTTPS sessions have been limited to 150. Please view the PCAPs for the complete data.
                                • Not all processes where analyzed, report is missing behavior information
                                • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                • VT rate limit hit for: file.exe
                                No simulations
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                239.255.255.250https://u9313450.ct.sendgrid.net/ls/click?upn=u001.ZfA-2BqTl2mXIVteOCc-2BANg-2BtYQAbYWaU-2BKDDWa611GxHig-2BgElXnUy1eAOeNoTI9ToS9WuAxRUdR21lAIsTPE0g-3D-3Dd8kL_bf4JG6rVotaFp8XsYJMcbHq5p6ju5xz6OkJFWJQMhev1YsQkFFV7zJr96yz5256BnjjwP-2FrVNKeomJDukUeXnM2-2FUbrpvrFpNFdN8Hxo-2B8NA1G5PPzQiWnVnq4RPrf4MxseS-2FjeJBGe3OOYXNXxDmns1gfYeFwrIC6tXtQ3KJv23PKABAyqpBB-2FnsXl7BropPMbry14s3UYpaAeg1aJih0NQeQpVSOm5MBDYOXEHCyJCtLrpoW6SuZeJlGeeWyYAhbotSAdFsjwH5JN5fjIYp-2BMzHm9VPykPI2oeKmW91mIcQqO5YJ1dVv925b7N0T1vGet hashmaliciousUnknownBrowse
                                  http://reviewnewdocuments.wordpress.com/Get hashmaliciousUnknownBrowse
                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                      https://docsend.com/view/ws65kkaar2fwghuaGet hashmaliciousUnknownBrowse
                                        75c6a7ee973b556a2a3914a9e4b18bc019636e70fb6f4c2f8c6f7da0af050cbb.7zGet hashmaliciousUnknownBrowse
                                          https://ahchoadeegu.homes?u=k8pp605&o=c9ewtnr&t=8845Get hashmaliciousUnknownBrowse
                                            file.exeGet hashmaliciousCredential FlusherBrowse
                                              http://bernas-medical-com.powerappsportals.comGet hashmaliciousUnknownBrowse
                                                https://links.truthsocial.com/link/113203933939427541Get hashmaliciousUnknownBrowse
                                                  Activator by URKE v2.5.exeGet hashmaliciousLummaCBrowse
                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                    play.google.comhttps://u9313450.ct.sendgrid.net/ls/click?upn=u001.ZfA-2BqTl2mXIVteOCc-2BANg-2BtYQAbYWaU-2BKDDWa611GxHig-2BgElXnUy1eAOeNoTI9ToS9WuAxRUdR21lAIsTPE0g-3D-3Dd8kL_bf4JG6rVotaFp8XsYJMcbHq5p6ju5xz6OkJFWJQMhev1YsQkFFV7zJr96yz5256BnjjwP-2FrVNKeomJDukUeXnM2-2FUbrpvrFpNFdN8Hxo-2B8NA1G5PPzQiWnVnq4RPrf4MxseS-2FjeJBGe3OOYXNXxDmns1gfYeFwrIC6tXtQ3KJv23PKABAyqpBB-2FnsXl7BropPMbry14s3UYpaAeg1aJih0NQeQpVSOm5MBDYOXEHCyJCtLrpoW6SuZeJlGeeWyYAhbotSAdFsjwH5JN5fjIYp-2BMzHm9VPykPI2oeKmW91mIcQqO5YJ1dVv925b7N0T1vGet hashmaliciousUnknownBrowse
                                                    • 142.250.186.174
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 216.58.212.142
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 142.250.185.78
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 172.217.18.14
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 172.217.16.206
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 216.58.206.46
                                                    https://docs.google.com/forms/d/e/1FAIpQLSd11N0abxlW-jWhsgCqQSv4dirOC7CnOJxj0NYrOSmFOvEaMg/viewform?usp=pp_urlGet hashmaliciousHTMLPhisherBrowse
                                                    • 142.250.186.174
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 172.217.18.14
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 142.250.186.46
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 142.250.185.78
                                                    No context
                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                    28a2c9bd18a11de089ef85a160da29e4https://u9313450.ct.sendgrid.net/ls/click?upn=u001.ZfA-2BqTl2mXIVteOCc-2BANg-2BtYQAbYWaU-2BKDDWa611GxHig-2BgElXnUy1eAOeNoTI9ToS9WuAxRUdR21lAIsTPE0g-3D-3Dd8kL_bf4JG6rVotaFp8XsYJMcbHq5p6ju5xz6OkJFWJQMhev1YsQkFFV7zJr96yz5256BnjjwP-2FrVNKeomJDukUeXnM2-2FUbrpvrFpNFdN8Hxo-2B8NA1G5PPzQiWnVnq4RPrf4MxseS-2FjeJBGe3OOYXNXxDmns1gfYeFwrIC6tXtQ3KJv23PKABAyqpBB-2FnsXl7BropPMbry14s3UYpaAeg1aJih0NQeQpVSOm5MBDYOXEHCyJCtLrpoW6SuZeJlGeeWyYAhbotSAdFsjwH5JN5fjIYp-2BMzHm9VPykPI2oeKmW91mIcQqO5YJ1dVv925b7N0T1vGet hashmaliciousUnknownBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    http://reviewnewdocuments.wordpress.com/Get hashmaliciousUnknownBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    https://docsend.com/view/ws65kkaar2fwghuaGet hashmaliciousUnknownBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    0a839761915d.exeGet hashmaliciousLummaCBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    https://ahchoadeegu.homes?u=k8pp605&o=c9ewtnr&t=8845Get hashmaliciousUnknownBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    http://bernas-medical-com.powerappsportals.comGet hashmaliciousUnknownBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    https://links.truthsocial.com/link/113203933939427541Get hashmaliciousUnknownBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    Activator by URKE v2.5.exeGet hashmaliciousLummaCBrowse
                                                    • 172.202.163.200
                                                    • 4.245.163.56
                                                    • 184.28.90.27
                                                    • 13.107.246.60
                                                    No context
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (2907)
                                                    Category:downloaded
                                                    Size (bytes):23298
                                                    Entropy (8bit):5.429186219736739
                                                    Encrypted:false
                                                    SSDEEP:384:+BitNeB9HVPQmqySWyvbbb/XEm6k1JTM2qzhOF0bCjOgiQBH2f+wl9nyf0zHwx:+BiHeB9Hecebbb/PONOFnjOgPBHgSywx
                                                    MD5:A5C41D7BA22E9CF451810802AE5AC2E8
                                                    SHA1:858F35134A0BD7BAECB1B1A30EC3645642214554
                                                    SHA-256:D29364A1E9EDE91152F2CB84962B73644741817C9C6A615C1FB70A885DD1CB8D
                                                    SHA-512:DEA28AD362B51832D33CD9E936C0A255FA32C20DFFC6E806DA7AAF657D3490AF079C40FE21E10B2FDC971EB066E51ABDA182DEDC156759CCE06440E456FEB316
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,Rkm0ef,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=RqjULd"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.xu.prototype.da=_.ca(40,function(){return _.tj(this,3)});_.cz=function(a,b){this.key=a;this.defaultValue=!1;this.flagName=b};_.cz.prototype.ctor=function(a){return typeof a==="boolean"?a:this.defaultValue};_.dz=function(){this.ka=!0;var a=_.xj(_.fk(_.Be("TSDtV",window),_.Cya),_.xu,1,_.sj())[0];if(a){var b={};for(var c=_.n(_.xj(a,_.Dya,2,_.sj())),d=c.next();!d.done;d=c.next()){d=d.value;var e=_.Lj(d,1).toString();switch(_.vj(d,_.yu)){case 3:b[e]=_.Jj(d,_.nj(d,_.yu,3));break;case 2:b[e]=_.Lj(d,_.nj(d,_.yu,2));break;case 4:b[e]=_.Mj(d,_.nj(d,_.yu,4));break;case 5:b[e]=_.Nj(d,_.nj(d,_.yu,5));break;case 6:b[e]=_.Rj(d,_.ff,6,_.yu);break;default:throw Error("jd`"+_.vj(d,_.yu));}}}else b={};this.ea=b;this.token=.a?a.da():null};_.dz.prototype.aa=function(a){if(!this.ka||a.key in this.ea)a=a.ctor(this.ea[a.key]);else if(_.Be("nQyAE",window)){var b=_.Fya(a.flagName);if(b===null)a=a.de
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (533)
                                                    Category:downloaded
                                                    Size (bytes):9210
                                                    Entropy (8bit):5.393248075042016
                                                    Encrypted:false
                                                    SSDEEP:192:t7mFYxV97I4Ia0U44rS3mt8IV7ydti6M5/1JlNg:t7vB7Il2t+dEF1JlNg
                                                    MD5:2ED5BC88509286438B682EFF23518005
                                                    SHA1:D5C8FD77BA3ED7F977A4AD0C85CF026D0F74F3E2
                                                    SHA-256:F878D44B5CAC6BC95D638C13D0814C10E7D6CC145351ABA7945F53D8CB167979
                                                    SHA-512:12F5415A482286C53631D09B5F50BA4AAA0957DB61904430E5B728777A15DC62428ED560847AB1DFEC459E302FB4D009D32CC1770EAD5425023CA48DF4640AA4
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PrPYRd,Rkm0ef,SCuOPb,STuCOe,SpsfSb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,byfTOb,cYShmd,eVCnO,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,qPfo0c,qmdT9,rCcCxc,siKnQd,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=ltDFwf,SD8Jgb,rmumx,E87wgc,qPYxq,Tbb4sb,pxq3x,f8Gu1e,soHxf,YgOFye,yRXbo,bTi8wc,ywOR5c,PHUIyb"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.vNa=_.z("SD8Jgb",[]);._.GX=function(a,b){if(typeof b==="string")a.Nc(b);else if(b instanceof _.Ip&&b.ia&&b.ia===_.A)b=_.Za(b.Ku()),a.empty().append(b);else if(b instanceof _.Ua)b=_.Za(b),a.empty().append(b);else if(b instanceof Node)a.empty().append(b);else throw Error("Wf");};_.HX=function(a){var b=_.Lo(a,"[jsslot]");if(b.size()>0)return b;b=new _.Jo([_.Qk("span")]);_.Mo(b,"jsslot","");a.empty().append(b);return b};_.bMb=function(a){return a===null||typeof a==="string"&&_.Ji(a)};._.k("SD8Jgb");._.MX=function(a){_.X.call(this,a.Fa);this.Va=a.controller.Va;this.od=a.controllers.od[0]||null;this.header=a.controller.header;this.nav=a.controller.nav;var b;(b=this.oa().find("button:not([type])").el())==null||b.setAttribute("type","button")};_.J(_.MX,_.X);_.MX.Ba=function(){return{controller:{Va:{jsname:"n7vHCb",ctor:_.pv},header:{jsname:"tJHJj",ctor:_.pv},nav:{jsname:"DH6Rkf",ct
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (755)
                                                    Category:downloaded
                                                    Size (bytes):1460
                                                    Entropy (8bit):5.274624539239422
                                                    Encrypted:false
                                                    SSDEEP:24:kMYD7DUuXIqMSsN7UYgtx/mQ7hz1BU6TZ6BdXDMvUKGbWxlGb+jSFFV87Ofk8tp8:o7DhXI6PoXwsKGb2lGb+jS9Mwrw
                                                    MD5:481C149C4D3EE4A53C3E7CBA067371DF
                                                    SHA1:E0FED275636D3492C922C44F010157FAF0936733
                                                    SHA-256:9327A53F577C5FCEFDB162E02D8646CE5B70DF2201F4B3289384657B32BACE70
                                                    SHA-512:EC5C5A03ED4E1A27BEE7E1C488A238D79A9787D944E364CCE516FB28C22256919E49C99BFCFEA0F7815AB4232A350914E26D33D20F5A81ED19A39DFD40E30C79
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=P6sQOc"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("lOO0Vd");._.b_a=new _.pf(_.Dm);._.l();._.k("P6sQOc");.var g_a=!!(_.Mh[1]&16);var i_a=function(a,b,c,d,e){this.ea=a;this.xa=b;this.ka=c;this.Ca=d;this.Ga=e;this.aa=0;this.da=h_a(this)},j_a=function(a){var b={};_.Ma(a.HS(),function(e){b[e]=!0});var c=a.uS(),d=a.yS();return new i_a(a.wP(),c.aa()*1E3,a.bS(),d.aa()*1E3,b)},h_a=function(a){return Math.random()*Math.min(a.xa*Math.pow(a.ka,a.aa),a.Ca)},SG=function(a,b){return a.aa>=a.ea?!1:b!=null?!!a.Ga[b]:!0};var TG=function(a){_.W.call(this,a.Fa);this.da=a.Ea.JV;this.ea=a.Ea.metadata;a=a.Ea.cha;this.fetch=a.fetch.bind(a)};_.J(TG,_.W);TG.Ba=function(){return{Ea:{JV:_.e_a,metadata:_.b_a,cha:_.VZa}}};TG.prototype.aa=function(a,b){if(this.ea.getType(a.Od())!==1)return _.Vm(a);var c=this.da.jV;return(c=c?j_a(c):null)&&SG(c)?_.zya(a,k_a(this,a,b,c)):_.Vm(a)};.var k_a=function(a,b,c,d){return c.then(function(e){return e},function(e)
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (683)
                                                    Category:downloaded
                                                    Size (bytes):3131
                                                    Entropy (8bit):5.352056237104327
                                                    Encrypted:false
                                                    SSDEEP:48:o7hHD75byh9xqKP5jNQ8js63rAwrMNhYfmdpwoKLEy5aQW5Tx5v3MmFopMGIWO4x:oFD+95jOQr3AT7wRLDGD5flBb4Ew
                                                    MD5:ADEF03127F74F5E6742B8CFA7B863F28
                                                    SHA1:58D7C635582AF10E91EC047FD315FAF758AF51DA
                                                    SHA-256:5FDD639E222F58AEB6178EB02583086BCC50ED219DEAA953D0E7984DD0E1FEDC
                                                    SHA-512:3AC26E9569EE83298F386D551774F378D3E433A2C80C1D4BC7481C544605A2FA4943F6CBC8E97FBF8FE3C32C1EFB2A1CCAA01403819482FC7429538FDF2CA758
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=ZwDk9d,RMhBfe"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("ZwDk9d");.var kA=function(a){_.W.call(this,a.Fa)};_.J(kA,_.W);kA.Ba=_.W.Ba;kA.prototype.jS=function(a){return _.Ye(this,{Xa:{lT:_.ol}}).then(function(b){var c=window._wjdd,d=window._wjdc;return!c&&d?new _.ni(function(e){window._wjdc=function(f){d(f);e(dKa(f,b,a))}}):dKa(c,b,a)})};var dKa=function(a,b,c){return(a=a&&a[c])?a:b.Xa.lT.jS(c)};.kA.prototype.aa=function(a,b){var c=_.Dra(b).Tj;if(c.startsWith("$")){var d=_.jm.get(a);_.xq[b]&&(d||(d={},_.jm.set(a,d)),d[c]=_.xq[b],delete _.xq[b],_.yq--);if(d)if(a=d[c])b=_.af(a);else throw Error("Jb`"+b);else b=null}else b=null;return b};_.qu(_.Lfa,kA);._.l();._.k("SNUn3");._.cKa=new _.pf(_.wg);._.l();._.k("RMhBfe");.var eKa=function(a){var b=_.wq(a);return b?new _.ni(function(c,d){var e=function(){b=_.wq(a);var f=_.Sfa(a,b);f?c(f.getAttribute("jsdata")):window.document.readyState=="complete"?(f=["Unable to find deferred jsdata wit
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
                                                    Category:downloaded
                                                    Size (bytes):5430
                                                    Entropy (8bit):3.6534652184263736
                                                    Encrypted:false
                                                    SSDEEP:48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B
                                                    MD5:F3418A443E7D841097C714D69EC4BCB8
                                                    SHA1:49263695F6B0CDD72F45CF1B775E660FDC36C606
                                                    SHA-256:6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770
                                                    SHA-512:82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563
                                                    Malicious:false
                                                    URL:https://www.google.com/favicon.ico
                                                    Preview:............ .h...&... .... .........(....... ..... ............................................0...................................................................................................................................v.].X.:.X.:.r.Y........................................q.X.S.4.S.4.S.4.S.4.S.4.S.4...X....................0........q.W.S.4.X.:.................J...A...g.........................K.H.V.8..........................F..B.....................,.......................................B..............................................B..B..B..B..B...u..........................................B..B..B..B..B...{.................5.......k...........................................................7R..8F.................................................2........Vb..5C..;I..................R^.....................0................Xc..5C..5C..5C..5C..5C..5C..lv..........................................]i..<J..:G..Zf....................................................
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:Web Open Font Format (Version 2), TrueType, length 52280, version 1.0
                                                    Category:downloaded
                                                    Size (bytes):52280
                                                    Entropy (8bit):7.995413196679271
                                                    Encrypted:true
                                                    SSDEEP:1536:1rvqtK8DZilXxwJ8mMwAZy7phqsFLdG3B4d:xytBZits8bw4wzbFxG3B4d
                                                    MD5:F61F0D4D0F968D5BBA39A84C76277E1A
                                                    SHA1:AA3693EA140ECA418B4B2A30F6A68F6F43B4BEB2
                                                    SHA-256:57147F08949ABABE7DEEF611435AE418475A693E3823769A25C2A39B6EAD9CCC
                                                    SHA-512:6C3BD90F709BCF9151C9ED9FFEA55C4F6883E7FDA2A4E26BF018C83FE1CFBE4F4AA0DB080D6D024070D53B2257472C399C8AC44EEFD38B9445640EFA85D5C487
                                                    Malicious:false
                                                    URL:https://fonts.gstatic.com/s/googlesans/v58/4UaRrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_Iq2vgCI.woff2
                                                    Preview:wOF2.......8.....................................^...$..4?HVAR..?MVAR9.`?STAT.*',..J/.......`..(..Z.0..R.6.$.... .....K..[..q..c..T.....>.P.j.`.w..#...%......N.".....$..3.0.6......... .L.rX/r[j.y.|*(.4.%#.....2.v.m..-..%.....;-.Y.{..&..O=#l@...k..7g..ZI...#.Z./+T..r7...M..3).Z%.x....s..sL..[A!.5*1w'/.8V..2Z..%.X.h.o.).]..9..Q`.$.....7..kZ.~O........d..g.n.d.Rw+&....Cz..uy#..fz,(.J....v.%..`..9.....h...?O..:...c%.....6s....xl..#...5..._......1.>.)"U.4 W....?%......6//!$...!.n9C@n...........!""^.....W..Z<.7.x.."UT.T....E.."R>.R..t.....H d..e_.K../.+8.Q.P.ZQ....;...U....]......._.e*......71.?.7.ORv.?...l...G|.P...|:...I.X..2.,.L........d.g.]}W#uW]QnuP-s.;.-Y.....].......C..j_.M0...y.......J..........NY..@A...,....-.F......'..w./j5g.vUS...U..0.&...y7.LP.....%.....Y......Y..D. e.A..G.?.$.......6...eaK.n5.m...N...,...+BCl..L> .E9~.b[.w.x....6<...}.e...%V....O.......*.?...a..#[eE.4..p..$...].....%......o._......N.._~..El....b..A.0.r8.....|..D.d..
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (522)
                                                    Category:downloaded
                                                    Size (bytes):5050
                                                    Entropy (8bit):5.30005628600801
                                                    Encrypted:false
                                                    SSDEEP:96:o75BuBxJfma7bGZABddEgf8nI4zLm4KGo8Vh1EabPVTq8fv/xRw:WHMmaX9r8Igp7nBlHo
                                                    MD5:D9F15F1AEAF15673336FAA3507D1A2A7
                                                    SHA1:FC79D00AF2E2D44FEBA701F12ECD4AFCA327F464
                                                    SHA-256:AA3574ADCF3826390918BC2D5DCD88D7BC63238A6022DEF3487A67A731C30E7A
                                                    SHA-512:D756961B6BFC478274E390B94D613BD837DA011D680FC6D67779A8E12C7F082EF977FC15D02C076F92BC1D2CE7EFDE48F82B4EC1BD12CF38AEDDAB1917E36041
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,iAskyc,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziXSP,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=wg1P6b"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.oNa=_.z("wg1P6b",[_.XA,_.Fn,_.Nn]);._.k("wg1P6b");.var f6a;f6a=_.mh(["aria-"]);._.yJ=function(a){_.X.call(this,a.Fa);this.Ka=this.xa=this.aa=this.viewportElement=this.Na=null;this.Jc=a.Ea.ef;this.ab=a.Ea.focus;this.Fc=a.Ea.Fc;this.ea=this.Qi();a=-1*parseInt(_.Fo(this.Qi().el(),"marginTop")||"0",10);var b=parseInt(_.Fo(this.Qi().el(),"marginBottom")||"0",10);this.Ta={top:a,right:0,bottom:b,left:0};a=_.cf(this.getData("isMenuDynamic"),!1);b=_.cf(this.getData("isMenuHoisted"),!1);this.Ga=a?1:b?2:0;this.ka=!1;this.Ca=1;this.Ga!==1&&(this.aa=this.Sa("U0exHf").children().Wc(0),_.ku(this,.g6a(this,this.aa.el())));_.oF(this.oa())&&(a=this.oa().el(),b=this.we.bind(this),a.__soy_skip_handler=b)};_.J(_.yJ,_.X);_.yJ.Ba=function(){return{Ea:{ef:_.cF,focus:_.OE,Fc:_.uu}}};_.yJ.prototype.IF=function(a){var b=a.source;this.Na=b;var c;((c=a.data)==null?0:c.qz)?(a=a.data.qz,this.Ca=a==="MOUS
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (395)
                                                    Category:downloaded
                                                    Size (bytes):1608
                                                    Entropy (8bit):5.271783084011668
                                                    Encrypted:false
                                                    SSDEEP:48:o726BiFP89yAxKz1TtMxII+eXww7D2bc+rw:oyMyAAz1WNd8vw
                                                    MD5:45EA91A811A594F81B7F760DD14BE237
                                                    SHA1:2C97782C6D5D0BCFB3676FF24AA1008251090DAE
                                                    SHA-256:7488FF4710E7592F66BE1FAC090F73CB8F1D2D0794B57DEAC1798C5B309EE76F
                                                    SHA-512:4F79A36857D5A8AF1E2F938EF92EA75C384DE4789972B068BE82EADAA442C538A65035CCE8665A7283137E2075B8FE4C1C9E7B2A36585491683B4869005B772A
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=w9hDv,ZDZcre,A7fCU"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("w9hDv");._.vg(_.Ila);_.iA=function(a){_.W.call(this,a.Fa);this.aa=a.Xa.cache};_.J(_.iA,_.W);_.iA.Ba=function(){return{Xa:{cache:_.gt}}};_.iA.prototype.execute=function(a){_.Bb(a,function(b){var c;_.$e(b)&&(c=b.eb.kc(b.kb));c&&this.aa.LG(c)},this);return{}};_.qu(_.Ola,_.iA);._.l();._.k("ZDZcre");.var jH=function(a){_.W.call(this,a.Fa);this.Xl=a.Ea.Xl;this.j4=a.Ea.metadata;this.aa=a.Ea.wt};_.J(jH,_.W);jH.Ba=function(){return{Ea:{Xl:_.OG,metadata:_.b_a,wt:_.LG}}};jH.prototype.execute=function(a){var b=this;a=this.aa.create(a);return _.Bb(a,function(c){var d=b.j4.getType(c.Od())===2?b.Xl.Rb(c):b.Xl.fetch(c);return _.Bl(c,_.PG)?d.then(function(e){return _.Dd(e)}):d},this)};_.qu(_.Tla,jH);._.l();._.k("K5nYTd");._.a_a=new _.pf(_.Pla);._.l();._.k("sP4Vbe");.._.l();._.k("kMFpHd");.._.l();._.k("A7fCU");.var RG=function(a){_.W.call(this,a.Fa);this.aa=a.Ea.yQ};_.J(RG,_.W);RG.Ba=func
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text, with very long lines (681)
                                                    Category:downloaded
                                                    Size (bytes):4067
                                                    Entropy (8bit):5.3700036060139436
                                                    Encrypted:false
                                                    SSDEEP:96:G6mTOIiY1medWRQrf7VF6vtDgXJyA7oxcoTiw:3mTOImedWOVF6vtUJyA8xJ3
                                                    MD5:FA701F5D7BEF5AF6B676F099A00A1140
                                                    SHA1:4CA8594D1E845605E7F1242AD8E10FD3A41FA3BE
                                                    SHA-256:F1F311E29B597B507EE761AE40185A9BE194BA6498F91DD2A69610EF765B554A
                                                    SHA-512:D53CAD789CED1F1D05546CD9DDA662FF47DF4A9FE382F4936EB1579175B06A95770426E5A83C24EACE04014956F1971A6432D1FCB26F2A9E4B922D8A34FC9875
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=sOXFj,q0xTif,ZZ4WUe"
                                                    Preview:"use strict";_F_installCss(".N7rBcd{overflow-x:auto}sentinel{}");.this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.vg(_.bqa);._.k("sOXFj");.var wu=function(a){_.W.call(this,a.Fa)};_.J(wu,_.W);wu.Ba=_.W.Ba;wu.prototype.aa=function(a){return a()};_.qu(_.aqa,wu);._.l();._.k("oGtAuc");._.Bya=new _.pf(_.bqa);._.l();._.k("q0xTif");.var vza=function(a){var b=function(d){_.Zn(d)&&(_.Zn(d).Lc=null,_.Gu(d,null));d.XyHi9&&(d.XyHi9=null)};b(a);a=a.querySelectorAll("[c-wiz]");for(var c=0;c<a.length;c++)b(a[c])},Su=function(a){_.nt.call(this,a.Fa);this.Qa=this.dom=null;if(this.rl()){var b=_.Cm(this.Wg(),[_.Hm,_.Gm]);b=_.pi([b[_.Hm],b[_.Gm]]).then(function(c){this.Qa=c[0];this.dom=c[1]},null,this);_.ku(this,b)}this.Ra=a.lm.Dea};_.J(Su,_.nt);Su.Ba=function(){return{lm:{Dea:function(a){return _.Ue(a)}}}};Su.prototype.Bp=function(a){return this.Ra.Bp(a)};.Su.prototype.getData=function(a){return this.Ra.getData(a)};Su.prototype.uo=function(){_.Nt(this.d
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (553)
                                                    Category:downloaded
                                                    Size (bytes):744742
                                                    Entropy (8bit):5.79285433629193
                                                    Encrypted:false
                                                    SSDEEP:6144:S5bdWK/20rOQKKQtvqUGSGDdPSxdZqmguPH:kOeKGSpgu/
                                                    MD5:1C7A58214662CFB8B2B8D16B812B1856
                                                    SHA1:785EA4F246BCAA415B3925F7281FC9AE16DF7682
                                                    SHA-256:E2E174AC09FA66C8550B4DCAA98E32176A3B5FB861353E1E7FA9821C3C08561D
                                                    SHA-512:AF42906BD50592D00B12E5F57E69490D9E82D72AEF853397637D5572E6622D65FBC13D522ABF1E7BFB815699600A1B5BB83F236E8544903567D52E9C6C01311A
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/excm=_b,_tp,identifierview/ed=1/dg=0/wt=2/ujg=1/rs=AOaEmlHxjc0Ood9pBm5tn_36XhBkXPrbzg/m=_b,_tp"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([0x2860c1c4, 0x20469860, 0x39e1fc40, 0x14501e80, 0xe420, 0x0, 0x1a000000, 0x1d000003, 0xc, ]);./*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/./*.. Copyright Google LLC. SPDX-License-Identifier: Apache-2.0.*/./*.. Copyright 2024 Google, Inc. SPDX-License-Identifier: MIT.*/./*. SPDX-License-Identifier: Apache-2.0.*/./*. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var baa,daa,Na,Ta,gaa,iaa,jb,qaa,waa,Caa,Haa,Kaa,Jb,Laa,Ob,Qb,Rb,Maa,Naa,Sb,Oaa,Paa,Qaa,Yb,Vaa,Xaa,ec,fc,gc,bba,cba,gba,jba,lba,mba,qba,tba,nba,sba,rba,pba,oba,uba,yba,Cba,Dba,Aba,Hc,Ic,Gba,Iba,Mba,Nba,Oba,Pba,Lba,Qba,Sba,dd,Uba,Vba,Xba,Zba,Yba,aca,bca,cca,dca,fca,eca,hca,ica,jca,kca,nca,
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (1694)
                                                    Category:downloaded
                                                    Size (bytes):32500
                                                    Entropy (8bit):5.378121087555083
                                                    Encrypted:false
                                                    SSDEEP:768:OnTTScxIXeijt4aRZf4AEqTzQh2HIVVcYTVf79pew6cVEkAXtuWsmsL:iA4w4A4h2HIVVcMVf72QA9jOL
                                                    MD5:57D7B0A2CE36496F05AFA27B39C1F219
                                                    SHA1:418AD03C2E75AEAF188E2A00123B70E09D541656
                                                    SHA-256:E247A1F5E564A248C92E39C040A06B9B3BEA50A130CC98F2787FB5E2441E0707
                                                    SHA-512:78B135A69424F951AC7E3CCBDC4F496BCA0BE6A2312DC90DFA29032C7DB19455B7E35FEE57F470729EC5E86D52DC19037BB6404C27DF614A548DE409527866C2
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=_b,_tp/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=byfTOb,lsjVmc,LEikZe"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{.var Cua=function(a,b){this.da=a;this.ea=b;if(!c){var c=new _.gp("//www.google.com/images/cleardot.gif");_.rp(c)}this.ka=c};_.h=Cua.prototype;_.h.Zc=null;_.h.rZ=1E4;_.h.jA=!1;_.h.sQ=0;_.h.JJ=null;_.h.gV=null;_.h.setTimeout=function(a){this.rZ=a};_.h.start=function(){if(this.jA)throw Error("dc");this.jA=!0;this.sQ=0;Dua(this)};_.h.stop=function(){Eua(this);this.jA=!1};.var Dua=function(a){a.sQ++;navigator!==null&&"onLine"in navigator&&!navigator.onLine?_.om((0,_.bg)(a.hH,a,!1),0):(a.aa=new Image,a.aa.onload=(0,_.bg)(a.Kja,a),a.aa.onerror=(0,_.bg)(a.Jja,a),a.aa.onabort=(0,_.bg)(a.Ija,a),a.JJ=_.om(a.Lja,a.rZ,a),a.aa.src=String(a.ka))};_.h=Cua.prototype;_.h.Kja=function(){this.hH(!0)};_.h.Jja=function(){this.hH(!1)};_.h.Ija=function(){this.hH(!1)};_.h.Lja=function(){this.hH(!1)};._.h.hH=function(a){Eua(this);a?(this.jA=!1,this.da.call(this.ea,!0)):this.sQ<=0?Dua(this):(this.jA=!1,
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (468)
                                                    Category:downloaded
                                                    Size (bytes):1858
                                                    Entropy (8bit):5.297658905867848
                                                    Encrypted:false
                                                    SSDEEP:48:o7vjoGL3AeFkphnpiu7cOyBfO/3d/rYrv3Zrw:ofrLxFuLdyp2AVw
                                                    MD5:B42DB3D22B12B8E3BE1B82961FE2870E
                                                    SHA1:D9CFD11C1C2DE17A7E9301F11AD875B610B96576
                                                    SHA-256:75DC40A81CEACB57940F84D2B29E021974C3004B245CC7198362CA944E9C4058
                                                    SHA-512:EC0708797586F8F85EC8A0BBECA707D73778D93C12986B92965D1828B254D39485926354AEC4D73474BC5755E392B813D8045B19369FAE23B30BBD12E17F7053
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=iAskyc,ziXSP"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("iAskyc");._.QZ=function(a){_.W.call(this,a.Fa);this.window=a.Ea.window.get();this.Mc=a.Ea.Mc};_.J(_.QZ,_.W);_.QZ.Ba=function(){return{Ea:{window:_.tu,Mc:_.HE}}};_.QZ.prototype.Po=function(){};_.QZ.prototype.addEncryptionRecoveryMethod=function(){};_.RZ=function(a){return(a==null?void 0:a.Jo)||function(){}};_.SZ=function(a){return(a==null?void 0:a.r3)||function(){}};_.VPb=function(a){return(a==null?void 0:a.Qp)||function(){}};._.WPb=function(a){return new Map(Array.from(a,function(b){var c=_.n(b);b=c.next().value;c=c.next().value;return[b,c.map(function(d){return{epoch:d.epoch,key:new Uint8Array(d.key)}})]}))};_.XPb=function(a){setTimeout(function(){throw a;},0)};_.QZ.prototype.qO=function(){return!0};_.qu(_.Dn,_.QZ);._.l();._.k("ziXSP");.var j_=function(a){_.QZ.call(this,a.Fa)};_.J(j_,_.QZ);j_.Ba=_.QZ.Ba;j_.prototype.Po=function(a,b,c){var d;if((d=this.window.chrome)==nu
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with no line terminators
                                                    Category:downloaded
                                                    Size (bytes):84
                                                    Entropy (8bit):4.875266466142591
                                                    Encrypted:false
                                                    SSDEEP:3:DZFJu0+WVTBCq2Bjdw2KsJJuYHSKnZ:lFJuuVTBudw29nu4SKZ
                                                    MD5:87B6333E98B7620EA1FF98D1A837A39E
                                                    SHA1:105DE6815B0885357DE1414BFC0D77FCC9E924EF
                                                    SHA-256:DCD3C133C5C40BECD4100BBE6EDAE84C9735E778E4234A5E8395C56FF8A733BA
                                                    SHA-512:867D7943D813685FAA76394E53199750C55817E836FD19C933F74D11E9657CE66719A6D6B2E39EE1DE62358BCE364E38A55F4E138DF92337DE6985DDCD5D0994
                                                    Malicious:false
                                                    URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISHgmA6QC9dWevzxIFDRkBE_oSBQ3oIX6GEgUN05ioBw==?alt=proto
                                                    Preview:Cj0KBw0ZARP6GgAKKQ3oIX6GGgQISxgCKhwIClIYCg5AIS4jJF8qLSY/Ky8lLBABGP////8PCgcN05ioBxoA
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (5693)
                                                    Category:downloaded
                                                    Size (bytes):698852
                                                    Entropy (8bit):5.594980353163612
                                                    Encrypted:false
                                                    SSDEEP:6144:TN3KfgnkxgOYoRvEoQvSXwojVlmGa/ZLJiH7ZkvgTa5PB1+UO5Hx+B8U2+:TUMkxgOENagFxJiyU+
                                                    MD5:AA9FDCBE29C6D043DC83A7DAD848CCC3
                                                    SHA1:E3F0A387A0A4B060620C975E1C70AA20294F3F22
                                                    SHA-256:1A624C24D6D712C633F0B034606610DAD6B5AD7890FBFA3A9B204BD33207D60E
                                                    SHA-512:C93878CE1281349204ABDB4444B18A12C03A010D1A252827EBFE45523E834988CE95D6E625FF82A60934D7A275AD8DAAC689E4412C5719ACCA8C9E1D4365B4D3
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=LEikZe,_b,_tp,byfTOb,lsjVmc/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=n73qwf,SCuOPb,IZT63,vfuNJf,UUJqVe,ws9Tlc,siKnQd,XVq9Qb,STuCOe,njlZCf,m9oV,vjKJJ,y5vRwf,iyZMqd,NTMZac,mzzZzc,rCcCxc,vvMGie,K1ZKnb,ziZ8Mc,b3kMqb,mvkUhe,CMcBD,Fndnac,t2srLd,EN3i8d,z0u0L,xiZRqc,NOeYWe,O6y8ed,L9OGUe,PrPYRd,MpJwZc,qPfo0c,cYShmd,hc6Ubd,Rkm0ef,KUM7Z,oLggrd,inNHtf,L1AAkb,WpP9Yc,lwddkf,gJzDyc,SpsfSb,aC1iue,tUnxGc,aW3pY,ZakeSe,EFQ78c,xQtZb,I6YDgd,zbML3c,zr1jrb,vHEMJe,YHI3We,YTxL4,bSspM,Uas9Hd,zy0vNb,K0PMbc,AvtSve,qmdT9,MY7mZe,xBaz7b,GwYlN,eVCnO,EIOG1e,LDQI"
                                                    Preview:"use strict";_F_installCss(".r4WGQb{position:relative}.Dl08I>:first-child{margin-top:0}.Dl08I>:last-child{margin-bottom:0}.IzwVE{color:#1f1f1f;color:var(--gm3-sys-color-on-surface,#1f1f1f);font-family:\"Google Sans\",roboto,\"Noto Sans Myanmar UI\",arial,sans-serif;font-size:1.25rem;font-weight:400;letter-spacing:0rem;line-height:1.2}.l5PPKe{color:#1f1f1f;color:var(--gm3-sys-color-on-surface,#1f1f1f);font-size:1rem}.l5PPKe .dMNVAe{margin:0;padding:0}.l5PPKe>:first-child{margin-top:0;padding-top:0}.l5PPKe>:last-child{margin-bottom:0;padding-bottom:0}.Dl08I{margin:0;padding:0;position:relative}.Dl08I>.SmR8:only-child{padding-top:1px}.Dl08I>.SmR8:only-child::before{top:0}.Dl08I>.SmR8:not(first-child){padding-bottom:1px}.Dl08I>.SmR8::after{bottom:0}.Dl08I>.SmR8:only-child::before,.Dl08I>.SmR8::after{border-bottom:1px solid #c4c7c5;border-bottom:1px solid var(--gm3-sys-color-outline-variant,#c4c7c5);content:\"\";height:0;left:0;position:absolute;width:100%}.aZvCDf{margin-top:8px;margin-left
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (570)
                                                    Category:downloaded
                                                    Size (bytes):3467
                                                    Entropy (8bit):5.508385764606741
                                                    Encrypted:false
                                                    SSDEEP:96:ogbsxK3SrI2Jrutmxy9FALtcP+EGYkxhclzV9xCw:Psc3OIpDj2ZYkxhATxX
                                                    MD5:231ABD6E6C360E709640B399EDF85476
                                                    SHA1:6CB98F38D9B6FDCF2E7D7C7682A219082F2E1E75
                                                    SHA-256:44B5D535663C65CD2E6228EF1F0C3DBA9C89EAE5C1BF079A6C4C64972DEE989D
                                                    SHA-512:D45455810B34493A05BA2DD7ADF24C0C009F4CF0898AE9C57978D38C8F2654CEEFC11D1C151BA72B902E0FA87537D43C37957DCAEC1792B5277B54C8E7BCCA3C
                                                    Malicious:false
                                                    URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBimEQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,iAskyc,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,wg1P6b,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziXSP,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_Qg1PP-75cLw_ogQnFnTJMeFddQ/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=Wt6vjf,hhhU8,FCpbqb,WhJNk"
                                                    Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("Wt6vjf");.var fya=function(){var a=_.He();return _.Nj(a,1)},au=function(a){this.Da=_.t(a,0,au.messageId)};_.J(au,_.v);au.prototype.Ha=function(){return _.Fj(this,1)};au.prototype.Ua=function(a){return _.Xj(this,1,a)};au.messageId="f.bo";var bu=function(){_.km.call(this)};_.J(bu,_.km);bu.prototype.xd=function(){this.NT=!1;gya(this);_.km.prototype.xd.call(this)};bu.prototype.aa=function(){hya(this);if(this.JC)return iya(this),!1;if(!this.UV)return cu(this),!0;this.dispatchEvent("p");if(!this.HP)return cu(this),!0;this.NM?(this.dispatchEvent("r"),cu(this)):iya(this);return!1};.var jya=function(a){var b=new _.gp(a.b5);a.vQ!=null&&_.Mn(b,"authuser",a.vQ);return b},iya=function(a){a.JC=!0;var b=jya(a),c="rt=r&f_uid="+_.rk(a.HP);_.fn(b,(0,_.bg)(a.ea,a),"POST",c)};.bu.prototype.ea=function(a){a=a.target;hya(this);if(_.jn(a)){this.iK=0;if(this.NM)this.JC=!1,this.dispatchEvent("r"
                                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                    Entropy (8bit):6.583820839811423
                                                    TrID:
                                                    • Win32 Executable (generic) a (10002005/4) 99.96%
                                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                                    • DOS Executable Generic (2002/1) 0.02%
                                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                    File name:file.exe
                                                    File size:919'040 bytes
                                                    MD5:feb3d620cdd56c7fbe1c54ae29328327
                                                    SHA1:938774fde226ba51c661ecc5a45200081b0c5d5a
                                                    SHA256:30e8732cac1a2ab649d3aad8a297889cad6eb13754e4607d641a4a610f86ef27
                                                    SHA512:e0f3f8beb34585e00978d386a33ae41a892edd29b77e7a9c2442c1c274934c5f79967851d06f66af4bf713d86a3975630d200c52fb0f653f3a8372325825d705
                                                    SSDEEP:24576:gqDEvCTbMWu7rQYlBQcBiT6rprG8a4OK:gTvC/MTQYxsWR7a4
                                                    TLSH:B4159E0273D1C062FFAB92334B5AF6515BBC69260123E61F13981DB9BE701B1563E7A3
                                                    File Content Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......................j:......j:..C...j:......@.*...............................n.......~.............{.......{.......{.........z....
                                                    Icon Hash:aaf3e3e3938382a0
                                                    Entrypoint:0x420577
                                                    Entrypoint Section:.text
                                                    Digitally signed:false
                                                    Imagebase:0x400000
                                                    Subsystem:windows gui
                                                    Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
                                                    DLL Characteristics:DYNAMIC_BASE, TERMINAL_SERVER_AWARE
                                                    Time Stamp:0x66FEBE4E [Thu Oct 3 15:54:54 2024 UTC]
                                                    TLS Callbacks:
                                                    CLR (.Net) Version:
                                                    OS Version Major:5
                                                    OS Version Minor:1
                                                    File Version Major:5
                                                    File Version Minor:1
                                                    Subsystem Version Major:5
                                                    Subsystem Version Minor:1
                                                    Import Hash:948cc502fe9226992dce9417f952fce3
                                                    Instruction
                                                    call 00007F93ECFEBEF3h
                                                    jmp 00007F93ECFEB7FFh
                                                    push ebp
                                                    mov ebp, esp
                                                    push esi
                                                    push dword ptr [ebp+08h]
                                                    mov esi, ecx
                                                    call 00007F93ECFEB9DDh
                                                    mov dword ptr [esi], 0049FDF0h
                                                    mov eax, esi
                                                    pop esi
                                                    pop ebp
                                                    retn 0004h
                                                    and dword ptr [ecx+04h], 00000000h
                                                    mov eax, ecx
                                                    and dword ptr [ecx+08h], 00000000h
                                                    mov dword ptr [ecx+04h], 0049FDF8h
                                                    mov dword ptr [ecx], 0049FDF0h
                                                    ret
                                                    push ebp
                                                    mov ebp, esp
                                                    push esi
                                                    push dword ptr [ebp+08h]
                                                    mov esi, ecx
                                                    call 00007F93ECFEB9AAh
                                                    mov dword ptr [esi], 0049FE0Ch
                                                    mov eax, esi
                                                    pop esi
                                                    pop ebp
                                                    retn 0004h
                                                    and dword ptr [ecx+04h], 00000000h
                                                    mov eax, ecx
                                                    and dword ptr [ecx+08h], 00000000h
                                                    mov dword ptr [ecx+04h], 0049FE14h
                                                    mov dword ptr [ecx], 0049FE0Ch
                                                    ret
                                                    push ebp
                                                    mov ebp, esp
                                                    push esi
                                                    mov esi, ecx
                                                    lea eax, dword ptr [esi+04h]
                                                    mov dword ptr [esi], 0049FDD0h
                                                    and dword ptr [eax], 00000000h
                                                    and dword ptr [eax+04h], 00000000h
                                                    push eax
                                                    mov eax, dword ptr [ebp+08h]
                                                    add eax, 04h
                                                    push eax
                                                    call 00007F93ECFEE59Dh
                                                    pop ecx
                                                    pop ecx
                                                    mov eax, esi
                                                    pop esi
                                                    pop ebp
                                                    retn 0004h
                                                    lea eax, dword ptr [ecx+04h]
                                                    mov dword ptr [ecx], 0049FDD0h
                                                    push eax
                                                    call 00007F93ECFEE5E8h
                                                    pop ecx
                                                    ret
                                                    push ebp
                                                    mov ebp, esp
                                                    push esi
                                                    mov esi, ecx
                                                    lea eax, dword ptr [esi+04h]
                                                    mov dword ptr [esi], 0049FDD0h
                                                    push eax
                                                    call 00007F93ECFEE5D1h
                                                    test byte ptr [ebp+08h], 00000001h
                                                    pop ecx
                                                    Programming Language:
                                                    • [ C ] VS2008 SP1 build 30729
                                                    • [IMP] VS2008 SP1 build 30729
                                                    NameVirtual AddressVirtual Size Is in Section
                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0xc8e640x17c.rdata
                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0xd40000x9bb8.rsrc
                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0xde0000x7594.reloc
                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0xb0ff00x1c.rdata
                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_TLS0xc34000x18.rdata
                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xb10100x40.rdata
                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IAT0x9c0000x894.rdata
                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                    .text0x10000x9ab1d0x9ac000a1473f3064dcbc32ef93c5c8a90f3a6False0.565500681542811data6.668273581389308IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                    .rdata0x9c0000x2fb820x2fc00c9cf2468b60bf4f80f136ed54b3989fbFalse0.35289185209424084data5.691811547483722IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                    .data0xcc0000x706c0x480053b9025d545d65e23295e30afdbd16d9False0.04356553819444445DOS executable (block device driver @\273\)0.5846666986982398IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    .rsrc0xd40000x9bb80x9c008b216824b2df68708e384352eb9c55f0False0.3166316105769231data5.332375934592244IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                    .reloc0xde0000x75940x7600c68ee8931a32d45eb82dc450ee40efc3False0.7628111758474576data6.7972128181359786IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                    RT_ICON0xd45a80x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishGreat Britain0.7466216216216216
                                                    RT_ICON0xd46d00x128Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colorsEnglishGreat Britain0.3277027027027027
                                                    RT_ICON0xd47f80x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishGreat Britain0.3885135135135135
                                                    RT_ICON0xd49200x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 0EnglishGreat Britain0.3333333333333333
                                                    RT_ICON0xd4c080x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishGreat Britain0.5
                                                    RT_ICON0xd4d300xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0EnglishGreat Britain0.2835820895522388
                                                    RT_ICON0xd5bd80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0EnglishGreat Britain0.37906137184115524
                                                    RT_ICON0xd64800x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishGreat Britain0.23699421965317918
                                                    RT_ICON0xd69e80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishGreat Britain0.13858921161825727
                                                    RT_ICON0xd8f900x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishGreat Britain0.25070356472795496
                                                    RT_ICON0xda0380x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishGreat Britain0.3173758865248227
                                                    RT_MENU0xda4a00x50dataEnglishGreat Britain0.9
                                                    RT_STRING0xda4f00x594dataEnglishGreat Britain0.3333333333333333
                                                    RT_STRING0xdaa840x68adataEnglishGreat Britain0.2735961768219833
                                                    RT_STRING0xdb1100x490dataEnglishGreat Britain0.3715753424657534
                                                    RT_STRING0xdb5a00x5fcdataEnglishGreat Britain0.3087467362924282
                                                    RT_STRING0xdbb9c0x65cdataEnglishGreat Britain0.34336609336609336
                                                    RT_STRING0xdc1f80x466dataEnglishGreat Britain0.3605683836589698
                                                    RT_STRING0xdc6600x158Matlab v4 mat-file (little endian) n, numeric, rows 0, columns 0EnglishGreat Britain0.502906976744186
                                                    RT_RCDATA0xdc7b80xe7edata1.002964959568733
                                                    RT_GROUP_ICON0xdd6380x76dataEnglishGreat Britain0.6610169491525424
                                                    RT_GROUP_ICON0xdd6b00x14dataEnglishGreat Britain1.25
                                                    RT_GROUP_ICON0xdd6c40x14dataEnglishGreat Britain1.15
                                                    RT_GROUP_ICON0xdd6d80x14dataEnglishGreat Britain1.25
                                                    RT_VERSION0xdd6ec0xdcdataEnglishGreat Britain0.6181818181818182
                                                    RT_MANIFEST0xdd7c80x3efASCII text, with CRLF line terminatorsEnglishGreat Britain0.5074478649453823
                                                    DLLImport
                                                    WSOCK32.dllgethostbyname, recv, send, socket, inet_ntoa, setsockopt, ntohs, WSACleanup, WSAStartup, sendto, htons, __WSAFDIsSet, select, accept, listen, bind, inet_addr, ioctlsocket, recvfrom, WSAGetLastError, closesocket, gethostname, connect
                                                    VERSION.dllGetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
                                                    WINMM.dlltimeGetTime, waveOutSetVolume, mciSendStringW
                                                    COMCTL32.dllImageList_ReplaceIcon, ImageList_Destroy, ImageList_Remove, ImageList_SetDragCursorImage, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_EndDrag, ImageList_DragMove, InitCommonControlsEx, ImageList_Create
                                                    MPR.dllWNetGetConnectionW, WNetCancelConnection2W, WNetUseConnectionW, WNetAddConnection2W
                                                    WININET.dllHttpOpenRequestW, InternetCloseHandle, InternetOpenW, InternetSetOptionW, InternetCrackUrlW, HttpQueryInfoW, InternetQueryOptionW, InternetConnectW, HttpSendRequestW, FtpOpenFileW, FtpGetFileSize, InternetOpenUrlW, InternetReadFile, InternetQueryDataAvailable
                                                    PSAPI.DLLGetProcessMemoryInfo
                                                    IPHLPAPI.DLLIcmpSendEcho, IcmpCloseHandle, IcmpCreateFile
                                                    USERENV.dllDestroyEnvironmentBlock, LoadUserProfileW, CreateEnvironmentBlock, UnloadUserProfile
                                                    UxTheme.dllIsThemeActive
                                                    KERNEL32.dllDuplicateHandle, CreateThread, WaitForSingleObject, HeapAlloc, GetProcessHeap, HeapFree, Sleep, GetCurrentThreadId, MultiByteToWideChar, MulDiv, GetVersionExW, IsWow64Process, GetSystemInfo, FreeLibrary, LoadLibraryA, GetProcAddress, SetErrorMode, GetModuleFileNameW, WideCharToMultiByte, lstrcpyW, lstrlenW, GetModuleHandleW, QueryPerformanceCounter, VirtualFreeEx, OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateFileW, SetFilePointerEx, SetEndOfFile, ReadFile, WriteFile, FlushFileBuffers, TerminateProcess, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetFileTime, GetFileAttributesW, FindFirstFileW, FindClose, GetLongPathNameW, GetShortPathNameW, DeleteFileW, IsDebuggerPresent, CopyFileExW, MoveFileW, CreateDirectoryW, RemoveDirectoryW, SetSystemPowerState, QueryPerformanceFrequency, LoadResource, LockResource, SizeofResource, OutputDebugStringW, GetTempPathW, GetTempFileNameW, DeviceIoControl, LoadLibraryW, GetLocalTime, CompareStringW, GetCurrentThread, EnterCriticalSection, LeaveCriticalSection, GetStdHandle, CreatePipe, InterlockedExchange, TerminateThread, LoadLibraryExW, FindResourceExW, CopyFileW, VirtualFree, FormatMessageW, GetExitCodeProcess, GetPrivateProfileStringW, WritePrivateProfileStringW, GetPrivateProfileSectionW, WritePrivateProfileSectionW, GetPrivateProfileSectionNamesW, FileTimeToLocalFileTime, FileTimeToSystemTime, SystemTimeToFileTime, LocalFileTimeToFileTime, GetDriveTypeW, GetDiskFreeSpaceExW, GetDiskFreeSpaceW, GetVolumeInformationW, SetVolumeLabelW, CreateHardLinkW, SetFileAttributesW, CreateEventW, SetEvent, GetEnvironmentVariableW, SetEnvironmentVariableW, GlobalLock, GlobalUnlock, GlobalAlloc, GetFileSize, GlobalFree, GlobalMemoryStatusEx, Beep, GetSystemDirectoryW, HeapReAlloc, HeapSize, GetComputerNameW, GetWindowsDirectoryW, GetCurrentProcessId, GetProcessIoCounters, CreateProcessW, GetProcessId, SetPriorityClass, VirtualAlloc, GetCurrentDirectoryW, lstrcmpiW, DecodePointer, GetLastError, RaiseException, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, InterlockedDecrement, InterlockedIncrement, ResetEvent, WaitForSingleObjectEx, IsProcessorFeaturePresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, CloseHandle, GetFullPathNameW, GetStartupInfoW, GetSystemTimeAsFileTime, InitializeSListHead, RtlUnwind, SetLastError, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, ExitProcess, GetModuleHandleExW, ExitThread, ResumeThread, FreeLibraryAndExitThread, GetACP, GetDateFormatW, GetTimeFormatW, LCMapStringW, GetStringTypeW, GetFileType, SetStdHandle, GetConsoleCP, GetConsoleMode, ReadConsoleW, GetTimeZoneInformation, FindFirstFileExW, IsValidCodePage, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableA, SetCurrentDirectoryW, FindNextFileW, WriteConsoleW
                                                    USER32.dllGetKeyboardLayoutNameW, IsCharAlphaW, IsCharAlphaNumericW, IsCharLowerW, IsCharUpperW, GetMenuStringW, GetSubMenu, GetCaretPos, IsZoomed, GetMonitorInfoW, SetWindowLongW, SetLayeredWindowAttributes, FlashWindow, GetClassLongW, TranslateAcceleratorW, IsDialogMessageW, GetSysColor, InflateRect, DrawFocusRect, DrawTextW, FrameRect, DrawFrameControl, FillRect, PtInRect, DestroyAcceleratorTable, CreateAcceleratorTableW, SetCursor, GetWindowDC, GetSystemMetrics, GetActiveWindow, CharNextW, wsprintfW, RedrawWindow, DrawMenuBar, DestroyMenu, SetMenu, GetWindowTextLengthW, CreateMenu, IsDlgButtonChecked, DefDlgProcW, CallWindowProcW, ReleaseCapture, SetCapture, PeekMessageW, GetInputState, UnregisterHotKey, CharLowerBuffW, MonitorFromPoint, MonitorFromRect, LoadImageW, mouse_event, ExitWindowsEx, SetActiveWindow, FindWindowExW, EnumThreadWindows, SetMenuDefaultItem, InsertMenuItemW, IsMenu, ClientToScreen, GetCursorPos, DeleteMenu, CheckMenuRadioItem, GetMenuItemID, GetMenuItemCount, SetMenuItemInfoW, GetMenuItemInfoW, SetForegroundWindow, IsIconic, FindWindowW, SystemParametersInfoW, LockWindowUpdate, SendInput, GetAsyncKeyState, SetKeyboardState, GetKeyboardState, GetKeyState, VkKeyScanW, LoadStringW, DialogBoxParamW, MessageBeep, EndDialog, SendDlgItemMessageW, GetDlgItem, SetWindowTextW, CopyRect, ReleaseDC, GetDC, EndPaint, BeginPaint, GetClientRect, GetMenu, DestroyWindow, EnumWindows, GetDesktopWindow, IsWindow, IsWindowEnabled, IsWindowVisible, EnableWindow, InvalidateRect, GetWindowLongW, GetWindowThreadProcessId, AttachThreadInput, GetFocus, GetWindowTextW, SendMessageTimeoutW, EnumChildWindows, CharUpperBuffW, GetClassNameW, GetParent, GetDlgCtrlID, SendMessageW, MapVirtualKeyW, PostMessageW, GetWindowRect, SetUserObjectSecurity, CloseDesktop, CloseWindowStation, OpenDesktopW, RegisterHotKey, GetCursorInfo, SetWindowPos, CopyImage, AdjustWindowRectEx, SetRect, SetClipboardData, EmptyClipboard, CountClipboardFormats, CloseClipboard, GetClipboardData, IsClipboardFormatAvailable, OpenClipboard, BlockInput, TrackPopupMenuEx, GetMessageW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, GetUserObjectSecurity, MessageBoxW, DefWindowProcW, MoveWindow, SetFocus, PostQuitMessage, KillTimer, CreatePopupMenu, RegisterWindowMessageW, SetTimer, ShowWindow, CreateWindowExW, RegisterClassExW, LoadIconW, LoadCursorW, GetSysColorBrush, GetForegroundWindow, MessageBoxA, DestroyIcon, DispatchMessageW, keybd_event, TranslateMessage, ScreenToClient
                                                    GDI32.dllEndPath, DeleteObject, GetTextExtentPoint32W, ExtCreatePen, StrokeAndFillPath, GetDeviceCaps, SetPixel, CloseFigure, LineTo, AngleArc, MoveToEx, Ellipse, CreateCompatibleBitmap, CreateCompatibleDC, PolyDraw, BeginPath, Rectangle, SetViewportOrgEx, GetObjectW, SetBkMode, RoundRect, SetBkColor, CreatePen, SelectObject, StretchBlt, CreateSolidBrush, SetTextColor, CreateFontW, GetTextFaceW, GetStockObject, CreateDCW, GetPixel, DeleteDC, GetDIBits, StrokePath
                                                    COMDLG32.dllGetSaveFileNameW, GetOpenFileNameW
                                                    ADVAPI32.dllGetAce, RegEnumValueW, RegDeleteValueW, RegDeleteKeyW, RegEnumKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegQueryValueExW, RegConnectRegistryW, InitializeSecurityDescriptor, InitializeAcl, AdjustTokenPrivileges, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, CreateProcessAsUserW, CreateProcessWithLogonW, GetLengthSid, CopySid, LogonUserW, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, GetTokenInformation, RegCreateKeyExW, GetSecurityDescriptorDacl, GetAclInformation, GetUserNameW, AddAce, SetSecurityDescriptorDacl, InitiateSystemShutdownExW
                                                    SHELL32.dllDragFinish, DragQueryPoint, ShellExecuteExW, DragQueryFileW, SHEmptyRecycleBinW, SHGetPathFromIDListW, SHBrowseForFolderW, SHCreateShellItem, SHGetDesktopFolder, SHGetSpecialFolderLocation, SHGetFolderPathW, SHFileOperationW, ExtractIconExW, Shell_NotifyIconW, ShellExecuteW
                                                    ole32.dllCoTaskMemAlloc, CoTaskMemFree, CLSIDFromString, ProgIDFromCLSID, CLSIDFromProgID, OleSetMenuDescriptor, MkParseDisplayName, OleSetContainedObject, CoCreateInstance, IIDFromString, StringFromGUID2, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoInitialize, CoUninitialize, GetRunningObjectTable, CoGetInstanceFromFile, CoGetObject, CoInitializeSecurity, CoCreateInstanceEx, CoSetProxyBlanket
                                                    OLEAUT32.dllCreateStdDispatch, CreateDispTypeInfo, UnRegisterTypeLib, UnRegisterTypeLibForUser, RegisterTypeLibForUser, RegisterTypeLib, LoadTypeLibEx, VariantCopyInd, SysReAllocString, SysFreeString, VariantChangeType, SafeArrayDestroyData, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayAllocData, SafeArrayAllocDescriptorEx, SafeArrayCreateVector, SysStringLen, QueryPathOfRegTypeLib, SysAllocString, VariantInit, VariantClear, DispCallFunc, VariantTimeToSystemTime, VarR8FromDec, SafeArrayGetVartype, SafeArrayDestroyDescriptor, VariantCopy, OleLoadPicture
                                                    Language of compilation systemCountry where language is spokenMap
                                                    EnglishGreat Britain
                                                    TimestampSource PortDest PortSource IPDest IP
                                                    Oct 3, 2024 18:16:11.004517078 CEST49675443192.168.2.4173.222.162.32
                                                    Oct 3, 2024 18:16:12.189805984 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.189865112 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:12.189934015 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.194423914 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.194441080 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:12.844944954 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:12.845160007 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.845204115 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:12.845772982 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:12.845972061 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.846760035 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:12.846811056 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.848433971 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.848534107 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:12.848547935 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.893898964 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:12.893920898 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:12.941004992 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:13.134985924 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:13.135221958 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:13.135482073 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:13.135529041 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:13.135745049 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:13.327898026 CEST49731443192.168.2.4142.250.185.238
                                                    Oct 3, 2024 18:16:13.327965975 CEST44349731142.250.185.238192.168.2.4
                                                    Oct 3, 2024 18:16:13.345716000 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:13.345805883 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:13.345889091 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:13.346118927 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:13.346143007 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.266396999 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.266742945 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.266805887 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.267936945 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.268040895 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.268955946 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.269038916 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.270556927 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.270641088 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.270945072 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.270962954 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.315772057 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.575162888 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.575330973 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.575366020 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.575440884 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:14.577111959 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.577233076 CEST49736443192.168.2.4172.217.16.206
                                                    Oct 3, 2024 18:16:14.577265978 CEST44349736172.217.16.206192.168.2.4
                                                    Oct 3, 2024 18:16:16.481487989 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:16.481566906 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:16.481640100 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:16.481833935 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:16.481867075 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:16.641568899 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:16.641669989 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:16.641771078 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:16.643246889 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:16.643280029 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.144670963 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:17.145042896 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:17.145102978 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:17.146759987 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:17.147062063 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:17.147819042 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:17.147917986 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:17.190851927 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:17.190911055 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:17.237587929 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:17.316942930 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.320667982 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.326709032 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.326762915 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.327191114 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.367867947 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.458646059 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.503411055 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.644099951 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.644258022 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.644320965 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.645806074 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.645833015 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.645848989 CEST49742443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.645855904 CEST44349742184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.800228119 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.800290108 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:17.800431013 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.800723076 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:17.800749063 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:18.472877979 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:18.472965956 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:18.476448059 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:18.476475000 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:18.477382898 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:18.479361057 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:18.523430109 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:18.747590065 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:18.747745037 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:18.747839928 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:18.748555899 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:18.748555899 CEST49744443192.168.2.4184.28.90.27
                                                    Oct 3, 2024 18:16:18.748586893 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:18.748608112 CEST44349744184.28.90.27192.168.2.4
                                                    Oct 3, 2024 18:16:21.698443890 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:21.698545933 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:21.698625088 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:21.698949099 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:21.698983908 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.130594969 CEST49672443192.168.2.4173.222.162.32
                                                    Oct 3, 2024 18:16:22.130685091 CEST44349672173.222.162.32192.168.2.4
                                                    Oct 3, 2024 18:16:22.340605021 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.350147009 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.350171089 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.351664066 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.351739883 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.353871107 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.353923082 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.356832027 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.357106924 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.357114077 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.357219934 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.411411047 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.411426067 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.457334995 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.667355061 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.667517900 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.667598963 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.667627096 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.667655945 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.667682886 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.670206070 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.670265913 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.670296907 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.675538063 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.675597906 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.675611973 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.675637007 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.675687075 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.675699949 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.681565046 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.681622982 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.681634903 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.688050032 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.688107014 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.688119888 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.688141108 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.688188076 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.688199043 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.732510090 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.751497984 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.751555920 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.751579046 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.751638889 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.760397911 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.760458946 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.760485888 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.760538101 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.760562897 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.760613918 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.764691114 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.764753103 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.771226883 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.771289110 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.771308899 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.777009010 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.777067900 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.777085066 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.783468008 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.783528090 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.783541918 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.783993006 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.784054041 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.787444115 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.787444115 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:22.787477016 CEST44349756216.58.206.78192.168.2.4
                                                    Oct 3, 2024 18:16:22.787528038 CEST49756443192.168.2.4216.58.206.78
                                                    Oct 3, 2024 18:16:24.462224960 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:24.462260962 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:24.462398052 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:24.463402033 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:24.463418007 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:24.627908945 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:24.671457052 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:24.898178101 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:24.898308039 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:24.898405075 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:24.898473024 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:24.898493052 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:24.898519993 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:24.898561001 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:24.898777008 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:24.898833990 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:24.911020994 CEST49741443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:16:24.911061049 CEST44349741142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:16:25.147536993 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:25.147603989 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:25.150512934 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:25.150530100 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:25.150928020 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:25.191787004 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:25.882014036 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:25.927401066 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104053974 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104120970 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104145050 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104214907 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:26.104216099 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:26.104233027 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104244947 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104311943 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:26.104335070 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104460955 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:26.104468107 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104481936 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.104522943 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:26.859304905 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:26.859306097 CEST49769443192.168.2.4172.202.163.200
                                                    Oct 3, 2024 18:16:26.859333992 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:26.859347105 CEST44349769172.202.163.200192.168.2.4
                                                    Oct 3, 2024 18:16:58.996618032 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:58.996687889 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:58.996766090 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:58.997046947 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:58.997102022 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.642244101 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.642513990 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.645915985 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.645946026 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.646477938 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.653837919 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.699405909 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.757448912 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.757517099 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.757563114 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.757607937 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.757680893 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.757725000 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.757747889 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.839792013 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.839853048 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.840075016 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.840135098 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.840384007 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.841525078 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.841581106 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.841731071 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.841747046 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.841804028 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.926063061 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.926129103 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.926156044 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.926172972 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.926198959 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.926217079 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.927481890 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.927545071 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.927556038 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.927577019 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.927608967 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.927651882 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.928206921 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.928260088 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.928283930 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.928294897 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.928322077 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.928340912 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.951503992 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.951565981 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.951575994 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.951597929 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:16:59.951627016 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:16:59.951649904 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.013020039 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.013051033 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.013098001 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.013119936 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.013144016 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.013163090 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.013788939 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.013833046 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.013868093 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.013880968 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.013905048 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.013927937 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.014925957 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.014952898 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.014996052 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.015007019 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.015031099 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.015054941 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.015811920 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.015834093 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.015873909 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.015886068 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.015911102 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.015937090 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.016921997 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.016952991 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.016990900 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.017003059 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.017028093 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.017045975 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.017220974 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.017267942 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.017321110 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.017884016 CEST49784443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.017915010 CEST4434978413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.046221972 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.046314001 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.046621084 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.047328949 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.047432899 CEST4434978613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.047507048 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.047610044 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.047643900 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.048715115 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.048765898 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.048825026 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.048829079 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.048852921 CEST4434978613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.048907995 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.048922062 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.049396038 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.049487114 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.049546957 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.049705982 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.049729109 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.050249100 CEST49789443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.050337076 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.050409079 CEST49789443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.050508976 CEST49789443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.050529003 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.691709042 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.693960905 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.699199915 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.699325085 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.707845926 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.707900047 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.711319923 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.711333990 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.712857962 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.712918043 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.713566065 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.713579893 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.714394093 CEST49789443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.714452982 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.714751959 CEST49789443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.714804888 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.714961052 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.715017080 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.716861963 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.716878891 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.731018066 CEST4434978613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.731482983 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.731542110 CEST4434978613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.731931925 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.731983900 CEST4434978613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.808936119 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.808990002 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.809114933 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.809215069 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.809288979 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.809603930 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.809604883 CEST49787443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.809658051 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.809678078 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.809685946 CEST4434978713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.809732914 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.809807062 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.809849024 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.810195923 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.810195923 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.810197115 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.811055899 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.811199903 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.811269999 CEST49789443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.811806917 CEST49789443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.811806917 CEST49789443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.811872959 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.811908960 CEST4434978913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.813648939 CEST49790443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.813731909 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.813745022 CEST49791443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.813833952 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.813834906 CEST49790443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.813896894 CEST49791443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.813955069 CEST49790443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.813976049 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.814034939 CEST49791443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.814069033 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.814116001 CEST49792443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.814169884 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.814224005 CEST49792443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.814361095 CEST49792443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.814368963 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.815002918 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.815059900 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.815123081 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.815165997 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.815200090 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.815224886 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.815252066 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.815289021 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.815289021 CEST49785443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.815319061 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.815340996 CEST4434978513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.817100048 CEST49793443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.817184925 CEST4434979313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.817418098 CEST49793443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.817418098 CEST49793443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.817548037 CEST4434979313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.899524927 CEST4434978613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.899714947 CEST4434978613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.899912119 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.899913073 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.899913073 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.901535034 CEST49794443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.901618004 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:00.901719093 CEST49794443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.901798010 CEST49794443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:00.901822090 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.035693884 CEST49788443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.035770893 CEST4434978813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.118897915 CEST49786443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.118958950 CEST4434978613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.460201025 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.462227106 CEST49792443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.462274075 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.462680101 CEST49792443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.462687016 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.485305071 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.486056089 CEST49790443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.486085892 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.486330986 CEST49790443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.486356974 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.487258911 CEST4434979313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.487343073 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.487751007 CEST49793443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.487807989 CEST4434979313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.487859011 CEST49791443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.487917900 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.488111973 CEST49793443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.488126993 CEST4434979313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.488137007 CEST49791443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.488157988 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.540258884 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.540916920 CEST49794443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.540999889 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.541102886 CEST49794443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.541117907 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.570832014 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.570975065 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.571146965 CEST49792443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.571192980 CEST49792443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.571213961 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.571254015 CEST49792443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.571265936 CEST4434979213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.573899984 CEST49795443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.573925018 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.574137926 CEST49795443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.574137926 CEST49795443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.574204922 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.584887028 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.585038900 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.585108995 CEST49790443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.585352898 CEST49790443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.585354090 CEST49790443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.585386038 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.585403919 CEST4434979013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.587156057 CEST49796443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.587193012 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.587260962 CEST49796443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.587379932 CEST49796443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.587397099 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.589251041 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.589436054 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.589500904 CEST49791443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.589575052 CEST49791443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.589576006 CEST49791443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.589622974 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.589648962 CEST4434979113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.591182947 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.591239929 CEST4434979313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.591269970 CEST4434979713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.591361046 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.591425896 CEST4434979313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.591486931 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.591509104 CEST49793443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.591509104 CEST49793443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.591516018 CEST4434979713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.591588974 CEST49793443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.591624975 CEST4434979313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.593281031 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.593363047 CEST4434979813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.593445063 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.593533039 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.593555927 CEST4434979813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.643093109 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.643162966 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.643462896 CEST49794443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.644469976 CEST49794443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.644469976 CEST49794443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.644535065 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.644570112 CEST4434979413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.645194054 CEST49799443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.645207882 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:01.645262957 CEST49799443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.645344973 CEST49799443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:01.645350933 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.236413002 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.237149954 CEST49795443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.237194061 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.237729073 CEST49795443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.237755060 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.241286993 CEST4434979813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.241705894 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.241765976 CEST4434979813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.242053986 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.242108107 CEST4434979813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.250169039 CEST4434979713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.250405073 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.250463963 CEST4434979713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.250791073 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.250844002 CEST4434979713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.269035101 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.269433975 CEST49796443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.269448996 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.269882917 CEST49796443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.269887924 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.308952093 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.309289932 CEST49799443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.309309006 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.309607029 CEST49799443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.309612989 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.337812901 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.337905884 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.337971926 CEST49795443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.338093996 CEST49795443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.338118076 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.338131905 CEST49795443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.338140965 CEST4434979513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.341032982 CEST49800443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.341128111 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.341403008 CEST49800443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.341403961 CEST49800443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.341533899 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.342065096 CEST4434979813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.342215061 CEST4434979813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.342391014 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.342391968 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.342391968 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.344091892 CEST49801443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.344177961 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.344268084 CEST49801443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.344377041 CEST49801443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.344394922 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.353684902 CEST4434979713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.353833914 CEST4434979713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.354043007 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.354043007 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.354043961 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.355618000 CEST49802443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.355638981 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.355715036 CEST49802443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.355829954 CEST49802443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.355839968 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.375104904 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.375269890 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.375329018 CEST49796443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.375350952 CEST49796443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.375365019 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.375375032 CEST49796443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.375379086 CEST4434979613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.377151012 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.377235889 CEST4434980313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.377345085 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.377424955 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.377448082 CEST4434980313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.409579992 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.409734011 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.409989119 CEST49799443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.410037994 CEST49799443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.410047054 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.410057068 CEST49799443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.410062075 CEST4434979913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.411951065 CEST49804443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.412034035 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.412138939 CEST49804443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.412239075 CEST49804443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.412261009 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.643796921 CEST49798443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.643831015 CEST4434979813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:02.659401894 CEST49797443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:02.659430981 CEST4434979713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.000854969 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.005654097 CEST49801443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.005702019 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.006098986 CEST49801443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.006113052 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.011059999 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.011706114 CEST49800443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.011766911 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.011903048 CEST49800443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.011931896 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.039052963 CEST4434980313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.062357903 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.062417030 CEST4434980313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.062716007 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.062769890 CEST4434980313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.089231968 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.104571104 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.104753017 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.104842901 CEST49801443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.110444069 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.114209890 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.114377975 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.114566088 CEST49800443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.121298075 CEST49804443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.121359110 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.121742010 CEST49804443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.121794939 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.121936083 CEST49800443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.121937037 CEST49800443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.122004032 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.122039080 CEST4434980013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.122636080 CEST49801443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.122672081 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.122699022 CEST49801443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.122715950 CEST4434980113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.123316050 CEST49802443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.123331070 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.123678923 CEST49802443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.123688936 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.128086090 CEST49805443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.128176928 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.128249884 CEST49805443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.130614042 CEST49805443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.130647898 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.136404991 CEST49806443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.136425972 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.136503935 CEST49806443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.156985998 CEST49806443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.157013893 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.160923958 CEST4434980313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.161077976 CEST4434980313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.161292076 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.161292076 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.161292076 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.163372993 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.163475990 CEST4434980713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.163805962 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.163805962 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.163934946 CEST4434980713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.223160028 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.223325014 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.223800898 CEST49804443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.223886967 CEST49804443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.223886967 CEST49804443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.223929882 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.223959923 CEST4434980413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.226274967 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.226357937 CEST4434980813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.226455927 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.226546049 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.226568937 CEST4434980813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.447875977 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:03.447962046 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:03.448051929 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:03.448498011 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:03.448592901 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:03.477097034 CEST49803443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.477161884 CEST4434980313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.508527040 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.508682013 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.509213924 CEST49802443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.509991884 CEST49802443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.510025978 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.510055065 CEST49802443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.510068893 CEST4434980213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.512625933 CEST49810443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.512662888 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.512722015 CEST49810443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.512854099 CEST49810443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.512859106 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.801522017 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.802391052 CEST49805443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.802448034 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.803112984 CEST49805443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.803126097 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.830940962 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.831290960 CEST49806443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.831321955 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.831835985 CEST49806443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.831845999 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.845936060 CEST4434980713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.846415997 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.846474886 CEST4434980713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.846631050 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.846647978 CEST4434980713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.893774986 CEST4434980813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.894555092 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.894639969 CEST4434980813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.895163059 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.895216942 CEST4434980813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.900625944 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.900777102 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.900837898 CEST49805443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.900892973 CEST49805443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.900928974 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.900954008 CEST49805443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.900970936 CEST4434980513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.903898001 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.903983116 CEST4434981113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.904082060 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.904184103 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.904205084 CEST4434981113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.947603941 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.947772980 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.947841883 CEST49806443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.947875977 CEST49806443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.947894096 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.947916985 CEST49806443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.947927952 CEST4434980613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.949924946 CEST49812443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.950009108 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.950093031 CEST49812443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.950229883 CEST49812443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.950252056 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.955583096 CEST4434980713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.955743074 CEST4434980713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.955924034 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.955924034 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.955924034 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.958158970 CEST49813443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.958193064 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.958250999 CEST49813443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.958347082 CEST49813443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.958352089 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.993699074 CEST4434980813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.993824959 CEST4434980813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.994107008 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.994107008 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.994107008 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.995642900 CEST49814443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.995651007 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:03.995716095 CEST49814443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.995837927 CEST49814443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:03.995841026 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.170578957 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.171073914 CEST49810443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.171096087 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.171364069 CEST49810443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.171369076 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.256560087 CEST49807443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.256623983 CEST4434980713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.261368990 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.261452913 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.263495922 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.263510942 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.263916016 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.272532940 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.302768946 CEST49808443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.302830935 CEST4434980813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.315406084 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.624191999 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.624375105 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.624475956 CEST49810443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.624555111 CEST49810443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.624571085 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.624612093 CEST49810443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.624618053 CEST4434981013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.627676964 CEST49815443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.627765894 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.627873898 CEST49815443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.628593922 CEST49815443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.628673077 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.630150080 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.630213976 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.630316973 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.630378008 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.630484104 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.631130934 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.631304979 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.631366014 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.631447077 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.631459951 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.631506920 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.635246992 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.635246992 CEST49809443192.168.2.44.245.163.56
                                                    Oct 3, 2024 18:17:04.635313988 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.635350943 CEST443498094.245.163.56192.168.2.4
                                                    Oct 3, 2024 18:17:04.813807964 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.814389944 CEST49814443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.814409971 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.814846992 CEST49814443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.814851046 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.816308975 CEST4434981113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.816713095 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.816795111 CEST4434981113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.817235947 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.817289114 CEST4434981113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.912542105 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.912674904 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.914319992 CEST49814443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.914472103 CEST49814443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.914486885 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.914504051 CEST49814443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.914509058 CEST4434981413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.917474031 CEST49816443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.917541027 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.917893887 CEST49816443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.918028116 CEST49816443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.918044090 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.918482065 CEST4434981113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.918637991 CEST4434981113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.920142889 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.920142889 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.920142889 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.921744108 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.921825886 CEST4434981713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:04.922065020 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.922065020 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:04.922194004 CEST4434981713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.226072073 CEST49811443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.226134062 CEST4434981113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.275944948 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.276797056 CEST49815443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.276879072 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.277321100 CEST49815443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.277374029 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.375802994 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.375965118 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.376204014 CEST49815443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.377991915 CEST49815443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.377991915 CEST49815443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.378057957 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.378089905 CEST4434981513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.381046057 CEST49818443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.381131887 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.381263018 CEST49818443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.381387949 CEST49818443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.381421089 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.584934950 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.585305929 CEST4434981713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.592573881 CEST49816443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.592609882 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.592890024 CEST49816443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.592900991 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.593106031 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.593163013 CEST4434981713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.596219063 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.596236944 CEST4434981713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.708281040 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.708440065 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.708523035 CEST49816443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.708571911 CEST49816443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.708571911 CEST49816443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.708600044 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.708621979 CEST4434981613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.709084988 CEST4434981713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.709247112 CEST4434981713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.709507942 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.709507942 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.709507942 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.711731911 CEST49819443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.711769104 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.711775064 CEST49820443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.711837053 CEST49819443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.711862087 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.711965084 CEST49819443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.711976051 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:05.711988926 CEST49820443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.712119102 CEST49820443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:05.712136984 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.019504070 CEST49817443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.019565105 CEST4434981713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.200098038 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.201030016 CEST49813443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.201056957 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.201325893 CEST49813443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.201345921 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.209481955 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.210061073 CEST49812443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.210119963 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.210184097 CEST49812443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.210199118 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.364059925 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.364214897 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.364276886 CEST49813443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.364485979 CEST49813443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.364501953 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.364510059 CEST49813443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.364515066 CEST4434981313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.367084980 CEST49821443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.367172956 CEST4434982113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.367270947 CEST49821443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.367499113 CEST49821443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.367518902 CEST4434982113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.369844913 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.369920015 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.369988918 CEST49812443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.370148897 CEST49812443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.370148897 CEST49812443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.370202065 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.370230913 CEST4434981213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.372287989 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.372370958 CEST4434982213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.372648001 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.372648001 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.372775078 CEST4434982213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.374659061 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.375763893 CEST49818443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.375818014 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.376178026 CEST49818443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.376190901 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.485877991 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.485944986 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.486452103 CEST49818443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.487066984 CEST49818443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.487066984 CEST49818443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.487132072 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.487171888 CEST4434981813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.488785028 CEST49823443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.488873005 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.488966942 CEST49823443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.489083052 CEST49823443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.489101887 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.642294884 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.642864943 CEST49820443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.642903090 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.643317938 CEST49820443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.643322945 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.645062923 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.645342112 CEST49819443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.645401001 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.645617008 CEST49819443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.645632029 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.747890949 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.748027086 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.748092890 CEST49820443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.748172998 CEST49820443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.748217106 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.748246908 CEST49820443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.748262882 CEST4434982013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.749793053 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.749938965 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.750003099 CEST49819443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.750086069 CEST49819443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.750086069 CEST49819443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.750128984 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.750154018 CEST4434981913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.751224041 CEST49824443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.751267910 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.751334906 CEST49824443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.751487017 CEST49824443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.751522064 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.752185106 CEST49825443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.752268076 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:06.752347946 CEST49825443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.752459049 CEST49825443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:06.752509117 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.010230064 CEST4434982213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.010826111 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.010885000 CEST4434982213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.011173010 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.011189938 CEST4434982213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.047445059 CEST4434982113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.048037052 CEST49821443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.048105001 CEST4434982113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.048162937 CEST49821443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.048177958 CEST4434982113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.111190081 CEST4434982213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.111345053 CEST4434982213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.111520052 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.111520052 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.111520052 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.114218950 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.114334106 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.114444971 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.114540100 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.114559889 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.138426065 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.138761044 CEST49823443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.138829947 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.139226913 CEST49823443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.139240980 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.150260925 CEST4434982113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.150414944 CEST4434982113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.150623083 CEST49821443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.150624037 CEST49821443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.151324987 CEST49821443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.151407003 CEST4434982113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.152126074 CEST49827443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.152167082 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.152245045 CEST49827443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.152348042 CEST49827443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.152359009 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.237124920 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.237281084 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.237411022 CEST49823443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.237550974 CEST49823443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.237569094 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.237616062 CEST49823443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.237627983 CEST4434982313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.239643097 CEST49828443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.239705086 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.239779949 CEST49828443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.239883900 CEST49828443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.239902973 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.412776947 CEST49822443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.412838936 CEST4434982213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.413724899 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.414664984 CEST49824443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.414747000 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.414937019 CEST49824443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.414952040 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.445004940 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.445708036 CEST49825443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.445797920 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.445967913 CEST49825443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.445982933 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.515490055 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.515647888 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.515727043 CEST49824443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.515810966 CEST49824443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.515810966 CEST49824443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.515852928 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.515877962 CEST4434982413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.518353939 CEST49829443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.518383026 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.518594980 CEST49829443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.518594980 CEST49829443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.518639088 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.551903009 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.552051067 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.552117109 CEST49825443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.552197933 CEST49825443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.552197933 CEST49825443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.552237988 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.552267075 CEST4434982513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.554219961 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.554250956 CEST4434983013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.554414988 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.554414988 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.554462910 CEST4434983013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.784540892 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.832437992 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.833547115 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.839848042 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.839899063 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.840338945 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.840390921 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.840728998 CEST49827443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.840770006 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.841329098 CEST49827443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.841336012 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.884346008 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.890156031 CEST49828443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.890233040 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.895792961 CEST49828443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.895813942 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.946368933 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.946513891 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.946573973 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.946590900 CEST49827443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.946706057 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.947002888 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.949135065 CEST49827443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.949135065 CEST49827443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.949178934 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.949204922 CEST4434982713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.952008963 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.952008963 CEST49826443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.952075005 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.952107906 CEST4434982613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.956186056 CEST49831443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.956249952 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.956331015 CEST49831443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.956995010 CEST49832443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.957042933 CEST49831443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.957072973 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.957079887 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:07.957168102 CEST49832443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.957235098 CEST49832443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:07.957256079 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.338675022 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.338826895 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.339000940 CEST49828443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.339085102 CEST49828443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.339086056 CEST49828443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.339128971 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.339157104 CEST4434982813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.341572046 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.341613054 CEST4434983313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.341690063 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.341820002 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.341825962 CEST4434983313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.458062887 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.458991051 CEST49829443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.459049940 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.459371090 CEST49829443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.459453106 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.553575039 CEST4434983013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.553952932 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.554033995 CEST4434983013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.554409981 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.554464102 CEST4434983013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.559552908 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.559714079 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.559781075 CEST49829443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.559838057 CEST49829443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.559838057 CEST49829443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.559870005 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.559895039 CEST4434982913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.561975002 CEST49834443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.562010050 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.562068939 CEST49834443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.562220097 CEST49834443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.562230110 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.637331963 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.637974977 CEST49831443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.638034105 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.638411999 CEST49831443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.638463974 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.643304110 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.643747091 CEST49832443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.643806934 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.644164085 CEST49832443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.644217968 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.652616978 CEST4434983013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.652754068 CEST4434983013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.652961969 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.652962923 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.652962923 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.655009031 CEST49835443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.655095100 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.655380011 CEST49835443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.655380011 CEST49835443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.655489922 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.738976955 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.739130974 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.739197016 CEST49831443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.739278078 CEST49831443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.739278078 CEST49831443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.739324093 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.739351034 CEST4434983113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.741611004 CEST49836443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.741692066 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.741771936 CEST49836443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.741949081 CEST49836443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.741981030 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.745330095 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.745474100 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.745541096 CEST49832443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.745620012 CEST49832443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.745620966 CEST49832443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.745661974 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.745690107 CEST4434983213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.747298002 CEST49837443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.747330904 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.747407913 CEST49837443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.747503042 CEST49837443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.747517109 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:08.958868980 CEST49830443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:08.958930969 CEST4434983013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.014852047 CEST4434983313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.031080961 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.031110048 CEST4434983313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.031537056 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.031541109 CEST4434983313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.131144047 CEST4434983313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.131299973 CEST4434983313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.131503105 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.131503105 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.131503105 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.134223938 CEST49838443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.134262085 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.134335995 CEST49838443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.134454966 CEST49838443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.134462118 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.238127947 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.238466024 CEST49834443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.238473892 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.239177942 CEST49834443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.239182949 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.339806080 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.341429949 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.341583014 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.341634989 CEST49834443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.344779968 CEST49835443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.344842911 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.345287085 CEST49835443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.345340967 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.345366001 CEST49834443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.345379114 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.345386982 CEST49834443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.345391989 CEST4434983413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.350445986 CEST49839443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.350529909 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.350606918 CEST49839443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.353718996 CEST49839443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.353795052 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.398243904 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.398672104 CEST49836443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.398747921 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.399096012 CEST49836443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.399111032 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.405926943 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.406172037 CEST49837443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.406189919 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.406485081 CEST49837443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.406491041 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.443022013 CEST49833443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.443036079 CEST4434983313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.446397066 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.446554899 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.446635962 CEST49835443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.446757078 CEST49835443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.446757078 CEST49835443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.446799994 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.446827888 CEST4434983513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.449029922 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.449110985 CEST4434984013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.449186087 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.449300051 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.449323893 CEST4434984013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.497165918 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.497322083 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.497395992 CEST49836443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.497472048 CEST49836443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.497472048 CEST49836443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.497514009 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.497545004 CEST4434983613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.499898911 CEST49841443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.499974012 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.500046015 CEST49841443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.500179052 CEST49841443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.500205040 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.506892920 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.507044077 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.507098913 CEST49837443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.507121086 CEST49837443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.507134914 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.507145882 CEST49837443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.507152081 CEST4434983713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.508853912 CEST49842443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.508877039 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.509083033 CEST49842443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.509083986 CEST49842443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.509125948 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.781640053 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.782124996 CEST49838443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.782149076 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.782628059 CEST49838443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.782634020 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.881618977 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.881769896 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.881830931 CEST49838443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.881910086 CEST49838443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.881927013 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.881936073 CEST49838443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.881942034 CEST4434983813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.884762049 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.884848118 CEST4434984313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:09.884947062 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.885106087 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:09.885126114 CEST4434984313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.006860018 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.010626078 CEST49839443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.010700941 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.011099100 CEST49839443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.011115074 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.088967085 CEST4434984013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.089633942 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.089720011 CEST4434984013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.090084076 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.090138912 CEST4434984013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.113115072 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.113274097 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.113363981 CEST49839443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.114278078 CEST49839443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.114322901 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.114351988 CEST49839443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.114367962 CEST4434983913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.116911888 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.116945028 CEST4434984413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.117146015 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.117146015 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.117204905 CEST4434984413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.173887014 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.174412966 CEST49841443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.174468040 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.174710989 CEST49841443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.174725056 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.187665939 CEST4434984013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.187799931 CEST4434984013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.187992096 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.187992096 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.187992096 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.188834906 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.189197063 CEST49842443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.189230919 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.189598083 CEST49842443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.189609051 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.221927881 CEST49845443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.222060919 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.222156048 CEST49845443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.224095106 CEST49845443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.224136114 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.277458906 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.277616024 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.277735949 CEST49841443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.292793036 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.292947054 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.293073893 CEST49842443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.306207895 CEST49841443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.306207895 CEST49841443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.306238890 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.306272030 CEST4434984113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.314949036 CEST49842443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.314960957 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.315006971 CEST49842443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.315021038 CEST4434984213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.386146069 CEST49846443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.386198997 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.386332035 CEST49846443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.412429094 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.412516117 CEST4434984713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.412563086 CEST49846443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.412606955 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.412610054 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.413666010 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.413744926 CEST4434984713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.491532087 CEST49840443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.491595984 CEST4434984013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.553687096 CEST4434984313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.554172993 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.554255009 CEST4434984313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.554500103 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.554514885 CEST4434984313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.653218985 CEST4434984313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.653395891 CEST4434984313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.653575897 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.653577089 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.653577089 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.655814886 CEST49848443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.655841112 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.655909061 CEST49848443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.656017065 CEST49848443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.656021118 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.797765017 CEST4434984413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.798398018 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.798477888 CEST4434984413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.798852921 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.798906088 CEST4434984413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.896015882 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.896555901 CEST49845443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.896606922 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.896855116 CEST49845443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.896869898 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.903932095 CEST4434984413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.904079914 CEST4434984413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.904299974 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.904299974 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.904299974 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.906862974 CEST49849443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.906950951 CEST4434984913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.907226086 CEST49849443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.907227039 CEST49849443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.907345057 CEST4434984913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:10.957160950 CEST49843443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:10.957222939 CEST4434984313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.000350952 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.000489950 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.000574112 CEST49845443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.000627041 CEST49845443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.000627041 CEST49845443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.000658035 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.000679016 CEST4434984513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.002557993 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.002640963 CEST4434985013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.002736092 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.002842903 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.002896070 CEST4434985013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.207004070 CEST49844443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.207066059 CEST4434984413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.404866934 CEST4434984713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.405574083 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.405591011 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.405673981 CEST4434984713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.405828953 CEST49846443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.405881882 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.405965090 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.406018019 CEST4434984713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.406266928 CEST49846443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.406280041 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.504916906 CEST4434984713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.505070925 CEST4434984713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.505294085 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.505294085 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.505294085 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.508135080 CEST49851443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.508167028 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.508241892 CEST49851443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.508435011 CEST49851443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.508443117 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.510802984 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.510950089 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.511013031 CEST49846443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.511069059 CEST49846443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.511069059 CEST49846443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.511096001 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.511120081 CEST4434984613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.512876034 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.512908936 CEST4434985213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.512969971 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.513072968 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.513077974 CEST4434985213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.596575022 CEST4434984913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.596982956 CEST49849443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.597019911 CEST4434984913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.597501040 CEST49849443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.597507954 CEST4434984913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.604317904 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.604571104 CEST49848443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.604588032 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.604876041 CEST49848443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.604881048 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.645417929 CEST4434985013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.645921946 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.645953894 CEST4434985013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.646070957 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.646080017 CEST4434985013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.700457096 CEST4434984913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.700613022 CEST4434984913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.700795889 CEST49849443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.700795889 CEST49849443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.701273918 CEST49849443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.701335907 CEST4434984913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.702601910 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.702687025 CEST4434985313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.702795982 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.702904940 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.702930927 CEST4434985313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.710587978 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.710737944 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.710804939 CEST49848443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.710827112 CEST49848443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.710839033 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.710865974 CEST49848443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.710870981 CEST4434984813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.712677956 CEST49854443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.712762117 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.712847948 CEST49854443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.712960005 CEST49854443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.712980986 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.744318008 CEST4434985013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.744461060 CEST4434985013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.744628906 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.744628906 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.744628906 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.746162891 CEST49855443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.746192932 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.746257067 CEST49855443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.746351957 CEST49855443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.746357918 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.816318035 CEST49847443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.816359043 CEST4434984713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:11.972673893 CEST49850443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:11.972703934 CEST4434985013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.149599075 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.150116920 CEST49851443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.150140047 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.150561094 CEST49851443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.150566101 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.166985989 CEST4434985213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.167289019 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.167311907 CEST4434985213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.167617083 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.167620897 CEST4434985213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.248533964 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.248689890 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.248754978 CEST49851443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.248820066 CEST49851443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.248836040 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.248845100 CEST49851443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.248850107 CEST4434985113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.251693964 CEST49857443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.251776934 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.252075911 CEST49857443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.252077103 CEST49857443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.252192020 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.267608881 CEST4434985213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.267782927 CEST4434985213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.267893076 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.267893076 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.267893076 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.270066977 CEST49858443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.270148039 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.270251036 CEST49858443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.270353079 CEST49858443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.270378113 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.369158030 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.369657993 CEST49854443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.369716883 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.370043039 CEST49854443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.370096922 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.398058891 CEST4434985313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.398489952 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.398549080 CEST4434985313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.398735046 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.398750067 CEST4434985313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.402311087 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.402710915 CEST49855443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.402730942 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.403045893 CEST49855443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.403052092 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.472481012 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.472553968 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.472626925 CEST49854443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.479300022 CEST49854443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.479300022 CEST49854443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.479366064 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.479401112 CEST4434985413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.481942892 CEST49859443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.481987953 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.482055902 CEST49859443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.482196093 CEST49859443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.482209921 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.501848936 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.502016068 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.502077103 CEST49855443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.502132893 CEST49855443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.502151012 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.502163887 CEST49855443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.502170086 CEST4434985513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.504429102 CEST49860443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.504451990 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.504508018 CEST49860443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.504657984 CEST49860443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.504663944 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.505889893 CEST4434985313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.506042957 CEST4434985313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.506241083 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.506241083 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.506241083 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.508287907 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.508374929 CEST4434986113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.508481026 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.508563042 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.508585930 CEST4434986113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.581923008 CEST49852443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.581933975 CEST4434985213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.722723961 CEST49853443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.722784996 CEST4434985313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.893121958 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.901772976 CEST49857443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.901855946 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.902232885 CEST49857443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.902287006 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.909873009 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.910871029 CEST49858443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.910948038 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.911381006 CEST49858443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.911412954 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.997898102 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.998040915 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.998094082 CEST49857443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.998229980 CEST49857443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.998245001 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:12.998256922 CEST49857443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:12.998264074 CEST4434985713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.001363993 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.001447916 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.001538992 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.001683950 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.001719952 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.011749983 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.011893034 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.011955023 CEST49858443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.011970043 CEST49858443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.011976004 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.012006998 CEST49858443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.012012005 CEST4434985813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.014079094 CEST49863443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.014127016 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.014173985 CEST49863443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.014332056 CEST49863443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.014353037 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.104760885 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.105144024 CEST49860443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.105163097 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.105521917 CEST49860443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.105526924 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.135018110 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.135449886 CEST49859443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.135461092 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.135912895 CEST49859443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.135919094 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.159415960 CEST4434986113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.159807920 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.159866095 CEST4434986113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.160130024 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.160182953 CEST4434986113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.212063074 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.212214947 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.212287903 CEST49860443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.212308884 CEST49860443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.212320089 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.212330103 CEST49860443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.212336063 CEST4434986013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.214425087 CEST49864443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.214508057 CEST4434986413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.214620113 CEST49864443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.214699984 CEST49864443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.214719057 CEST4434986413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.259912014 CEST4434986113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.260066032 CEST4434986113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.260266066 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.260266066 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.260266066 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.262697935 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.262795925 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.262888908 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.263005972 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.263025045 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.566226006 CEST49861443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.566287994 CEST4434986113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.577423096 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.579700947 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.579793930 CEST49859443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.579844952 CEST49859443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.579874992 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.579902887 CEST49859443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.579909086 CEST4434985913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.582679033 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.582775116 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.582855940 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.582987070 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.583008051 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.642184973 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.642728090 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.642811060 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.643030882 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.643044949 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.683815956 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.684161901 CEST49863443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.684191942 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.684504986 CEST49863443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.684510946 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.741580009 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.741641045 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.741772890 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.742003918 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.742132902 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.742134094 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.742134094 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.744278908 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.744364023 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.744601965 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.744602919 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.744728088 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.786813021 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.786964893 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.787149906 CEST49863443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.787190914 CEST49863443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.787211895 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.787224054 CEST49863443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.787231922 CEST4434986313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.789275885 CEST49868443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.789359093 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.789575100 CEST49868443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.789575100 CEST49868443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.789694071 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.856424093 CEST4434986413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.856796980 CEST49864443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.856877089 CEST4434986413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.857330084 CEST49864443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.857345104 CEST4434986413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.906212091 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.906507969 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.906569004 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.906956911 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.906970024 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.954896927 CEST4434986413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.955059052 CEST4434986413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.955154896 CEST49864443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.955156088 CEST49864443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.955233097 CEST49864443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.955269098 CEST4434986413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.957957029 CEST49869443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.958004951 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:13.958080053 CEST49869443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.958213091 CEST49869443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:13.958220959 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.046753883 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.046808958 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.046941042 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.046961069 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.047120094 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.047173977 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.047214985 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.047246933 CEST49865443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.047261953 CEST4434986513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.049448013 CEST49870443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.049487114 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.049557924 CEST49870443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.049669981 CEST49870443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.049678087 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.050483942 CEST49862443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.050544977 CEST4434986213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.238293886 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.238713026 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.238785982 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.239258051 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.239273071 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.338834047 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.338891029 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.339011908 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.339122057 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.339360952 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.339360952 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.341159105 CEST49866443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.341200113 CEST4434986613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.342489004 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.342575073 CEST4434987113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.342798948 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.342907906 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.342937946 CEST4434987113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.418606043 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.419478893 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.419537067 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.420075893 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.420092106 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.430126905 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.430706978 CEST49868443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.430763960 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.431214094 CEST49868443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.431227922 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.832767010 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.832839012 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.832900047 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.832973003 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.833009005 CEST49868443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.833095074 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.833169937 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.833169937 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.833323002 CEST49868443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.833323002 CEST49868443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.833365917 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.833395958 CEST4434986813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.833535910 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.833535910 CEST49867443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.833600998 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.833636999 CEST4434986713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.838753939 CEST49872443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.838839054 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.838978052 CEST49872443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.839024067 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.839255095 CEST49873443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.839302063 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.839302063 CEST49872443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.839337111 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.839353085 CEST49873443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.839519024 CEST49873443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.839536905 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.839811087 CEST49869443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.839839935 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.840249062 CEST49869443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.840255022 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.948966026 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.949120045 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.949179888 CEST49869443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.949268103 CEST49869443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.949280024 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.949300051 CEST49869443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.949305058 CEST4434986913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.952178955 CEST49874443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.952224970 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:14.952303886 CEST49874443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.952467918 CEST49874443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:14.952478886 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.026055098 CEST4434987113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.026581049 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.026659012 CEST4434987113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.027020931 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.027035952 CEST4434987113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.030150890 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.030455112 CEST49870443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.030479908 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.030797958 CEST49870443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.030802011 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.124214888 CEST4434987113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.124953985 CEST4434987113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.125190020 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.125190973 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.125190973 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.127242088 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.127434969 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.127513885 CEST49870443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.128196001 CEST49875443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.128282070 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.128313065 CEST49870443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.128313065 CEST49870443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.128365993 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.128388882 CEST4434987013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.128408909 CEST49875443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.131242037 CEST49875443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.131278038 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.132484913 CEST49876443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.132549047 CEST4434987613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.132616997 CEST49876443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.132720947 CEST49876443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.132740974 CEST4434987613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.426192999 CEST49871443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.426255941 CEST4434987113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.510138035 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.513887882 CEST49873443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.513921022 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.514322042 CEST49873443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.514328003 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.597326994 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.597959042 CEST49874443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.597970963 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.598341942 CEST49874443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.598346949 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.613845110 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.613996983 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.614080906 CEST49873443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.614161015 CEST49873443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.614180088 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.614217997 CEST49873443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.614226103 CEST4434987313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.618293047 CEST49877443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.618343115 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.618418932 CEST49877443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.618568897 CEST49877443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.618580103 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.696933985 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.697088957 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.697153091 CEST49874443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.697218895 CEST49874443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.697227001 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.697247028 CEST49874443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.697252035 CEST4434987413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.699573994 CEST49878443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.699589014 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.699662924 CEST49878443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.699827909 CEST49878443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.699832916 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.788995028 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.789594889 CEST49875443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.789685011 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.790189028 CEST49875443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.790241957 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.828903913 CEST4434987613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.829735041 CEST49876443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.829816103 CEST4434987613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.830355883 CEST49876443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.830410957 CEST4434987613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.891064882 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.891163111 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.891236067 CEST49875443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.891320944 CEST49875443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.891364098 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.891398907 CEST49875443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.891415119 CEST4434987513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.894248962 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.894284010 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.894345045 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.894458055 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.894465923 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.948488951 CEST4434987613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.948640108 CEST4434987613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.948813915 CEST49876443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.948813915 CEST49876443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.949148893 CEST49876443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.949209929 CEST4434987613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.953665972 CEST49880443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.953754902 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:15.953840971 CEST49880443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.954108953 CEST49880443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:15.954129934 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.308366060 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.308917046 CEST49877443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.308938980 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.309268951 CEST49877443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.309274912 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.387717962 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.388181925 CEST49878443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.388196945 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.388586998 CEST49878443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.388592005 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.412604094 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.412760019 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.412822008 CEST49877443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.413007975 CEST49877443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.413007975 CEST49877443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.413024902 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.413034916 CEST4434987713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.415648937 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.415734053 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.415828943 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.415952921 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.415972948 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.492011070 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.492139101 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.492222071 CEST49878443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.492273092 CEST49878443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.492281914 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.492290974 CEST49878443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.492297888 CEST4434987813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.494301081 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.494385004 CEST4434988213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.494493008 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.494575024 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.494596958 CEST4434988213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.524729013 CEST49883443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:17:16.524812937 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:16.525139093 CEST49883443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:17:16.525140047 CEST49883443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:17:16.525274038 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:16.586534977 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.586958885 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.587028980 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.587158918 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.587173939 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.602669001 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.602968931 CEST49880443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.602998018 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.603313923 CEST49880443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.603326082 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.687819958 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.687891006 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.687992096 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.688046932 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.688185930 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.688185930 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.688185930 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.690499067 CEST49884443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.690593004 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.690687895 CEST49884443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.690807104 CEST49884443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.690829992 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.703442097 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.703593969 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.703655005 CEST49880443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.703711987 CEST49880443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.703711987 CEST49880443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.703738928 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.703763962 CEST4434988013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.705677032 CEST49885443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.705761909 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.705845118 CEST49885443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.705961943 CEST49885443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.705996990 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:16.988454103 CEST49879443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:16.988516092 CEST4434987913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.059289932 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.059942007 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.060018063 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.060317039 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.060329914 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.142101049 CEST4434988213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.142481089 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.142560959 CEST4434988213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.142808914 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.142822981 CEST4434988213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.163502932 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.163803101 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.163873911 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.163979053 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.163979053 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.163979053 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.163979053 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.166529894 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.166613102 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.166712999 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.166829109 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.166851997 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.169109106 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:17.169352055 CEST49883443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:17:17.169369936 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:17.170042992 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:17.170336962 CEST49883443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:17:17.170420885 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:17.222548962 CEST49883443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:17:17.242791891 CEST4434988213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.243102074 CEST4434988213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.243468046 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.243468046 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.243468046 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.245430946 CEST49887443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.245516062 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.245620012 CEST49887443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.245721102 CEST49887443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.245743036 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.351881027 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.352344036 CEST49884443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.352422953 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.352963924 CEST49884443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.352978945 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.378597975 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.378912926 CEST49885443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.378963947 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.379244089 CEST49885443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.379256964 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.451030016 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.451186895 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.451252937 CEST49884443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.451329947 CEST49884443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.451366901 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.451419115 CEST49884443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.451435089 CEST4434988413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.454440117 CEST49888443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.454483032 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.454555035 CEST49888443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.454719067 CEST49888443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.454731941 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.472342014 CEST49881443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.472404003 CEST4434988113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.481427908 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.482099056 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.482276917 CEST49885443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.482350111 CEST49885443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.482351065 CEST49885443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.482391119 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.482426882 CEST4434988513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.484460115 CEST49889443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.484540939 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.484637022 CEST49889443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.484729052 CEST49889443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.484747887 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.550435066 CEST49882443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.550496101 CEST4434988213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.837192059 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.840229034 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.840286970 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.843322039 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.843374968 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.898462057 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.900718927 CEST49887443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.900794029 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.901081085 CEST49887443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.901093960 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.952900887 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.952970982 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.953068018 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.953169107 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.953169107 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.953257084 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.953257084 CEST49886443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.953295946 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.953326941 CEST4434988613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.956142902 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.956226110 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.956317902 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.956423044 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:17.956444979 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.999746084 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.999908924 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:17.999970913 CEST49887443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.000035048 CEST49887443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.000035048 CEST49887443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.000087023 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.000108004 CEST4434988713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.002127886 CEST49891443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.002176046 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.002248049 CEST49891443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.002345085 CEST49891443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.002357960 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.149867058 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.150711060 CEST49888443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.150772095 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.151032925 CEST49888443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.151050091 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.163609028 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.164105892 CEST49889443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.164161921 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.164427042 CEST49889443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.164441109 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.254898071 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.255054951 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.255131960 CEST49888443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.255340099 CEST49888443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.255398989 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.255435944 CEST49888443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.255451918 CEST4434988813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.258408070 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.258496046 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.258580923 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.258719921 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.258738995 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.271559000 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.271714926 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.271959066 CEST49889443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.272072077 CEST49889443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.272110939 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.272170067 CEST49889443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.272186041 CEST4434988913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.274485111 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.274568081 CEST4434989313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.274682045 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.274801970 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.274825096 CEST4434989313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.964700937 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.965270042 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.965347052 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.965466022 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.965697050 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.965712070 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.965771914 CEST49891443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.965847015 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:18.966140032 CEST49891443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:18.966152906 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.066629887 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.066706896 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.066773891 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.066800117 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.066829920 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.066879988 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.067892075 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.067925930 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.067955017 CEST49890443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.067969084 CEST4434989013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.068332911 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.068464041 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.068525076 CEST49891443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.069097042 CEST49891443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.069097042 CEST49891443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.069139957 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.069169998 CEST4434989113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.072962999 CEST49894443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.073045015 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.073144913 CEST49894443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.073642969 CEST49895443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.073738098 CEST4434989513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.073761940 CEST49894443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.073797941 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.073820114 CEST49895443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.073885918 CEST49895443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.073909044 CEST4434989513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.185355902 CEST4434989313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.185834885 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.185856104 CEST4434989313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.186268091 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.186283112 CEST4434989313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.293174982 CEST4434989313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.293325901 CEST4434989313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.293514013 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.293514013 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.293514013 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.296133995 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.296219110 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.296329975 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.296663046 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.296721935 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.597886086 CEST49893443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.597948074 CEST4434989313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.618094921 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.618908882 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.618988037 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.619338036 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.619352102 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.718919992 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.718995094 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.719094038 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.719166994 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.719264030 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.719698906 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.719739914 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.719769001 CEST49892443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.719784975 CEST4434989213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.722414017 CEST49897443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.722460032 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.722546101 CEST49897443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.722912073 CEST49897443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.722929001 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.794111013 CEST4434989513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.794822931 CEST49895443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.794864893 CEST4434989513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.795192003 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.795440912 CEST49895443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.795454025 CEST4434989513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.795475960 CEST49894443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.795552969 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.795906067 CEST49894443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.795918941 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.892613888 CEST4434989513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.892765999 CEST4434989513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.892885923 CEST49895443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.893630028 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.893809080 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.893862963 CEST49894443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.894524097 CEST49895443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.894542933 CEST4434989513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.898169041 CEST49894443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.898169041 CEST49894443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.898211002 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.898237944 CEST4434989413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.907233000 CEST49898443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.907258034 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.907310963 CEST49898443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.908128023 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.908212900 CEST4434989913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.908294916 CEST49898443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.908298969 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.908310890 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.908708096 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.908786058 CEST4434989913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.958982944 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.972913027 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.975224018 CEST49872443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.975306988 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.975713015 CEST49872443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.975765944 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.975986958 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.976069927 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:19.976353884 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:19.976407051 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.083992958 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.084073067 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.084176064 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.084287882 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.084287882 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.090150118 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.090151072 CEST49896443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.090217113 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.090265036 CEST4434989613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.092746973 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.092829943 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.092931986 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.093053102 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.093076944 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.099086046 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.099236965 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.099322081 CEST49872443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.119343996 CEST49872443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.119343996 CEST49872443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.119410038 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.119446039 CEST4434987213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.122128010 CEST49901443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.122174025 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.122237921 CEST49901443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.122374058 CEST49901443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.122384071 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.384533882 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.385092974 CEST49897443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.385116100 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.385576010 CEST49897443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.385581970 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.484612942 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.484782934 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.484831095 CEST49897443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.484956026 CEST49897443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.484971046 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.484980106 CEST49897443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.484985113 CEST4434989713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.487651110 CEST49902443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.487682104 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.487754107 CEST49902443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.487879038 CEST49902443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.487891912 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.549696922 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.550506115 CEST49898443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.550525904 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.550924063 CEST49898443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.550928116 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.563534021 CEST4434989913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.564275026 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.564333916 CEST4434989913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.564456940 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.564482927 CEST4434989913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.647430897 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.647696018 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.647808075 CEST49898443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.648096085 CEST49898443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.648106098 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.648122072 CEST49898443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.648127079 CEST4434989813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.650410891 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.650496006 CEST4434990313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.650796890 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.650798082 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.650927067 CEST4434990313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.678678989 CEST4434989913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.681585073 CEST4434989913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.681850910 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.681850910 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.681850910 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.683686018 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.683768988 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.683860064 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.684111118 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.684191942 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.760818005 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.761147022 CEST49901443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.761158943 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.761532068 CEST49901443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.761535883 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.762130022 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.762550116 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.762609005 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.762702942 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.762718916 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.863349915 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.863554001 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.863697052 CEST49901443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.864397049 CEST49901443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.864397049 CEST49901443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.864408970 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.864414930 CEST4434990113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.866878033 CEST49905443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.866970062 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.867270947 CEST49905443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.867271900 CEST49905443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.867412090 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.867419958 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.867448092 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.867496014 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.867624044 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.867624044 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.867711067 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.867711067 CEST49900443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.867750883 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.867784023 CEST4434990013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.869776011 CEST49906443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.869858980 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.869952917 CEST49906443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.870090008 CEST49906443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.870107889 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:20.910306931 CEST49899443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:20.910367966 CEST4434989913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.148787975 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.149312019 CEST49902443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.149322987 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.149736881 CEST49902443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.149740934 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.248323917 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.248486996 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.248553038 CEST49902443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.248653889 CEST49902443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.248666048 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.248673916 CEST49902443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.248680115 CEST4434990213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.251207113 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.251291037 CEST4434990713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.251403093 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.251488924 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.251513004 CEST4434990713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.331243038 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.332267046 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.332324982 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.332643986 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.332698107 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.339827061 CEST4434990313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.340486050 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.340547085 CEST4434990313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:21.340847969 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:21.340903044 CEST4434990313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.416496992 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.416524887 CEST4434990313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.416579962 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.416733027 CEST4434990313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.416760921 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.416791916 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.416862965 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.416928053 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.416928053 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.416934013 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.416928053 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.416934013 CEST49904443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.416979074 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.417010069 CEST4434990413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.419609070 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.419639111 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.419656038 CEST4434990813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.419729948 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.419790030 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.419883013 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.419898987 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.419917107 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.419949055 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.419965029 CEST4434990813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.421895981 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.422228098 CEST49906443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.422275066 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.422599077 CEST49906443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.422610998 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.426342964 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.426728010 CEST49905443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.426759005 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.427078009 CEST49905443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.427088976 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.524422884 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.524589062 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.524705887 CEST49906443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.525504112 CEST49906443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.525547981 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.525576115 CEST49906443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.525590897 CEST4434990613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.528749943 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.528800011 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.528891087 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.529009104 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.529020071 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.544183016 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.544868946 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.544949055 CEST49905443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.544986010 CEST49905443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.544986010 CEST49905443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.545002937 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.545021057 CEST4434990513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.546778917 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.546822071 CEST4434991113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.547035933 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.547035933 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.547100067 CEST4434991113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.617816925 CEST4434990713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.618314981 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.618396044 CEST4434990713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.618716955 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.618771076 CEST4434990713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.720890999 CEST4434990713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.721097946 CEST4434990713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.721297979 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.721298933 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.721298933 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.722434998 CEST49903443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.722497940 CEST4434990313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.724196911 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.724224091 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:22.724289894 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.724436045 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:22.724440098 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.034976959 CEST49907443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.035038948 CEST4434990713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.065721035 CEST4434990813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.066520929 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.066562891 CEST4434990813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.066926003 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.066952944 CEST4434990813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.088263988 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.088738918 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.088810921 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.089085102 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.089097977 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.164453030 CEST4434990813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.164696932 CEST4434990813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.164897919 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.164899111 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.164899111 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.168112993 CEST49913443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.168198109 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.168500900 CEST49913443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.168502092 CEST49913443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.168628931 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.175950050 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.176239014 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.176312923 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.176574945 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.176589012 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.185168028 CEST4434991113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.185601950 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.185642004 CEST4434991113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.185919046 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.185945988 CEST4434991113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.190260887 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.190423012 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.190485001 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.190505028 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.190534115 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.190593958 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.191060066 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.191093922 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.191121101 CEST49909443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.191134930 CEST4434990913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.193413973 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.193497896 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.193589926 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.193850994 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.193909883 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.275543928 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.275613070 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.275727034 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.275759935 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.275816917 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.276004076 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.276050091 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.276170015 CEST49910443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.276185989 CEST4434991013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.278642893 CEST49915443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.278680086 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.278755903 CEST49915443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.278913021 CEST49915443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.278918982 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.285785913 CEST4434991113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.285868883 CEST4434991113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.286016941 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.286016941 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.286016941 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.287869930 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.287909031 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.287985086 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.288100004 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.288106918 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.366650105 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.367010117 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.367032051 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.367376089 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.367381096 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.471925974 CEST49908443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.471957922 CEST4434990813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.582062006 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.582096100 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.582139015 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.582140923 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.582180023 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.582581043 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.582592010 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.582604885 CEST49912443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.582611084 CEST4434991213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.585710049 CEST49917443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.585752964 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.585992098 CEST49917443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.588140011 CEST49917443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.588221073 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.596788883 CEST49911443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.596811056 CEST4434991113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.815186024 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.815723896 CEST49913443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.815798998 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.816250086 CEST49913443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.816303968 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.847979069 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.848453045 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.848511934 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.848643064 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.848658085 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.914628983 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.915354967 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.915441036 CEST49913443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.915518045 CEST49913443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.915518045 CEST49913443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.915560007 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.915606976 CEST4434991313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.918628931 CEST49919443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.918658018 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.918720007 CEST49919443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.918874979 CEST49919443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.918880939 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.923540115 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.923964977 CEST49915443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.923996925 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.924418926 CEST49915443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.924424887 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.950213909 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.950284958 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.950403929 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.950496912 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.950498104 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.950587034 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.950587034 CEST49914443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.950627089 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.950658083 CEST4434991413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.953178883 CEST49920443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.953262091 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.953325987 CEST49920443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.953455925 CEST49920443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.953475952 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.955456972 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.955859900 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.955868006 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:23.956401110 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:23.956410885 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.174293041 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.174443007 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.174499989 CEST49915443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.174587011 CEST49915443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.174602032 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.174616098 CEST49915443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.174622059 CEST4434991513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.177923918 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.177943945 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.177999973 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.178220034 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.178225994 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.267031908 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.267107010 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.267178059 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.267190933 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.267220020 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.267267942 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.267364979 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.267380953 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.267393112 CEST49916443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.267396927 CEST4434991613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.270349979 CEST49922443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.270381927 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.270453930 CEST49922443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.270643950 CEST49922443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.270653009 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.358366013 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.358928919 CEST49917443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.358987093 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.359498978 CEST49917443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.359551907 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.458646059 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.458813906 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.458895922 CEST49917443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.458950996 CEST49917443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.458950996 CEST49917443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.458981991 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.459006071 CEST4434991713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.461361885 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.461447001 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.461541891 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.461664915 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.461684942 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.614278078 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.642816067 CEST49919443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.642833948 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.643718958 CEST49919443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.643723011 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.743113041 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.743684053 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.743758917 CEST49919443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.768572092 CEST49919443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.768594027 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.768630028 CEST49919443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.768635988 CEST4434991913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.807673931 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.817945957 CEST49920443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.818032026 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.821851015 CEST49920443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.821903944 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.821909904 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.825547934 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.825561047 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.826141119 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.826145887 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.837497950 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.841511011 CEST49922443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.841519117 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.842061996 CEST49922443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.842067003 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.863935947 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.864018917 CEST4434992413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.864346027 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.864346027 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.864473104 CEST4434992413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.917306900 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.917509079 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.917742968 CEST49920443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.926939011 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.927014112 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.927099943 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.927117109 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.927138090 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.928235054 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.945290089 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.945287943 CEST49920443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.945287943 CEST49920443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.945323944 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.945342064 CEST49921443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.945348978 CEST4434992113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.945354939 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.945389986 CEST4434992013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.948091984 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.948163986 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.948215961 CEST49922443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.948419094 CEST49922443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.948426008 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.948446989 CEST49922443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.948451042 CEST4434992213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.948857069 CEST49925443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.948896885 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.948947906 CEST49925443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.950270891 CEST49926443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.950278044 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.950438023 CEST49926443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.950468063 CEST49925443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.950479031 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.950918913 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.951003075 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.951049089 CEST49926443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.951060057 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:24.951098919 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.951220989 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:24.951245070 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.134880066 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.135503054 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.135561943 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.135993958 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.136049032 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.235313892 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.235879898 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.236042023 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.236224890 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.236226082 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.236226082 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.238717079 CEST49928443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.238805056 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.239346027 CEST49928443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.239707947 CEST49928443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.239743948 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.516880035 CEST4434992413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.517843962 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.517927885 CEST4434992413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.518403053 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.518455982 CEST4434992413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.550544024 CEST49923443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.550606966 CEST4434992313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.591056108 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.591506958 CEST49925443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.591523886 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.592078924 CEST49925443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.592084885 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.598922014 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.600604057 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.600684881 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.600955963 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.601011038 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.626513004 CEST4434992413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.626621008 CEST4434992413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.626972914 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.626972914 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.626972914 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.629966974 CEST49931443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.630018950 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.630076885 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.630089045 CEST49931443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.630337954 CEST49931443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.630351067 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.630848885 CEST49926443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.630863905 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.631433964 CEST49926443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.631438971 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.690768003 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.690923929 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.691003084 CEST49925443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.691126108 CEST49925443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.691139936 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.691157103 CEST49925443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.691164017 CEST4434992513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.693844080 CEST49932443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.693929911 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.694003105 CEST49932443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.694180012 CEST49932443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.694202900 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.700081110 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.700149059 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.700251102 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.700349092 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.700349092 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.700436115 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.700436115 CEST49927443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.700478077 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.700511932 CEST4434992713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.702143908 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.702229977 CEST4434993313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.703821898 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.703924894 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.703944921 CEST4434993313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.740935087 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.741022110 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.741136074 CEST49926443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.741161108 CEST49926443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.741170883 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.741183996 CEST49926443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.741189957 CEST4434992613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.743299007 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.743381977 CEST4434993413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.743484020 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.743592024 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.743613958 CEST4434993413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.881033897 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.881591082 CEST49928443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.881669998 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.882107019 CEST49928443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.882119894 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.930577993 CEST49924443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.930640936 CEST4434992413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.985011101 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.985826969 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.985907078 CEST49928443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.985971928 CEST49928443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.985971928 CEST49928443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.986010075 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.986032009 CEST4434992813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.989435911 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.989490032 CEST4434993513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:25.989557981 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.989691019 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:25.989706039 CEST4434993513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.287154913 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.293201923 CEST49931443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.293201923 CEST49931443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.293263912 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.293307066 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.337649107 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.339412928 CEST49932443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.339471102 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.340004921 CEST49932443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.340018034 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.347454071 CEST4434993313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.349507093 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.349565983 CEST4434993313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.350035906 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.350089073 CEST4434993313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.389404058 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.389483929 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.389600039 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.389684916 CEST49931443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.389837027 CEST49931443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.389837027 CEST49931443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.389872074 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.389894009 CEST4434993113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.392911911 CEST49936443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.392946959 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.393027067 CEST49936443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.393167973 CEST49936443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.393173933 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.419996023 CEST4434993413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.420562029 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.420620918 CEST4434993413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.421092033 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.421144962 CEST4434993413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.435806036 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.435969114 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.436038017 CEST49932443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.436358929 CEST49932443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.436358929 CEST49932443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.436392069 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.436414003 CEST4434993213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.439114094 CEST49937443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.439198017 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.439295053 CEST49937443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.439450026 CEST49937443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.439470053 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.447653055 CEST4434993313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.447808027 CEST4434993313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.448029041 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.448029041 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.448029041 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.450325966 CEST49938443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.450408936 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.450503111 CEST49938443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.450628042 CEST49938443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.450648069 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.551903009 CEST4434993413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.552731037 CEST4434993413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.553009033 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.553009033 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.553009033 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.554881096 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.554908037 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.555088997 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.555088997 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.555121899 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.567047119 CEST4434993513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.568339109 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.568417072 CEST4434993513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.568964958 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.568978071 CEST4434993513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.675647020 CEST4434993513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.676265955 CEST4434993513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.676453114 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.676453114 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.676453114 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.678643942 CEST49940443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.678680897 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.678740025 CEST49940443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.678877115 CEST49940443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.678881884 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.753317118 CEST49933443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.753381014 CEST4434993313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.866132021 CEST49934443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.866194963 CEST4434993413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:26.990567923 CEST49935443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:26.990618944 CEST4434993513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.065076113 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.065573931 CEST49936443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.065597057 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.067315102 CEST49936443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.067321062 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.075284004 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:27.075468063 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:27.075690031 CEST49883443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:17:27.138717890 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.139233112 CEST49937443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.139292955 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.139659882 CEST49937443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.139713049 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.146924973 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.147239923 CEST49938443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.147260904 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.147710085 CEST49938443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.147762060 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.164264917 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.164789915 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.164855003 CEST49936443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.164892912 CEST49936443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.164910078 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.164921045 CEST49936443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.164930105 CEST4434993613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.167505026 CEST49941443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.167593002 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.167697906 CEST49941443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.168057919 CEST49941443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.168117046 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.196768045 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.197105885 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.197118044 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.197479963 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.197485924 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.243887901 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.244065046 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.244133949 CEST49937443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.244236946 CEST49937443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.244236946 CEST49937443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.244280100 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.244306087 CEST4434993713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.248785973 CEST49942443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.248869896 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.248996973 CEST49942443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.249347925 CEST49942443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.249428988 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.256820917 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.256975889 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.257148027 CEST49938443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.270503044 CEST49938443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.270503044 CEST49938443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.270566940 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.270602942 CEST4434993813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.273586035 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.273654938 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.273722887 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.273859978 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.273866892 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.515338898 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.515465975 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.515547991 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.515567064 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.515587091 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.515639067 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.515753031 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.515763998 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.515778065 CEST49939443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.515784025 CEST4434993913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.521428108 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.530205965 CEST49940443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.530225992 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.530632019 CEST49940443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.530636072 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.532100916 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.532185078 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.532265902 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.532388926 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.532419920 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.632091999 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.632293940 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.632349014 CEST49940443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.632384062 CEST49940443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.632395029 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.632402897 CEST49940443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.632406950 CEST4434994013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.635119915 CEST49945443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.635188103 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:27.635270119 CEST49945443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.635433912 CEST49945443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:27.635449886 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.059782982 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.059802055 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.060446978 CEST49941443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.060534000 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.060568094 CEST49942443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.060599089 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.060973883 CEST49941443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.060992002 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.061115980 CEST49942443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.061125994 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.158376932 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.158598900 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.158670902 CEST49942443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.158746958 CEST49942443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.158747911 CEST49942443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.158791065 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.158821106 CEST4434994213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.162026882 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.162178040 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.162305117 CEST49941443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.163451910 CEST49941443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.163453102 CEST49941443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.163535118 CEST49946443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.163547039 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.163582087 CEST4434994113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.163626909 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.163702965 CEST49946443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.163840055 CEST49946443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.163858891 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.165958881 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.166044950 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.166135073 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.166284084 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.166310072 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.242885113 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.243360996 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.243447065 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.243834972 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.243887901 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.249452114 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.249785900 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.249805927 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.250276089 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.250281096 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.288713932 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.289180040 CEST49945443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.289251089 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.289613962 CEST49945443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.289628983 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.341594934 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.341691017 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.341773033 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.341799021 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.341854095 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.341905117 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.341905117 CEST49944443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.341947079 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.341978073 CEST4434994413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.344152927 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.344238043 CEST4434994813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.344336987 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.344444036 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.344465017 CEST4434994813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.352941036 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.352996111 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.353053093 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.353075027 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.353132963 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.353173971 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.353246927 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.353264093 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.353276014 CEST49943443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.353280067 CEST4434994313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.355917931 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.356023073 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.356112957 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.359206915 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.359247923 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.389255047 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.389327049 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.389441967 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.389499903 CEST49945443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.389549017 CEST49945443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.389549017 CEST49945443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.389592886 CEST4434994513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.392087936 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.392122984 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.392215014 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.392369986 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.392383099 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.968516111 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.969048977 CEST49946443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.969142914 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.969465017 CEST49946443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.969479084 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.973746061 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.974212885 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.974294901 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.974600077 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.974653006 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.988559008 CEST4434994813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.988972902 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.989053965 CEST4434994813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:28.989322901 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:28.989376068 CEST4434994813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.024163961 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.024499893 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.024591923 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.024920940 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.024934053 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.045495987 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.046084881 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.046122074 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.046439886 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.046449900 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.077119112 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.077198982 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.077295065 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.077416897 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.077416897 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.077503920 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.077503920 CEST49947443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.077543974 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.077574968 CEST4434994713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.080521107 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.080604076 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.080954075 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.080955029 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.081063986 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.088331938 CEST4434994813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.088496923 CEST4434994813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.088685989 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.088685989 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.088685989 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.090459108 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.090512991 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.090595007 CEST4434995213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.090637922 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.090692997 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.090697050 CEST49946443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.090761900 CEST49946443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.090761900 CEST49946443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.090801954 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.090816975 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.090825081 CEST4434994613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.090841055 CEST4434995213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.092515945 CEST49953443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.092576027 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.092658043 CEST49953443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.092782021 CEST49953443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.092806101 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.124623060 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.124679089 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.124809980 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.124830008 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.124876022 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.124912977 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.124936104 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.124960899 CEST49949443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.124973059 CEST4434994913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.126605988 CEST49954443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.126626015 CEST4434995413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.126703978 CEST49954443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.126817942 CEST49954443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.126840115 CEST4434995413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.146899939 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.146971941 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.147034883 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.147094011 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.147252083 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.147252083 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.147252083 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.147275925 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.149005890 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.149091005 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.149182081 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.149307013 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.149327993 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.393986940 CEST49948443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.394049883 CEST4434994813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.456269026 CEST49950443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.456341028 CEST4434995013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.733836889 CEST4434995213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.734499931 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.734581947 CEST4434995213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.734982014 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.735034943 CEST4434995213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.746676922 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.747114897 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.747174025 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.747447968 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.747467041 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.760761976 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.761105061 CEST49953443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.761181116 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.761535883 CEST49953443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.761548996 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.794363022 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.794874907 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.794958115 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.795274019 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.795327902 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.806371927 CEST4434995413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.806772947 CEST49954443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.806806087 CEST4434995413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.806999922 CEST49954443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.807010889 CEST4434995413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.833321095 CEST4434995213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.833925962 CEST4434995213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.834146023 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.834146023 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.834146023 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.836832047 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.836915016 CEST4434995613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.837196112 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.837196112 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.837315083 CEST4434995613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.849184036 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.849261045 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.849366903 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.849430084 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.849431038 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.849515915 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.849515915 CEST49951443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.849555969 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.849586964 CEST4434995113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.851500034 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.851587057 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.851674080 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.851809978 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.851829052 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.863374949 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.863545895 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.863614082 CEST49953443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.863670111 CEST49953443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.863670111 CEST49953443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.863703012 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.863723993 CEST4434995313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.865622044 CEST49958443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.865641117 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.865715027 CEST49958443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.865832090 CEST49958443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.865843058 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.893587112 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.893868923 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.893990040 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.894186020 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.894186974 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.894186974 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.894186974 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.895752907 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.895811081 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.895884991 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.895983934 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.895998955 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.910687923 CEST4434995413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.911361933 CEST4434995413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.911469936 CEST49954443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.911469936 CEST49954443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.911506891 CEST49954443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.911520004 CEST4434995413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.913149118 CEST49960443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.913178921 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:29.913245916 CEST49960443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.913360119 CEST49960443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:29.913364887 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.143884897 CEST49952443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.143946886 CEST4434995213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.206475973 CEST49955443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.206536055 CEST4434995513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.492301941 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.492860079 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.492921114 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.493295908 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.493309021 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.494210005 CEST4434995613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.494606972 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.494666100 CEST4434995613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.494738102 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.494754076 CEST4434995613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.518930912 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.519282103 CEST49958443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.519298077 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.519700050 CEST49958443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.519710064 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.559803963 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.560533047 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.560591936 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.560920000 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.560973883 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.581561089 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.582200050 CEST49960443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.582220078 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.582370043 CEST49960443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.582374096 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.593487024 CEST4434995613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.593883991 CEST4434995613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.594113111 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.594113111 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.594113111 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.595506907 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.595577002 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.595652103 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.595684052 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.595742941 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.595796108 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.595796108 CEST49957443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.595837116 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.595861912 CEST4434995713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.596954107 CEST49961443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.597038031 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.597327948 CEST49961443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.597327948 CEST49961443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.597457886 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.597796917 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.597840071 CEST4434996213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.597912073 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.598001957 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.598014116 CEST4434996213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.619751930 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.619916916 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.619982958 CEST49958443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.620032072 CEST49958443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.620033026 CEST49958443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.620049953 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.620069981 CEST4434995813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.621961117 CEST49963443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.621994972 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.622060061 CEST49963443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.622195959 CEST49963443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.622204065 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.659965038 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.660044909 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.660151005 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.660243988 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.660243988 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.660243988 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.660243988 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.662566900 CEST49964443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.662592888 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.662637949 CEST49964443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.663103104 CEST49964443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.663115978 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.689269066 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.690090895 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.690145016 CEST49960443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.690187931 CEST49960443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.690203905 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.690211058 CEST49960443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.690216064 CEST4434996013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.692672014 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.692756891 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.692825079 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.692961931 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.692981958 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.896991014 CEST49956443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.897052050 CEST4434995613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:30.973380089 CEST49959443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:30.973442078 CEST4434995913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.254281044 CEST4434996213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.255625963 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.255707979 CEST4434996213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.256093025 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.256145954 CEST4434996213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.258989096 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.259283066 CEST49963443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.259296894 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.259587049 CEST49963443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.259591103 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.264938116 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.265259981 CEST49961443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.265317917 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.265590906 CEST49961443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.265604973 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.333630085 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.333920956 CEST49964443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.333936930 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.334278107 CEST49964443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.334285021 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.346678019 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.346971035 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.347024918 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.347453117 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.347503901 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.356528997 CEST4434996213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.357033014 CEST4434996213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.357253075 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.357254028 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.357254028 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.359909058 CEST49966443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.359991074 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.360104084 CEST49966443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.360219002 CEST49966443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.360244036 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:31.660501957 CEST49962443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:31.660564899 CEST4434996213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.406994104 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.407094002 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.407125950 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.407311916 CEST49961443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.407326937 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.407402039 CEST49963443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.407464981 CEST49963443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.407480955 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.407529116 CEST49963443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.407535076 CEST4434996313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.407535076 CEST49961443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.407578945 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.407630920 CEST49961443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.407648087 CEST4434996113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408082962 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408252001 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408251047 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408319950 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408328056 CEST49964443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.408382893 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.408443928 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408485889 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408548117 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.408622980 CEST49964443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.408638000 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408655882 CEST49964443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.408662081 CEST4434996413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408818007 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.408818007 CEST49965443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.408884048 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.408919096 CEST4434996513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.411930084 CEST49967443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.411947966 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.412034988 CEST49967443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.412797928 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.412882090 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.412972927 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.413043976 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.413130999 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.413223028 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.413237095 CEST49967443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.413249016 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.413326979 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.413356066 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.413502932 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.413583040 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.413638115 CEST49970443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.413691998 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:32.413770914 CEST49970443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.414012909 CEST49970443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:32.414026022 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.404532909 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.404959917 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.405180931 CEST49967443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.405194044 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.405396938 CEST49970443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.405479908 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.405700922 CEST49967443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.405705929 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.405924082 CEST49970443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.405977964 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.419714928 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.420294046 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.420352936 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.420671940 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.420725107 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.421099901 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.421598911 CEST49966443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.421658039 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.421963930 CEST49966443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.422015905 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.434041977 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.434304953 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.434377909 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.434606075 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.434619904 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.504204988 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.504384995 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.504446030 CEST49967443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.504483938 CEST49967443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.504497051 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.504507065 CEST49967443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.504512072 CEST4434996713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.505740881 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.505892038 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.506093979 CEST49970443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.506515026 CEST49970443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.506515026 CEST49970443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.506562948 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.506592989 CEST4434997013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.507985115 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.508065939 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.508142948 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.508528948 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.508558989 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.509329081 CEST49972443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.509412050 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.509499073 CEST49972443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.509589911 CEST49972443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.509607077 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.522581100 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.523454905 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.523523092 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.523544073 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.523633003 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.524307966 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.524471045 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.524673939 CEST49966443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.524760008 CEST49966443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.524760008 CEST49966443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.524801016 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.524801016 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.524801016 CEST49969443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.524832964 CEST4434996613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.524867058 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.524899006 CEST4434996913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.527004957 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.527004957 CEST49974443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.527097940 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.527144909 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.527183056 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.527250051 CEST49974443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.527321100 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.527344942 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.527370930 CEST49974443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.527380943 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.538224936 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.538430929 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.538496971 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.538516998 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.538551092 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.538605928 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.538660049 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.538660049 CEST49968443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.538685083 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.538705111 CEST4434996813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.540345907 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.540376902 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:33.540452957 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.540568113 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:33.540601015 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.125052929 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.125699043 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.125722885 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.126076937 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.126080990 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.145240068 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.145764112 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.145813942 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.146059990 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.146074057 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.149924040 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.150247097 CEST49972443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.150253057 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.150680065 CEST49972443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.150685072 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.198271990 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.199074984 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.199134111 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.199985981 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.200040102 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.220033884 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.220598936 CEST49974443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.220657110 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.220963001 CEST49974443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.220980883 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.223843098 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.223917007 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.224005938 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.224024057 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.224076986 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.224277973 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.224322081 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.224350929 CEST49975443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.224366903 CEST4434997513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.227185011 CEST49976443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.227272987 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.227380037 CEST49976443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.227463007 CEST49976443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.227484941 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.245197058 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.245255947 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.245307922 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.245320082 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.245475054 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.245517969 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.245562077 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.245610952 CEST49971443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.245626926 CEST4434997113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.247692108 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.247729063 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.247807026 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.247946978 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.247953892 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.253467083 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.253619909 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.253674030 CEST49972443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.253703117 CEST49972443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.253705978 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.253714085 CEST49972443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.253716946 CEST4434997213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.257076025 CEST49978443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.257086992 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.257150888 CEST49978443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.257302999 CEST49978443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.257308960 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.298253059 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.298284054 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.298579931 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.298630953 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.298701048 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.298701048 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.298701048 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.302444935 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.302527905 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.302618980 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.302911997 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.302992105 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.323137045 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.323189974 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.323255062 CEST49974443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.323287010 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.323425055 CEST49974443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.323426008 CEST49974443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.323447943 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.323494911 CEST4434997413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.325292110 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.325376034 CEST4434998013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.325479984 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.325561047 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.325582027 CEST4434998013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.612628937 CEST49973443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.612694025 CEST4434997313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.867726088 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.868459940 CEST49976443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.868546963 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.869082928 CEST49976443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.869137049 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.899097919 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.899703026 CEST49978443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.899736881 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.900319099 CEST49978443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.900325060 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.927731037 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.928090096 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.928103924 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.928600073 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.928606033 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.959861040 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.960381985 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.960464001 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.960768938 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.960822105 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.968595028 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.968790054 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.968863010 CEST49976443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.968957901 CEST49976443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.968997955 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.969047070 CEST49976443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.969063044 CEST4434997613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.972275972 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.972309113 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.972374916 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.972503901 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.972507954 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.996687889 CEST4434998013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.997237921 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.997318983 CEST4434998013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:34.997653961 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:34.997706890 CEST4434998013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.001158953 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.002243042 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.002300024 CEST49978443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.002341032 CEST49978443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.002363920 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.002377987 CEST49978443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.002386093 CEST4434997813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.006340981 CEST49982443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.006350040 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.006403923 CEST49982443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.007014990 CEST49982443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.007025957 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.047966957 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.048068047 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.048115969 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.048130035 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.048204899 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.048206091 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.048224926 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.048255920 CEST49977443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.048264980 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.048274040 CEST4434997713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.052042961 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.052129984 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.052216053 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.052527905 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.052583933 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.062185049 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.062259912 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.062393904 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.062423944 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.062491894 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.062531948 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.062531948 CEST49979443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.062572956 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.062603951 CEST4434997913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.064923048 CEST49984443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.065006018 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.065100908 CEST49984443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.065237999 CEST49984443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.065263987 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.099112034 CEST4434998013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.099273920 CEST4434998013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.099466085 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.099467039 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.099467039 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.101416111 CEST49985443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.101439953 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.101495981 CEST49985443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.101592064 CEST49985443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.101598024 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.410379887 CEST49980443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.410444021 CEST4434998013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.642807961 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.646123886 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.646147013 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.646682978 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.646686077 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.691979885 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.693546057 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.693576097 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.694434881 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.695050001 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.695075989 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.695570946 CEST49982443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.695585966 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.696280956 CEST49982443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.696285963 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.739264011 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.740339994 CEST49984443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.740397930 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.740874052 CEST49984443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.740958929 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.748017073 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.748086929 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.748152971 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.748183966 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.748202085 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.748265028 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.748462915 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.748476982 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.748488903 CEST49981443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.748496056 CEST4434998113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.751708984 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.751756907 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:35.751853943 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.752012968 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:35.752022982 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.147845984 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.147857904 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.147960901 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.148049116 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.148082972 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.148114920 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.148144960 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.148175001 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.148202896 CEST49982443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.148233891 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.148397923 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.148603916 CEST49984443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.151058912 CEST49982443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.151077032 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.151087999 CEST49982443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.151093006 CEST4434998213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.153589964 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.155447006 CEST49985443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.155493975 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.163378954 CEST49985443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.163386106 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.167434931 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.167434931 CEST49983443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.167501926 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.167537928 CEST4434998313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.170887947 CEST49984443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.170887947 CEST49984443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.170953035 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.170990944 CEST4434998413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.177740097 CEST49987443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.177830935 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.177937984 CEST49987443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.178414106 CEST49987443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.178450108 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.180471897 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.180556059 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.180639982 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.180741072 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.180758953 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.181452036 CEST49989443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.181477070 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.181526899 CEST49989443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.181648970 CEST49989443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.181658030 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.262693882 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.262864113 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.262939930 CEST49985443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.268800020 CEST49985443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.268826008 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.268840075 CEST49985443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.268846989 CEST4434998513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.280946016 CEST49990443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.280976057 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.281044960 CEST49990443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.281378031 CEST49990443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.281385899 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.815867901 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.816833973 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.816857100 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.817895889 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.817900896 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.824098110 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.824541092 CEST49989443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.824570894 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.824893951 CEST49989443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.824902058 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.834474087 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.835036039 CEST49987443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.835118055 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.835800886 CEST49987443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.835853100 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.848856926 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.849374056 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.849455118 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.849679947 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.849695921 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.917725086 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.917819023 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.917876005 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.917891979 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.917926073 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.917977095 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.918015003 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.918015003 CEST49986443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.918032885 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.918041945 CEST4434998613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.920460939 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.920547962 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.920835018 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.920944929 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.920974970 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.923948050 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.924101114 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.924159050 CEST49989443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.924216986 CEST49989443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.924232960 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.924246073 CEST49989443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.924252987 CEST4434998913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.927006006 CEST49992443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.927093983 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.927176952 CEST49992443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.927356958 CEST49992443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.927381039 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.952439070 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.952595949 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.952785969 CEST49987443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.952871084 CEST49987443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.952871084 CEST49987443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.952913046 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.952940941 CEST4434998713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.954663992 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.954778910 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.954879999 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.954952002 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.954952002 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.955120087 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.955121040 CEST49988443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.955172062 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.955204010 CEST4434998813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.956140041 CEST49993443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.956223965 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.956314087 CEST49993443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.956743956 CEST49993443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.956823111 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.957576990 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.957632065 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.957715988 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.957825899 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.957838058 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.966286898 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.966834068 CEST49990443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.966852903 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:36.967353106 CEST49990443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:36.967359066 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.073416948 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.073592901 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.073678017 CEST49990443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.073848963 CEST49990443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.073863983 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.073874950 CEST49990443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.073879957 CEST4434999013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.076196909 CEST49995443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.076261997 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.076354027 CEST49995443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.076678991 CEST49995443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.076708078 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.597601891 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.598221064 CEST49993443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.598278046 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.598843098 CEST49993443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.598895073 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.614706039 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.615262032 CEST49992443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.615324020 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.615849972 CEST49992443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.615864038 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.622364998 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.622837067 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.622869015 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.623153925 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.623182058 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.629302025 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.629628897 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.629714966 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.630732059 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.630784988 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.713496923 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.713574886 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.713748932 CEST49993443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.714104891 CEST49993443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.714104891 CEST49993443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.714174032 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.714211941 CEST4434999313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.716975927 CEST49996443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.717082024 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.717190981 CEST49996443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.717402935 CEST49996443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.717427015 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.720653057 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.720840931 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.720927954 CEST49992443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.721009970 CEST49992443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.721054077 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.721081018 CEST49992443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.721097946 CEST4434999213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.723432064 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.723521948 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.723625898 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.723896980 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.723957062 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.730389118 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.730417013 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.730467081 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.730568886 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.730568886 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.730803967 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.730803967 CEST49991443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.730837107 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.730854034 CEST4434999113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.732383966 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.732819080 CEST49995443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.732841015 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.733074903 CEST49998443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.733197927 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.733216047 CEST49995443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.733242989 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.733278036 CEST49998443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.733607054 CEST49998443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.733689070 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.735825062 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.735896111 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.735965967 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.736026049 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.736068010 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.736130953 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.736179113 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.736179113 CEST49994443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.736212015 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.736236095 CEST4434999413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.738521099 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.738547087 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.738631964 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.738786936 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.738797903 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.862380028 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.862557888 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.862683058 CEST49995443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.862942934 CEST49995443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.862984896 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.863035917 CEST49995443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.863049030 CEST4434999513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.866028070 CEST50000443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.866069078 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:37.866159916 CEST50000443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.866362095 CEST50000443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:37.866373062 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.290050983 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.293673992 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.293756962 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.294105053 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.294122934 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.357300043 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.360102892 CEST49996443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.360152960 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.360752106 CEST49996443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.360766888 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.393021107 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.393099070 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.393210888 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.393342018 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.393572092 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.393572092 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.393572092 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.393613100 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.396301031 CEST50001443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.396425009 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.396524906 CEST50001443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.396641970 CEST50001443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.396670103 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.418376923 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.419785023 CEST49998443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.419872046 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.420156956 CEST49998443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.420209885 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.429577112 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.429852009 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.429864883 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.430171967 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.430176973 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.478702068 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.478924990 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.479115009 CEST49996443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.481538057 CEST49996443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.481580019 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.481606960 CEST49996443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.481625080 CEST4434999613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.501662970 CEST50002443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.501749992 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.502003908 CEST50002443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.502130032 CEST50002443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.502161026 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.536417007 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.536669016 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.536951065 CEST49998443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.566179037 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.566251993 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.566373110 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.566370010 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.566440105 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.573573112 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.575076103 CEST49998443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.575076103 CEST49998443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.575109959 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.575130939 CEST4434999813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.577023983 CEST50000443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.577069044 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.577662945 CEST50000443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.577668905 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.577850103 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.577851057 CEST49999443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.577882051 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.577903032 CEST4434999913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.581026077 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.581062078 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.581139088 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.581427097 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.581437111 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.588885069 CEST50004443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.588927984 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.589013100 CEST50004443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.589210987 CEST50004443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.589219093 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.678076029 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.678251982 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.678421974 CEST50000443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.682570934 CEST49997443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.682636023 CEST4434999713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.686908007 CEST50000443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.686908007 CEST50000443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.686922073 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.686932087 CEST4435000013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.699451923 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.699537039 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:38.699626923 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.699911118 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:38.699970961 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.386049032 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.386667967 CEST50002443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.386693001 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.387329102 CEST50002443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.387336016 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.388317108 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.388643980 CEST50001443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.388658047 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.389102936 CEST50001443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.389107943 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.491698027 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.492717028 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.492805958 CEST50002443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.492865086 CEST50002443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.492865086 CEST50002443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.492899895 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.492924929 CEST4435000213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.494894981 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.495081902 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.495152950 CEST50001443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.495197058 CEST50001443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.495197058 CEST50001443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.495213985 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.495235920 CEST4435000113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.496072054 CEST50006443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.496161938 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.496445894 CEST50006443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.496445894 CEST50006443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.496573925 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.497291088 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.497338057 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.497392893 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.497478962 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.497488976 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.576302052 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.576747894 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.576787949 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.576901913 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.577208042 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.577214956 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.577219009 CEST50004443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.577244997 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.577769041 CEST50004443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.577775955 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.577982903 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.578418970 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.578500032 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.578563929 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.578577995 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.674947977 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.675111055 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.675321102 CEST50004443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.675390959 CEST50004443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.675421953 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.675438881 CEST50004443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.675445080 CEST4435000413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.678814888 CEST50008443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.678905010 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.678989887 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679059029 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679153919 CEST50008443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679162979 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679236889 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679236889 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679266930 CEST50008443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679299116 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679326057 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679326057 CEST50005443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679368973 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679398060 CEST4435000513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679502010 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679568052 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679614067 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679641962 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679673910 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679718018 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679740906 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679758072 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679758072 CEST50003443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.679766893 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.679774046 CEST4435000313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.681536913 CEST50009443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.681627035 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.681710005 CEST50010443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.681731939 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.681756973 CEST50009443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.681817055 CEST50010443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.681879044 CEST50009443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.681896925 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.681922913 CEST50010443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:39.681931973 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:39.785455942 CEST49883443192.168.2.4142.250.185.132
                                                    Oct 3, 2024 18:17:39.785491943 CEST44349883142.250.185.132192.168.2.4
                                                    Oct 3, 2024 18:17:40.138427019 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.138993025 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.139020920 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.139713049 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.139719963 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.143192053 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.143600941 CEST50006443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.143631935 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.144154072 CEST50006443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.144161940 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.237912893 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.237981081 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.238049030 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.238065004 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.238086939 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.238135099 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.238858938 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.238873005 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.238883972 CEST50007443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.238889933 CEST4435000713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.242409945 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.242502928 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.242608070 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.242784977 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.242805004 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.270684958 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.270872116 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.270952940 CEST50006443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.271020889 CEST50006443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.271022081 CEST50006443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.271054983 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.271076918 CEST4435000613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.273627996 CEST50012443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.273715019 CEST4435001213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.273823023 CEST50012443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.273962975 CEST50012443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.273983002 CEST4435001213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.324831009 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.325329065 CEST50009443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.325402021 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.325759888 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.325911045 CEST50009443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.325927019 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.326173067 CEST50010443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.326200008 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.326657057 CEST50010443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.326667070 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.346641064 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.347117901 CEST50008443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.347202063 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.347712994 CEST50008443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.347764969 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.423934937 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.423959970 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.424128056 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.424233913 CEST50010443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.424340963 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.424365997 CEST50010443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.424413919 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.424444914 CEST50010443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.424444914 CEST50009443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.424465895 CEST4435001013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.450547934 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.450690985 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.450901985 CEST50008443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.460381985 CEST50009443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.460381985 CEST50009443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.460455894 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.460486889 CEST4435000913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.462836027 CEST50008443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.462836027 CEST50008443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.462902069 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.462930918 CEST4435000813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.465809107 CEST50013443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.465873957 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.465956926 CEST50013443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.466625929 CEST50014443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.466658115 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.466727972 CEST50014443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.466849089 CEST50015443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.466934919 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.466972113 CEST50013443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.466996908 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.467008114 CEST50015443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.467093945 CEST50014443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.467113972 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.467189074 CEST50015443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.467225075 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.913126945 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.914083958 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.914129972 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.914716959 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.914743900 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.959063053 CEST4435001213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.959717035 CEST50012443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.959760904 CEST4435001213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:40.960302114 CEST50012443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:40.960309029 CEST4435001213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.029639959 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.029653072 CEST4435001213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.029683113 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.029750109 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.029759884 CEST4435001213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.029822111 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.029853106 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.030155897 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.030158997 CEST50012443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.030158997 CEST50012443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.030185938 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.030190945 CEST50012443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.030201912 CEST4435001213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.030203104 CEST50011443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.030210972 CEST4435001113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.033402920 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.034060001 CEST50016443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.034070015 CEST50013443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.034090042 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.034102917 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.034168005 CEST50016443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.034279108 CEST50017443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.034291983 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.034318924 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.034378052 CEST50017443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.034470081 CEST50016443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.034487009 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.034799099 CEST50017443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.034816980 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.034915924 CEST50013443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.034921885 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.035116911 CEST50014443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.035125017 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.035629034 CEST50014443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.035634041 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.038400888 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.038786888 CEST50015443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.038805008 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.039333105 CEST50015443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.039339066 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.134772062 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.134938002 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.135020971 CEST50013443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.135171890 CEST50013443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.135190964 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.135205030 CEST50013443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.135211945 CEST4435001313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.138816118 CEST50019443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.138911963 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.139012098 CEST50019443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.139260054 CEST50019443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.139296055 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.139324903 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.139411926 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.139472961 CEST50015443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.139586926 CEST50015443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.139586926 CEST50015443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.139611959 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.139632940 CEST4435001513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.142194033 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.142246008 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.142339945 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.142520905 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.142538071 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.301753998 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.301934958 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.302018881 CEST50014443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.302335978 CEST50014443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.302362919 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.302433968 CEST50014443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.302445889 CEST4435001413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.305483103 CEST50021443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.305573940 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:42.305670977 CEST50021443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.305831909 CEST50021443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:42.305850029 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.008383989 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.008856058 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.008959055 CEST50017443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.008992910 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.009438038 CEST50017443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.009447098 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.009722948 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.009740114 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.009743929 CEST50019443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.009784937 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.010380983 CEST50019443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.010390997 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.010732889 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.010763884 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.011239052 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.011245966 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.011835098 CEST50016443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.011843920 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.012449026 CEST50016443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.012454987 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.107908964 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.108125925 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.108185053 CEST50017443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.108302116 CEST50017443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.108324051 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.108338118 CEST50017443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.108345032 CEST4435001713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.108592033 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.108634949 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.108748913 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.108799934 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.108805895 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.108855009 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.109111071 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.109175920 CEST50019443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.109807014 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.109839916 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.109858990 CEST50020443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.109869003 CEST4435002013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.110466003 CEST50019443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.110496044 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.110515118 CEST50019443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.110523939 CEST4435001913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.113517046 CEST50022443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.113557100 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.113616943 CEST50022443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.114247084 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.114281893 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.114340067 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.114496946 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.114567995 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.114615917 CEST50016443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.114696026 CEST50022443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.114716053 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.114780903 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.114801884 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.115376949 CEST50024443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.115421057 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.115474939 CEST50024443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.115557909 CEST50024443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.115571022 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.115588903 CEST50016443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.115600109 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.115613937 CEST50016443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.115618944 CEST4435001613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.117296934 CEST50025443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.117367029 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.117443085 CEST50025443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.117546082 CEST50025443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.117578030 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.196568966 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.197187901 CEST50021443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.197269917 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.197937012 CEST50021443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.197958946 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.298945904 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.299288988 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.299357891 CEST50021443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.299514055 CEST50021443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.299514055 CEST50021443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.299534082 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.299545050 CEST4435002113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.302707911 CEST50026443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.302753925 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.302839994 CEST50026443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.303025007 CEST50026443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.303040981 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.982908964 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.983673096 CEST50025443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.983707905 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.984340906 CEST50025443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.984349012 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.990840912 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.990854979 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.991247892 CEST50026443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.991265059 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.991363049 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.991405010 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.991714001 CEST50026443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.991720915 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:43.991904020 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:43.991910934 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.000185013 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.000860929 CEST50024443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.000900984 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.001569986 CEST50024443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.001581907 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.006736040 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.007232904 CEST50022443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.007313013 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.007807016 CEST50022443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.007822037 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.097527981 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.097681046 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.097754002 CEST50025443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.097914934 CEST50025443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.097938061 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.097950935 CEST50025443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.097958088 CEST4435002513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.101706028 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.101727962 CEST50027443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.101785898 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.101856947 CEST50027443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.102056980 CEST50027443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.102077007 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.102277040 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.102339983 CEST50026443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.102415085 CEST50026443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.102420092 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.102435112 CEST50026443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.102440119 CEST4435002613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.103482962 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.103605986 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.103656054 CEST50024443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.103671074 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.103722095 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.103745937 CEST50024443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.103748083 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.103769064 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.103784084 CEST50024443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.103790998 CEST4435002413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.103991032 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.104029894 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.104036093 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.104073048 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.104123116 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.104145050 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.104160070 CEST50023443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.104166985 CEST4435002313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.106024027 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.106062889 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.106110096 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.106309891 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.106323957 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.108037949 CEST50029443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.108103991 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.108155012 CEST50029443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.108222008 CEST50030443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.108243942 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.108299971 CEST50030443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.108335018 CEST50029443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.108361959 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.108457088 CEST50030443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.108479023 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.112047911 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.112396955 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.112461090 CEST50022443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.112556934 CEST50022443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.112556934 CEST50022443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.112601042 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.112627983 CEST4435002213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.115305901 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.115317106 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.115366936 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.115482092 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.115489006 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.740988016 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.741585016 CEST50027443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.741606951 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.742228031 CEST50027443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.742235899 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.752340078 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.752623081 CEST50030443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.752640009 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.753067017 CEST50030443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.753072023 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.755625010 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.756066084 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.756092072 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.756520987 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.756525040 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.766655922 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.767010927 CEST50029443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.767026901 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.767492056 CEST50029443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.767496109 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.774663925 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.774952888 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.774965048 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.775302887 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.775306940 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.840545893 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.840681076 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.840786934 CEST50027443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.840876102 CEST50027443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.840894938 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.840912104 CEST50027443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.840919018 CEST4435002713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.843776941 CEST50032443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.843826056 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.843888044 CEST50032443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.844034910 CEST50032443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.844053984 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.851855993 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.851902008 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.851943970 CEST50030443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.852154970 CEST50030443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.852175951 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.852189064 CEST50030443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.852195024 CEST4435003013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.854418993 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.854460001 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.854532003 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.854636908 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.854648113 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.867377043 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.867454052 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.867510080 CEST50029443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.867594957 CEST50029443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.867613077 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.867635012 CEST50029443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.867640972 CEST4435002913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.869962931 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.869973898 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.870034933 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.870167971 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.870177031 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.882615089 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.883863926 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.883908987 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.883909941 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.883955956 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.883989096 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.883999109 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.884012938 CEST50028443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.884017944 CEST4435002813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.885966063 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.885979891 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.886039019 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.886142015 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.886156082 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.951960087 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.951987028 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.952060938 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.952168941 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.952380896 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.952380896 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.953191042 CEST50031443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.953203917 CEST4435003113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.955355883 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.955423117 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:44.955507040 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.955698967 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:44.955719948 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.646437883 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.647456884 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.647519112 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.648057938 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.648073912 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.651773930 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.652296066 CEST50032443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.652375937 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.652709007 CEST50032443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.652725935 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.694116116 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.694587946 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.694613934 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.695132971 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.695143938 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.744160891 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.744667053 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.744726896 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.745125055 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.745138884 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.747426033 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.747684002 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.747740984 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.748147011 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.748157024 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.754601955 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.754652977 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.754717112 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.754744053 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.754954100 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.754987001 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.755008936 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.755430937 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.755532026 CEST4435003313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.755589008 CEST50033443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.757389069 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.757553101 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.757612944 CEST50032443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.757658005 CEST50032443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.757682085 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.757697105 CEST50032443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.757705927 CEST4435003213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.757972002 CEST50037443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.758018017 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.758101940 CEST50037443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.758285999 CEST50037443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.758301020 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.760041952 CEST50038443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.760051966 CEST4435003813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.760123014 CEST50038443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.760240078 CEST50038443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.760251045 CEST4435003813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.828875065 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.828934908 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.829090118 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.829096079 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.829161882 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.829200983 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.829243898 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.829273939 CEST50034443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.829288960 CEST4435003413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.831228018 CEST50039443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.831262112 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.831317902 CEST50039443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.831418991 CEST50039443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.831428051 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.852018118 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.852047920 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.852106094 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.852145910 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.852205038 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.852360010 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.852444887 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.852469921 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.852485895 CEST50035443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.852497101 CEST4435003513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.854861021 CEST50040443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.854887962 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.854970932 CEST50040443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.855071068 CEST50040443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.855081081 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.867939949 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.867986917 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.868108988 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.868163109 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.868235111 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.868235111 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.868235111 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.870307922 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.870343924 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:45.870404005 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.870518923 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:45.870533943 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:46.175587893 CEST50036443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:46.175638914 CEST4435003613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.110661983 CEST4435003813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.112669945 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.113097906 CEST50038443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.113176107 CEST4435003813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.114192963 CEST50038443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.114212036 CEST4435003813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.114862919 CEST50037443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.114886045 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.115446091 CEST50037443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.115454912 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.116693974 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.117239952 CEST50040443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.117260933 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.117666960 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.117791891 CEST50040443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.117799044 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.118086100 CEST50039443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.118164062 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.118571997 CEST50039443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.118585110 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.212186098 CEST4435003813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.212327003 CEST4435003813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.212408066 CEST50038443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.212563992 CEST50038443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.212606907 CEST4435003813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.214920044 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.215012074 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.215073109 CEST50037443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.216087103 CEST50037443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.216109037 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.216134071 CEST50037443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.216149092 CEST4435003713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.218251944 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.218301058 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.218367100 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.219788074 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.219830990 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.219846964 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.219911098 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.219945908 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.219999075 CEST50040443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.220237970 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.220251083 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.220370054 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.220383883 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.220534086 CEST50040443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.220549107 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.220562935 CEST50040443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.220568895 CEST4435004013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.221257925 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.221457958 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.221535921 CEST50039443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.221615076 CEST50039443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.221659899 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.221687078 CEST50039443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.221703053 CEST4435003913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.226043940 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.226089001 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.226154089 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.226340055 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.226358891 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.227020979 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.227051020 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.227116108 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.231722116 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.231735945 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.559942007 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.560798883 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.560828924 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.561594009 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.561605930 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.658473969 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.658585072 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.658687115 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.658715010 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.658860922 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.658865929 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.658883095 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.658932924 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.659118891 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.659132004 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.659142971 CEST50041443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.659147978 CEST4435004113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.663496971 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.663536072 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.663639069 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.663861990 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.663882017 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.868712902 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.869467974 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.869493961 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.870033026 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.870038033 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.870197058 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.870631933 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.870668888 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.871198893 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.871203899 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.881980896 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.882688999 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.882730007 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.883253098 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.883256912 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.902359009 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.902806044 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.902842999 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.903422117 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.903429031 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.969866991 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.969926119 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.970019102 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.970048904 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.970084906 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.970143080 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.970390081 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.970406055 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.970415115 CEST50045443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.970421076 CEST4435004513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.972943068 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.973012924 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.973056078 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.973098040 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.973119974 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.973141909 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.973171949 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.976074934 CEST50047443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.976125002 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.976243019 CEST50047443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.976398945 CEST50047443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.976408958 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.985346079 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.985373974 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.985562086 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.985591888 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.985701084 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.985719919 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.985727072 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.985877991 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.985920906 CEST4435004213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.986011982 CEST50042443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.989063025 CEST50048443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.989150047 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:47.989252090 CEST50048443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.991651058 CEST50048443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:47.991683960 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.053498983 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.053531885 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.053560019 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.053648949 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.053687096 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.053715944 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.053751945 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.058296919 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.058392048 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.058406115 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.058475018 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.058528900 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.061358929 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.061373949 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.061384916 CEST50043443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.061392069 CEST4435004313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.065593958 CEST50049443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.065640926 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.065746069 CEST50049443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.065929890 CEST50049443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.065943956 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.128577948 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.128612041 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.128643990 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.128654003 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.128668070 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.128717899 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.131084919 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.131102085 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.131114006 CEST50044443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.131120920 CEST4435004413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.136457920 CEST50050443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.136491060 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.136543989 CEST50050443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.137664080 CEST50050443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.137680054 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.330323935 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.330946922 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.330967903 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.331490040 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.331496000 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.430362940 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.430418968 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.430500984 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.430512905 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.430558920 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.430742979 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.430845976 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.430891991 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.430913925 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.430924892 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.430932999 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.430938959 CEST50046443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.430942059 CEST4435004613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.434480906 CEST50051443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.434526920 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.434608936 CEST50051443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.434808016 CEST50051443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.434819937 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.616260052 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.617083073 CEST50047443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.617158890 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.617616892 CEST50047443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.617630959 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.664904118 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.665653944 CEST50048443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.665682077 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.666171074 CEST50048443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.666177034 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.715538979 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.715569973 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.715665102 CEST50047443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.715728998 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.716029882 CEST50047443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.716029882 CEST50047443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.716065884 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.716093063 CEST4435004713.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.720534086 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.720585108 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.720675945 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.720854998 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.720871925 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.746283054 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.746855021 CEST50049443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.746952057 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.747456074 CEST50049443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.747483015 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.770049095 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.770320892 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.770385981 CEST50048443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.770570040 CEST50048443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.770595074 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.770608902 CEST50048443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.770617008 CEST4435004813.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.774386883 CEST50053443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.774483919 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.774579048 CEST50053443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.774756908 CEST50053443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.774794102 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.778125048 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.778584003 CEST50050443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.778616905 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.779293060 CEST50050443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.779299021 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.853374958 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.853451967 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.853537083 CEST50049443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.853945017 CEST50049443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.853945017 CEST50049443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.853984118 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.854002953 CEST4435004913.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.857646942 CEST50054443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.857744932 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.857888937 CEST50054443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.858127117 CEST50054443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.858165979 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.878137112 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.878308058 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.878392935 CEST50050443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.878474951 CEST50050443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.878474951 CEST50050443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.878519058 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.878545046 CEST4435005013.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.881588936 CEST50055443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.881683111 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:48.881799936 CEST50055443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.882025957 CEST50055443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:48.882057905 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.145947933 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.146619081 CEST50051443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.146703959 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.147278070 CEST50051443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.147293091 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.464710951 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.464962959 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.465060949 CEST50051443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.465153933 CEST50051443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.465198994 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.465231895 CEST50051443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.465249062 CEST4435005113.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.469253063 CEST50056443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.469305038 CEST4435005613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.469410896 CEST50056443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.469616890 CEST50056443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.469633102 CEST4435005613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.558482885 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.559231997 CEST50053443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.559281111 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.559871912 CEST50053443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.559885025 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.561438084 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.561774015 CEST50054443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.561806917 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.562243938 CEST50054443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.562253952 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.572230101 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.572654963 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.572710991 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.573122025 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.573134899 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.659580946 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.659652948 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.659780025 CEST50053443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.660324097 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.660536051 CEST50053443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.660540104 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.660583019 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.660613060 CEST50053443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.660613060 CEST50054443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.660634041 CEST4435005313.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.662420034 CEST50054443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.662441969 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.662463903 CEST50054443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.662475109 CEST4435005413.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.681345940 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.681633949 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.681710005 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.681735992 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.681809902 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.681879997 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.681925058 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.681957006 CEST50052443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.681972980 CEST4435005213.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.776207924 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.776815891 CEST50055443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.776853085 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.777472973 CEST50055443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.777489901 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.874963045 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.875184059 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.875323057 CEST50055443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.898169994 CEST50055443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.898246050 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:49.898286104 CEST50055443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:49.898303986 CEST4435005513.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:50.071125984 CEST4435005613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:50.102935076 CEST50056443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:50.102972984 CEST4435005613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:50.103424072 CEST50056443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:50.103441000 CEST4435005613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:51.238280058 CEST4435005613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:51.238465071 CEST4435005613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:51.238621950 CEST50056443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:51.238663912 CEST50056443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:51.238663912 CEST50056443192.168.2.413.107.246.60
                                                    Oct 3, 2024 18:17:51.238684893 CEST4435005613.107.246.60192.168.2.4
                                                    Oct 3, 2024 18:17:51.238698006 CEST4435005613.107.246.60192.168.2.4
                                                    TimestampSource PortDest PortSource IPDest IP
                                                    Oct 3, 2024 18:16:11.963056087 CEST4945753192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:11.963228941 CEST6381953192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:12.180543900 CEST53520831.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:12.180609941 CEST53581691.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:12.180632114 CEST53638191.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:12.180711985 CEST53494571.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:13.334887981 CEST5947153192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:13.335280895 CEST5770753192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:13.343482971 CEST53594711.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:13.345201015 CEST53577071.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:13.346112967 CEST53543991.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:16.473275900 CEST5971453192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:16.473428011 CEST5514753192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:16.480211973 CEST53597141.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:16.480947971 CEST53551471.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:19.097579002 CEST53573271.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:21.689418077 CEST5381953192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:21.689616919 CEST5455553192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:21.696762085 CEST53538191.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:21.697999001 CEST53545551.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:22.803365946 CEST5172053192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:22.803757906 CEST5340253192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:16:22.810522079 CEST53517201.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:22.810568094 CEST53534021.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:23.102128983 CEST138138192.168.2.4192.168.2.255
                                                    Oct 3, 2024 18:16:24.419287920 CEST53591341.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:30.459474087 CEST53616361.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:16:49.357407093 CEST53635921.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:17:11.811007977 CEST53570501.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:17:12.027327061 CEST53592141.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:17:23.843159914 CEST53600671.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:17:25.396888971 CEST5030053192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:17:25.397017002 CEST6433053192.168.2.41.1.1.1
                                                    Oct 3, 2024 18:17:25.403696060 CEST53503001.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:17:25.405019999 CEST53643301.1.1.1192.168.2.4
                                                    Oct 3, 2024 18:17:39.793378115 CEST53593281.1.1.1192.168.2.4
                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                    Oct 3, 2024 18:16:11.963056087 CEST192.168.2.41.1.1.10x14fbStandard query (0)youtube.comA (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:11.963228941 CEST192.168.2.41.1.1.10xbfc4Standard query (0)youtube.com65IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.334887981 CEST192.168.2.41.1.1.10x3c89Standard query (0)www.youtube.comA (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.335280895 CEST192.168.2.41.1.1.10x6435Standard query (0)www.youtube.com65IN (0x0001)false
                                                    Oct 3, 2024 18:16:16.473275900 CEST192.168.2.41.1.1.10xf45aStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:16.473428011 CEST192.168.2.41.1.1.10x3972Standard query (0)www.google.com65IN (0x0001)false
                                                    Oct 3, 2024 18:16:21.689418077 CEST192.168.2.41.1.1.10x50d0Standard query (0)accounts.youtube.comA (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:21.689616919 CEST192.168.2.41.1.1.10x179dStandard query (0)accounts.youtube.com65IN (0x0001)false
                                                    Oct 3, 2024 18:16:22.803365946 CEST192.168.2.41.1.1.10x7ae3Standard query (0)play.google.comA (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:22.803757906 CEST192.168.2.41.1.1.10x7659Standard query (0)play.google.com65IN (0x0001)false
                                                    Oct 3, 2024 18:17:25.396888971 CEST192.168.2.41.1.1.10xdb8eStandard query (0)play.google.comA (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:17:25.397017002 CEST192.168.2.41.1.1.10x13d8Standard query (0)play.google.com65IN (0x0001)false
                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                    Oct 3, 2024 18:16:12.180632114 CEST1.1.1.1192.168.2.40xbfc4No error (0)youtube.com65IN (0x0001)false
                                                    Oct 3, 2024 18:16:12.180711985 CEST1.1.1.1192.168.2.40x14fbNo error (0)youtube.com142.250.185.238A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)www.youtube.comyoutube-ui.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com172.217.16.206A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.181.238A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.184.238A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.186.174A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com216.58.206.78A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.185.78A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com216.58.206.46A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.184.206A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.185.238A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.186.46A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.74.206A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.186.142A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com172.217.18.14A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.185.110A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.186.110A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.343482971 CEST1.1.1.1192.168.2.40x3c89No error (0)youtube-ui.l.google.com142.250.186.78A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.345201015 CEST1.1.1.1192.168.2.40x6435No error (0)www.youtube.comyoutube-ui.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                    Oct 3, 2024 18:16:13.345201015 CEST1.1.1.1192.168.2.40x6435No error (0)youtube-ui.l.google.com65IN (0x0001)false
                                                    Oct 3, 2024 18:16:16.480211973 CEST1.1.1.1192.168.2.40xf45aNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:16.480947971 CEST1.1.1.1192.168.2.40x3972No error (0)www.google.com65IN (0x0001)false
                                                    Oct 3, 2024 18:16:21.696762085 CEST1.1.1.1192.168.2.40x50d0No error (0)accounts.youtube.comwww3.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                    Oct 3, 2024 18:16:21.696762085 CEST1.1.1.1192.168.2.40x50d0No error (0)www3.l.google.com216.58.206.78A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:16:21.697999001 CEST1.1.1.1192.168.2.40x179dNo error (0)accounts.youtube.comwww3.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                    Oct 3, 2024 18:16:22.810522079 CEST1.1.1.1192.168.2.40x7ae3No error (0)play.google.com142.250.181.238A (IP address)IN (0x0001)false
                                                    Oct 3, 2024 18:17:25.403696060 CEST1.1.1.1192.168.2.40xdb8eNo error (0)play.google.com142.250.181.238A (IP address)IN (0x0001)false
                                                    • youtube.com
                                                    • www.youtube.com
                                                    • fs.microsoft.com
                                                    • https:
                                                      • accounts.youtube.com
                                                      • www.google.com
                                                    • slscr.update.microsoft.com
                                                    • otelrules.azureedge.net
                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                    0192.168.2.449731142.250.185.2384436884C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:16:12 UTC851OUTGET /account?=https://accounts.google.com/v3/signin/challenge/pwd HTTP/1.1
                                                    Host: youtube.com
                                                    Connection: keep-alive
                                                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                    sec-ch-ua-mobile: ?0
                                                    sec-ch-ua-platform: "Windows"
                                                    Upgrade-Insecure-Requests: 1
                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                    X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                                                    Sec-Fetch-Site: none
                                                    Sec-Fetch-Mode: navigate
                                                    Sec-Fetch-User: ?1
                                                    Sec-Fetch-Dest: document
                                                    Accept-Encoding: gzip, deflate, br
                                                    Accept-Language: en-US,en;q=0.9
                                                    2024-10-03 16:16:13 UTC1704INHTTP/1.1 301 Moved Permanently
                                                    Content-Type: application/binary
                                                    X-Content-Type-Options: nosniff
                                                    Expires: Thu, 03 Oct 2024 16:16:13 GMT
                                                    Date: Thu, 03 Oct 2024 16:16:13 GMT
                                                    Cache-Control: private, max-age=31536000
                                                    Location: https://www.youtube.com/account?=https%3A%2F%2Faccounts.google.com%2Fv3%2Fsignin%2Fchallenge%2Fpwd
                                                    Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                    X-Frame-Options: SAMEORIGIN
                                                    Report-To: {"group":"youtube_main","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/youtube_main"}]}
                                                    Origin-Trial: AmhMBR6zCLzDDxpW+HfpP67BqwIknWnyMOXOQGfzYswFmJe+fgaI6XZgAzcxOrzNtP7hEDsOo1jdjFnVr2IdxQ4AAAB4eyJvcmlnaW4iOiJodHRwczovL3lvdXR1YmUuY29tOjQ0MyIsImZlYXR1cmUiOiJXZWJWaWV3WFJlcXVlc3RlZFdpdGhEZXByZWNhdGlvbiIsImV4cGlyeSI6MTc1ODA2NzE5OSwiaXNTdWJkb21haW4iOnRydWV9
                                                    Content-Security-Policy: require-trusted-types-for 'script'
                                                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                    Vary: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
                                                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="youtube_main"
                                                    Server: ESF
                                                    Content-Length: 0
                                                    X-XSS-Protection: 0
                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                    Connection: close


                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                    1192.168.2.449736172.217.16.2064436884C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:16:14 UTC869OUTGET /account?=https%3A%2F%2Faccounts.google.com%2Fv3%2Fsignin%2Fchallenge%2Fpwd HTTP/1.1
                                                    Host: www.youtube.com
                                                    Connection: keep-alive
                                                    Upgrade-Insecure-Requests: 1
                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                    X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                                                    Sec-Fetch-Site: none
                                                    Sec-Fetch-Mode: navigate
                                                    Sec-Fetch-User: ?1
                                                    Sec-Fetch-Dest: document
                                                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                    sec-ch-ua-mobile: ?0
                                                    sec-ch-ua-platform: "Windows"
                                                    Accept-Encoding: gzip, deflate, br
                                                    Accept-Language: en-US,en;q=0.9
                                                    2024-10-03 16:16:14 UTC2634INHTTP/1.1 303 See Other
                                                    Content-Type: application/binary
                                                    X-Content-Type-Options: nosniff
                                                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                    Pragma: no-cache
                                                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                    Date: Thu, 03 Oct 2024 16:16:14 GMT
                                                    Location: https://accounts.google.com/ServiceLogin?service=youtube&uilel=3&passive=true&continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%253F%253Dhttps%25253A%25252F%25252Faccounts.google.com%25252Fv3%25252Fsignin%25252Fchallenge%25252Fpwd%26feature%3Dredirect_login&hl=en
                                                    Strict-Transport-Security: max-age=31536000
                                                    X-Frame-Options: SAMEORIGIN
                                                    Report-To: {"group":"youtube_main","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/youtube_main"}]}
                                                    Origin-Trial: AmhMBR6zCLzDDxpW+HfpP67BqwIknWnyMOXOQGfzYswFmJe+fgaI6XZgAzcxOrzNtP7hEDsOo1jdjFnVr2IdxQ4AAAB4eyJvcmlnaW4iOiJodHRwczovL3lvdXR1YmUuY29tOjQ0MyIsImZlYXR1cmUiOiJXZWJWaWV3WFJlcXVlc3RlZFdpdGhEZXByZWNhdGlvbiIsImV4cGlyeSI6MTc1ODA2NzE5OSwiaXNTdWJkb21haW4iOnRydWV9
                                                    Content-Security-Policy: require-trusted-types-for 'script'
                                                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                    Vary: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
                                                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="youtube_main"
                                                    P3P: CP="This is not a P3P policy! See http://support.google.com/accounts/answer/151657?hl=en for more info."
                                                    Server: ESF
                                                    Content-Length: 0
                                                    X-XSS-Protection: 0
                                                    Set-Cookie: GPS=1; Domain=.youtube.com; Expires=Thu, 03-Oct-2024 16:46:14 GMT; Path=/; Secure; HttpOnly
                                                    Set-Cookie: YSC=qusGJk9XSP4; Domain=.youtube.com; Path=/; Secure; HttpOnly; SameSite=none; Partitioned
                                                    Set-Cookie: VISITOR_INFO1_LIVE=oqY5ICC8iFg; Domain=.youtube.com; Expires=Tue, 01-Apr-2025 16:16:14 GMT; Path=/; Secure; HttpOnly; SameSite=none; Partitioned
                                                    Set-Cookie: VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgMQ%3D%3D; Domain=.youtube.com; Expires=Tue, 01-Apr-2025 16:16:14 GMT; Path=/; Secure; HttpOnly; SameSite=none; Partitioned
                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                    Connection: close


                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                    2192.168.2.449742184.28.90.27443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:16:17 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept: */*
                                                    Accept-Encoding: identity
                                                    User-Agent: Microsoft BITS/7.8
                                                    Host: fs.microsoft.com
                                                    2024-10-03 16:16:17 UTC465INHTTP/1.1 200 OK
                                                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                    Content-Type: application/octet-stream
                                                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                    Server: ECAcc (lpl/EF70)
                                                    X-CID: 11
                                                    X-Ms-ApiVersion: Distribute 1.2
                                                    X-Ms-Region: prod-neu-z1
                                                    Cache-Control: public, max-age=1719
                                                    Date: Thu, 03 Oct 2024 16:16:17 GMT
                                                    Connection: close
                                                    X-CID: 2


                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                    3192.168.2.449744184.28.90.27443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:16:18 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept: */*
                                                    Accept-Encoding: identity
                                                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                                                    Range: bytes=0-2147483646
                                                    User-Agent: Microsoft BITS/7.8
                                                    Host: fs.microsoft.com
                                                    2024-10-03 16:16:18 UTC514INHTTP/1.1 200 OK
                                                    ApiVersion: Distribute 1.1
                                                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                    Content-Type: application/octet-stream
                                                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                    Server: ECAcc (lpl/EF06)
                                                    X-CID: 11
                                                    X-Ms-ApiVersion: Distribute 1.2
                                                    X-Ms-Region: prod-weu-z1
                                                    Cache-Control: public, max-age=25938
                                                    Date: Thu, 03 Oct 2024 16:16:18 GMT
                                                    Content-Length: 55
                                                    Connection: close
                                                    X-CID: 2
                                                    2024-10-03 16:16:18 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                                                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                    4192.168.2.449756216.58.206.784436884C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:16:22 UTC1217OUTGET /accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1075052270&timestamp=1727972180607 HTTP/1.1
                                                    Host: accounts.youtube.com
                                                    Connection: keep-alive
                                                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                    sec-ch-ua-mobile: ?0
                                                    sec-ch-ua-full-version: "117.0.5938.132"
                                                    sec-ch-ua-arch: "x86"
                                                    sec-ch-ua-platform: "Windows"
                                                    sec-ch-ua-platform-version: "10.0.0"
                                                    sec-ch-ua-model: ""
                                                    sec-ch-ua-bitness: "64"
                                                    sec-ch-ua-wow64: ?0
                                                    sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                                                    Upgrade-Insecure-Requests: 1
                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                    X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                                                    Sec-Fetch-Site: cross-site
                                                    Sec-Fetch-Mode: navigate
                                                    Sec-Fetch-Dest: iframe
                                                    Referer: https://accounts.google.com/
                                                    Accept-Encoding: gzip, deflate, br
                                                    Accept-Language: en-US,en;q=0.9
                                                    2024-10-03 16:16:22 UTC1969INHTTP/1.1 200 OK
                                                    Content-Type: text/html; charset=utf-8
                                                    X-Frame-Options: ALLOW-FROM https://accounts.google.com
                                                    Content-Security-Policy: frame-ancestors https://accounts.google.com
                                                    Content-Security-Policy: script-src 'report-sample' 'nonce-hgHrG9d5O2hRoFZyPg5swA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/AccountsDomainCookiesCheckConnectionHttp/cspreport;worker-src 'self'
                                                    Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/AccountsDomainCookiesCheckConnectionHttp/cspreport/allowlist
                                                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/AccountsDomainCookiesCheckConnectionHttp/cspreport
                                                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                    Pragma: no-cache
                                                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                    Date: Thu, 03 Oct 2024 16:16:22 GMT
                                                    Cross-Origin-Resource-Policy: cross-origin
                                                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
                                                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                    Cross-Origin-Opener-Policy: same-origin
                                                    reporting-endpoints: default="/_/AccountsDomainCookiesCheckConnectionHttp/web-reports?context=eJzjstDikmJw0JBikPj6kkkNiJ3SZ7AGAHHSv_OsBUB8ufsS63UgVu25xGoMxEUSV1gbgFiIh-Na2-_tbAILdv5tZVLSS8ovjM9MSc0rySypTMnPTczMS87Pz85MLS5OLSpLLYo3MjAyMbA0MtIzsIgvMAAA3bQtiA"
                                                    Server: ESF
                                                    X-XSS-Protection: 0
                                                    X-Content-Type-Options: nosniff
                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                    Accept-Ranges: none
                                                    Vary: Accept-Encoding
                                                    Connection: close
                                                    Transfer-Encoding: chunked
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 37 36 32 30 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 73 63 72 69 70 74 20 6e 6f 6e 63 65 3d 22 68 67 48 72 47 39 64 35 4f 32 68 52 6f 46 5a 79 50 67 35 73 77 41 22 3e 22 75 73 65 20 73 74 72 69 63 74 22 3b 74 68 69 73 2e 64 65 66 61 75 6c 74 5f 41 63 63 6f 75 6e 74 73 44 6f 6d 61 69 6e 63 6f 6f 6b 69 65 73 43 68 65 63 6b 63 6f 6e 6e 65 63 74 69 6f 6e 4a 73 3d 74 68 69 73 2e 64 65 66 61 75 6c 74 5f 41 63 63 6f 75 6e 74 73 44 6f 6d 61 69 6e 63 6f 6f 6b 69 65 73 43 68 65 63 6b 63 6f 6e 6e 65 63 74 69 6f 6e 4a 73 7c 7c 7b 7d 3b 28 66 75 6e 63 74 69 6f 6e 28 5f 29 7b 76 61 72 20 77 69 6e 64 6f 77 3d 74 68 69 73 3b 0a 74 72 79 7b 0a 5f 2e 5f 46 5f 74 6f 67 67 6c 65 73 5f 69 6e 69 74 69 61 6c 69 7a 65 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 28 74 79 70 65 6f
                                                    Data Ascii: 7620<html><head><script nonce="hgHrG9d5O2hRoFZyPg5swA">"use strict";this.default_AccountsDomaincookiesCheckconnectionJs=this.default_AccountsDomaincookiesCheckconnectionJs||{};(function(_){var window=this;try{_._F_toggles_initialize=function(a){(typeo
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 54 72 69 64 65 6e 74 5c 2f 28 5c 64 2e 5c 64 29 2f 2e 65 78 65 63 28 62 29 2c 0a 63 5b 31 5d 3d 3d 22 37 2e 30 22 29 69 66 28 62 26 26 62 5b 31 5d 29 73 77 69 74 63 68 28 62 5b 31 5d 29 7b 63 61 73 65 20 22 34 2e 30 22 3a 61 3d 22 38 2e 30 22 3b 62 72 65 61 6b 3b 63 61 73 65 20 22 35 2e 30 22 3a 61 3d 22 39 2e 30 22 3b 62 72 65 61 6b 3b 63 61 73 65 20 22 36 2e 30 22 3a 61 3d 22 31 30 2e 30 22 3b 62 72 65 61 6b 3b 63 61 73 65 20 22 37 2e 30 22 3a 61 3d 22 31 31 2e 30 22 7d 65 6c 73 65 20 61 3d 22 37 2e 30 22 3b 65 6c 73 65 20 61 3d 63 5b 31 5d 3b 62 3d 61 7d 65 6c 73 65 20 62 3d 22 22 3b 72 65 74 75 72 6e 20 62 7d 76 61 72 20 64 3d 52 65 67 45 78 70 28 22 28 5b 41 2d 5a 5d 5b 5c 5c 77 20 5d 2b 29 2f 28 5b 5e 5c 5c 73 5d 2b 29 5c 5c 73 2a 28 3f 3a 5c 5c 28
                                                    Data Ascii: Trident\/(\d.\d)/.exec(b),c[1]=="7.0")if(b&&b[1])switch(b[1]){case "4.0":a="8.0";break;case "5.0":a="9.0";break;case "6.0":a="10.0";break;case "7.0":a="11.0"}else a="7.0";else a=c[1];b=a}else b="";return b}var d=RegExp("([A-Z][\\w ]+)/([^\\s]+)\\s*(?:\\(
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 74 63 68 28 74 79 70 65 6f 66 20 61 29 7b 63 61 73 65 20 22 6e 75 6d 62 65 72 22 3a 72 65 74 75 72 6e 20 69 73 46 69 6e 69 74 65 28 61 29 3f 61 3a 53 74 72 69 6e 67 28 61 29 3b 63 61 73 65 20 22 62 69 67 69 6e 74 22 3a 72 65 74 75 72 6e 28 41 61 3f 0a 61 3e 3d 42 61 26 26 61 3c 3d 43 61 3a 61 5b 30 5d 3d 3d 3d 22 2d 22 3f 75 61 28 61 2c 44 61 29 3a 75 61 28 61 2c 45 61 29 29 3f 4e 75 6d 62 65 72 28 61 29 3a 53 74 72 69 6e 67 28 61 29 3b 63 61 73 65 20 22 62 6f 6f 6c 65 61 6e 22 3a 72 65 74 75 72 6e 20 61 3f 31 3a 30 3b 63 61 73 65 20 22 6f 62 6a 65 63 74 22 3a 69 66 28 61 29 69 66 28 41 72 72 61 79 2e 69 73 41 72 72 61 79 28 61 29 29 7b 69 66 28 43 28 61 29 29 72 65 74 75 72 6e 7d 65 6c 73 65 20 69 66 28 46 61 26 26 61 21 3d 6e 75 6c 6c 26 26 61 20 69 6e
                                                    Data Ascii: tch(typeof a){case "number":return isFinite(a)?a:String(a);case "bigint":return(Aa?a>=Ba&&a<=Ca:a[0]==="-"?ua(a,Da):ua(a,Ea))?Number(a):String(a);case "boolean":return a?1:0;case "object":if(a)if(Array.isArray(a)){if(C(a))return}else if(Fa&&a!=null&&a in
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 7b 76 61 72 20 62 3b 69 66 28 61 26 26 28 62 3d 51 61 29 21 3d 6e 75 6c 6c 26 26 62 2e 68 61 73 28 61 29 26 26 28 62 3d 61 2e 43 29 29 66 6f 72 28 76 61 72 20 63 3d 30 3b 63 3c 62 2e 6c 65 6e 67 74 68 3b 63 2b 2b 29 7b 76 61 72 20 64 3d 62 5b 63 5d 3b 69 66 28 63 3d 3d 3d 62 2e 6c 65 6e 67 74 68 2d 31 26 26 41 28 64 29 29 66 6f 72 28 76 61 72 20 65 20 69 6e 20 64 29 7b 76 61 72 20 66 3d 64 5b 65 5d 3b 41 72 72 61 79 2e 69 73 41 72 72 61 79 28 66 29 26 26 0a 52 61 28 66 2c 61 29 7d 65 6c 73 65 20 41 72 72 61 79 2e 69 73 41 72 72 61 79 28 64 29 26 26 52 61 28 64 2c 61 29 7d 61 3d 45 3f 61 2e 43 3a 4d 61 28 61 2e 43 2c 50 61 2c 76 6f 69 64 20 30 2c 76 6f 69 64 20 30 2c 21 31 29 3b 65 3d 21 45 3b 69 66 28 62 3d 61 2e 6c 65 6e 67 74 68 29 7b 64 3d 61 5b 62 2d
                                                    Data Ascii: {var b;if(a&&(b=Qa)!=null&&b.has(a)&&(b=a.C))for(var c=0;c<b.length;c++){var d=b[c];if(c===b.length-1&&A(d))for(var e in d){var f=d[e];Array.isArray(f)&&Ra(f,a)}else Array.isArray(d)&&Ra(d,a)}a=E?a.C:Ma(a.C,Pa,void 0,void 0,!1);e=!E;if(b=a.length){d=a[b-
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 6f 6c 2e 69 74 65 72 61 74 6f 72 22 2c 66 75 6e 63 74 69 6f 6e 28 61 29 7b 69 66 28 61 29 72 65 74 75 72 6e 20 61 3b 61 3d 53 79 6d 62 6f 6c 28 22 63 22 29 3b 66 6f 72 28 76 61 72 20 62 3d 22 41 72 72 61 79 20 49 6e 74 38 41 72 72 61 79 20 55 69 6e 74 38 41 72 72 61 79 20 55 69 6e 74 38 43 6c 61 6d 70 65 64 41 72 72 61 79 20 49 6e 74 31 36 41 72 72 61 79 20 55 69 6e 74 31 36 41 72 72 61 79 20 49 6e 74 33 32 41 72 72 61 79 20 55 69 6e 74 33 32 41 72 72 61 79 20 46 6c 6f 61 74 33 32 41 72 72 61 79 20 46 6c 6f 61 74 36 34 41 72 72 61 79 22 2e 73 70 6c 69 74 28 22 20 22 29 2c 63 3d 30 3b 63 3c 62 2e 6c 65 6e 67 74 68 3b 63 2b 2b 29 7b 76 61 72 20 64 3d 57 61 5b 62 5b 63 5d 5d 3b 74 79 70 65 6f 66 20 64 3d 3d 3d 22 66 75 6e 63 74 69 6f 6e 22 26 26 74 79 70 65
                                                    Data Ascii: ol.iterator",function(a){if(a)return a;a=Symbol("c");for(var b="Array Int8Array Uint8Array Uint8ClampedArray Int16Array Uint16Array Int32Array Uint32Array Float32Array Float64Array".split(" "),c=0;c<b.length;c++){var d=Wa[b[c]];typeof d==="function"&&type
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 29 3b 65 28 22 66 72 65 65 7a 65 22 29 3b 65 28 22 70 72 65 76 65 6e 74 45 78 74 65 6e 73 69 6f 6e 73 22 29 3b 65 28 22 73 65 61 6c 22 29 3b 76 61 72 20 68 3d 30 2c 67 3d 66 75 6e 63 74 69 6f 6e 28 6b 29 7b 74 68 69 73 2e 67 3d 28 68 2b 3d 4d 61 74 68 2e 72 61 6e 64 6f 6d 28 29 2b 31 29 2e 74 6f 53 74 72 69 6e 67 28 29 3b 69 66 28 6b 29 7b 6b 3d 48 28 6b 29 3b 66 6f 72 28 76 61 72 20 6c 3b 21 28 6c 3d 6b 2e 6e 65 78 74 28 29 29 2e 64 6f 6e 65 3b 29 6c 3d 6c 2e 76 61 6c 75 65 2c 74 68 69 73 2e 73 65 74 28 6c 5b 30 5d 2c 6c 5b 31 5d 29 7d 7d 3b 67 2e 70 72 6f 74 6f 74 79 70 65 2e 73 65 74 3d 66 75 6e 63 74 69 6f 6e 28 6b 2c 6c 29 7b 69 66 28 21 63 28 6b 29 29 74 68 72 6f 77 20 45 72 72 6f 72 28 22 69 22 29 3b 64 28 6b 29 3b 69 66 28 21 49 28 6b 2c 66 29 29
                                                    Data Ascii: );e("freeze");e("preventExtensions");e("seal");var h=0,g=function(k){this.g=(h+=Math.random()+1).toString();if(k){k=H(k);for(var l;!(l=k.next()).done;)l=l.value,this.set(l[0],l[1])}};g.prototype.set=function(k,l){if(!c(k))throw Error("i");d(k);if(!I(k,f))
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 75 72 6e 20 67 2e 76 61 6c 75 65 7d 29 7d 3b 63 2e 70 72 6f 74 6f 74 79 70 65 2e 66 6f 72 45 61 63 68 3d 66 75 6e 63 74 69 6f 6e 28 67 2c 6b 29 7b 66 6f 72 28 76 61 72 20 6c 3d 74 68 69 73 2e 65 6e 74 72 69 65 73 28 29 2c 6d 3b 21 28 6d 3d 6c 2e 6e 65 78 74 28 29 29 2e 64 6f 6e 65 3b 29 6d 3d 0a 6d 2e 76 61 6c 75 65 2c 67 2e 63 61 6c 6c 28 6b 2c 6d 5b 31 5d 2c 6d 5b 30 5d 2c 74 68 69 73 29 7d 3b 63 2e 70 72 6f 74 6f 74 79 70 65 5b 53 79 6d 62 6f 6c 2e 69 74 65 72 61 74 6f 72 5d 3d 63 2e 70 72 6f 74 6f 74 79 70 65 2e 65 6e 74 72 69 65 73 3b 76 61 72 20 64 3d 66 75 6e 63 74 69 6f 6e 28 67 2c 6b 29 7b 76 61 72 20 6c 3d 6b 26 26 74 79 70 65 6f 66 20 6b 3b 6c 3d 3d 22 6f 62 6a 65 63 74 22 7c 7c 6c 3d 3d 22 66 75 6e 63 74 69 6f 6e 22 3f 62 2e 68 61 73 28 6b 29
                                                    Data Ascii: urn g.value})};c.prototype.forEach=function(g,k){for(var l=this.entries(),m;!(m=l.next()).done;)m=m.value,g.call(k,m[1],m[0],this)};c.prototype[Symbol.iterator]=c.prototype.entries;var d=function(g,k){var l=k&&typeof k;l=="object"||l=="function"?b.has(k)
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 61 3f 61 3a 66 75 6e 63 74 69 6f 6e 28 62 29 7b 72 65 74 75 72 6e 20 74 79 70 65 6f 66 20 62 3d 3d 3d 22 6e 75 6d 62 65 72 22 26 26 69 73 4e 61 4e 28 62 29 7d 7d 29 3b 76 61 72 20 66 62 3d 66 62 7c 7c 7b 7d 2c 71 3d 74 68 69 73 7c 7c 73 65 6c 66 2c 67 62 3d 71 2e 5f 46 5f 74 6f 67 67 6c 65 73 7c 7c 5b 5d 2c 68 62 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 61 3d 61 2e 73 70 6c 69 74 28 22 2e 22 29 3b 66 6f 72 28 76 61 72 20 62 3d 71 2c 63 3d 30 3b 63 3c 61 2e 6c 65 6e 67 74 68 3b 63 2b 2b 29 69 66 28 62 3d 62 5b 61 5b 63 5d 5d 2c 62 3d 3d 6e 75 6c 6c 29 72 65 74 75 72 6e 20 6e 75 6c 6c 3b 72 65 74 75 72 6e 20 62 7d 2c 69 62 3d 22 63 6c 6f 73 75 72 65 5f 75 69 64 5f 22 2b 28 4d 61 74 68 2e 72 61 6e 64 6f 6d 28 29 2a 31 45
                                                    Data Ascii: on(a){return a?a:function(b){return typeof b==="number"&&isNaN(b)}});var fb=fb||{},q=this||self,gb=q._F_toggles||[],hb=function(a){a=a.split(".");for(var b=q,c=0;c<a.length;c++)if(b=b[a[c]],b==null)return null;return b},ib="closure_uid_"+(Math.random()*1E
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 74 65 78 74 5f 5f 39 38 34 33 38 32 3d 7b 7d 29 3b 61 2e 5f 5f 63 6c 6f 73 75 72 65 5f 5f 65 72 72 6f 72 5f 5f 63 6f 6e 74 65 78 74 5f 5f 39 38 34 33 38 32 2e 73 65 76 65 72 69 74 79 3d 62 7d 3b 76 61 72 20 71 62 3d 66 75 6e 63 74 69 6f 6e 28 61 2c 62 2c 63 29 7b 63 3d 63 7c 7c 71 3b 76 61 72 20 64 3d 63 2e 6f 6e 65 72 72 6f 72 2c 65 3d 21 21 62 3b 63 2e 6f 6e 65 72 72 6f 72 3d 66 75 6e 63 74 69 6f 6e 28 66 2c 68 2c 67 2c 6b 2c 6c 29 7b 64 26 26 64 28 66 2c 68 2c 67 2c 6b 2c 6c 29 3b 61 28 7b 6d 65 73 73 61 67 65 3a 66 2c 66 69 6c 65 4e 61 6d 65 3a 68 2c 6c 69 6e 65 3a 67 2c 6c 69 6e 65 4e 75 6d 62 65 72 3a 67 2c 63 61 3a 6b 2c 65 72 72 6f 72 3a 6c 7d 29 3b 72 65 74 75 72 6e 20 65 7d 7d 2c 74 62 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 76 61 72 20 62 3d 68
                                                    Data Ascii: text__984382={});a.__closure__error__context__984382.severity=b};var qb=function(a,b,c){c=c||q;var d=c.onerror,e=!!b;c.onerror=function(f,h,g,k,l){d&&d(f,h,g,k,l);a({message:f,fileName:h,line:g,lineNumber:g,ca:k,error:l});return e}},tb=function(a){var b=h
                                                    2024-10-03 16:16:22 UTC1969INData Raw: 22 6e 75 6d 62 65 72 22 3a 66 3d 53 74 72 69 6e 67 28 66 29 3b 62 72 65 61 6b 3b 63 61 73 65 20 22 62 6f 6f 6c 65 61 6e 22 3a 66 3d 66 3f 22 74 72 75 65 22 3a 22 66 61 6c 73 65 22 3b 62 72 65 61 6b 3b 63 61 73 65 20 22 66 75 6e 63 74 69 6f 6e 22 3a 66 3d 28 66 3d 73 62 28 66 29 29 3f 66 3a 22 5b 66 6e 5d 22 3b 62 72 65 61 6b 3b 64 65 66 61 75 6c 74 3a 66 3d 0a 74 79 70 65 6f 66 20 66 7d 66 2e 6c 65 6e 67 74 68 3e 34 30 26 26 28 66 3d 66 2e 73 6c 69 63 65 28 30 2c 34 30 29 2b 22 2e 2e 2e 22 29 3b 63 2e 70 75 73 68 28 66 29 7d 62 2e 70 75 73 68 28 61 29 3b 63 2e 70 75 73 68 28 22 29 5c 6e 22 29 3b 74 72 79 7b 63 2e 70 75 73 68 28 77 62 28 61 2e 63 61 6c 6c 65 72 2c 62 29 29 7d 63 61 74 63 68 28 68 29 7b 63 2e 70 75 73 68 28 22 5b 65 78 63 65 70 74 69 6f 6e
                                                    Data Ascii: "number":f=String(f);break;case "boolean":f=f?"true":"false";break;case "function":f=(f=sb(f))?f:"[fn]";break;default:f=typeof f}f.length>40&&(f=f.slice(0,40)+"...");c.push(f)}b.push(a);c.push(")\n");try{c.push(wb(a.caller,b))}catch(h){c.push("[exception


                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                    5192.168.2.449741142.250.185.1324436884C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:16:24 UTC1017OUTGET /favicon.ico HTTP/1.1
                                                    Host: www.google.com
                                                    Connection: keep-alive
                                                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                    sec-ch-ua-mobile: ?0
                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                    sec-ch-ua-arch: "x86"
                                                    sec-ch-ua-full-version: "117.0.5938.132"
                                                    sec-ch-ua-platform-version: "10.0.0"
                                                    sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                                                    sec-ch-ua-bitness: "64"
                                                    sec-ch-ua-model: ""
                                                    sec-ch-ua-wow64: ?0
                                                    sec-ch-ua-platform: "Windows"
                                                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                    X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiUocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                                                    Sec-Fetch-Site: same-site
                                                    Sec-Fetch-Mode: no-cors
                                                    Sec-Fetch-Dest: image
                                                    Referer: https://accounts.google.com/
                                                    Accept-Encoding: gzip, deflate, br
                                                    Accept-Language: en-US,en;q=0.9
                                                    2024-10-03 16:16:24 UTC705INHTTP/1.1 200 OK
                                                    Accept-Ranges: bytes
                                                    Cross-Origin-Resource-Policy: cross-origin
                                                    Cross-Origin-Opener-Policy-Report-Only: same-origin; report-to="static-on-bigtable"
                                                    Report-To: {"group":"static-on-bigtable","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/static-on-bigtable"}]}
                                                    Content-Length: 5430
                                                    X-Content-Type-Options: nosniff
                                                    Server: sffe
                                                    X-XSS-Protection: 0
                                                    Date: Thu, 03 Oct 2024 15:43:02 GMT
                                                    Expires: Fri, 11 Oct 2024 15:43:02 GMT
                                                    Cache-Control: public, max-age=691200
                                                    Last-Modified: Tue, 22 Oct 2019 18:30:00 GMT
                                                    Content-Type: image/x-icon
                                                    Vary: Accept-Encoding
                                                    Age: 2002
                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                    Connection: close
                                                    2024-10-03 16:16:24 UTC685INData Raw: 00 00 01 00 02 00 10 10 00 00 01 00 20 00 68 04 00 00 26 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 8e 04 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 20 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 30 fd fd fd 96 fd fd fd d8 fd fd fd f9 fd fd fd f9 fd fd fd d7 fd fd fd 94 fe fe fe 2e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fe fe fe 09 fd fd fd 99 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd 95 ff ff ff 08 00 00 00 00 00 00 00 00 00 00 00 00 fe fe fe 09 fd fd fd c1 ff ff ff ff fa fd f9 ff b4 d9 a7 ff 76 ba 5d ff 58 ab 3a ff 58 aa 3a ff 72 b8 59 ff ac d5 9d ff f8 fb f6 ff ff
                                                    Data Ascii: h& ( 0.v]X:X:rY
                                                    2024-10-03 16:16:24 UTC1390INData Raw: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd d8 fd fd fd 99 ff ff ff ff 92 cf fb ff 37 52 ec ff 38 46 ea ff d0 d4 fa ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd 96 fe fe fe 32 ff ff ff ff f9 f9 fe ff 56 62 ed ff 35 43 ea ff 3b 49 eb ff 95 9c f4 ff cf d2 fa ff d1 d4 fa ff 96 9d f4 ff 52 5e ed ff e1 e3 fc ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 30 00 00 00 00 fd fd fd 9d ff ff ff ff e8 ea fd ff 58 63 ee ff 35 43 ea ff 35 43 ea ff 35 43 ea ff 35 43 ea ff 35 43 ea ff 35 43 ea ff 6c 76 f0 ff ff ff ff ff ff ff ff ff fd fd fd 98 00 00 00 00 00 00 00 00 ff ff ff 0a fd fd fd c3 ff ff ff ff f9 f9 fe ff a5 ac f6 ff 5d 69 ee ff 3c 4a
                                                    Data Ascii: 7R8F2Vb5C;IR^0Xc5C5C5C5C5C5Clv]i<J
                                                    2024-10-03 16:16:24 UTC1390INData Raw: ff ff ff ff ff ff ff ff ff ff ff fd fd fd d0 ff ff ff 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fd fd fd 8b ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff b1 d8 a3 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 60 a5 35 ff ca 8e 3e ff f9 c1 9f ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd 87 00 00 00 00 00 00 00 00 00 00 00 00 fe fe fe 25 fd fd fd fb ff ff ff ff ff ff ff ff ff ff ff ff c2 e0 b7 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 6e b6 54 ff 9f ce 8d ff b7 da aa ff b8 db ab ff a5 d2 95 ff 7b bc 64 ff 54 a8 35 ff 53 a8 34 ff 77 a0 37 ff e3 89 41 ff f4 85 42 ff f4 85 42 ff
                                                    Data Ascii: S4S4S4S4S4S4S4S4S4S4S4S4S4S4`5>%S4S4S4S4S4S4nT{dT5S4w7ABB
                                                    2024-10-03 16:16:24 UTC1390INData Raw: ff f4 85 42 ff f4 85 42 ff f4 85 42 ff f4 85 42 ff f4 85 42 ff f4 85 42 ff fb d5 bf ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd ea fd fd fd cb ff ff ff ff ff ff ff ff ff ff ff ff 46 cd fc ff 05 bc fb ff 05 bc fb ff 05 bc fb ff 21 ae f9 ff fb fb ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd c8 fd fd fd 9c ff ff ff ff ff ff ff ff ff ff ff ff 86 df fd ff 05 bc fb ff 05 bc fb ff 15 93 f5 ff 34 49 eb ff b3 b8 f7 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                                                    Data Ascii: BBBBBBF!4I
                                                    2024-10-03 16:16:24 UTC575INData Raw: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd d2 fe fe fe 24 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 0a fd fd fd 8d fd fd fd fc ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd fb fd fd fd 8b fe fe fe 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fe fe fe 27 fd fd fd 9f fd fd fd f7 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                                                    Data Ascii: $'


                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                    6192.168.2.449769172.202.163.200443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:16:25 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=UMfhhdA2rltUCLe&MD=zTzhemOD HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept: */*
                                                    User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                    Host: slscr.update.microsoft.com
                                                    2024-10-03 16:16:26 UTC560INHTTP/1.1 200 OK
                                                    Cache-Control: no-cache
                                                    Pragma: no-cache
                                                    Content-Type: application/octet-stream
                                                    Expires: -1
                                                    Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                    ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                                                    MS-CorrelationId: 5f1fbec8-322e-44a0-8f22-8959663d3cfe
                                                    MS-RequestId: 4afc12e2-452b-477f-b19e-11d64393fe1d
                                                    MS-CV: ouUHMu0S8Uq/W3/E.0
                                                    X-Microsoft-SLSClientCache: 2880
                                                    Content-Disposition: attachment; filename=environment.cab
                                                    X-Content-Type-Options: nosniff
                                                    Date: Thu, 03 Oct 2024 16:16:25 GMT
                                                    Connection: close
                                                    Content-Length: 24490
                                                    2024-10-03 16:16:26 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                                                    Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                                                    2024-10-03 16:16:26 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                                                    Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    7192.168.2.44978413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:16:59 UTC195OUTGET /rules/other-Win32-v19.bundle HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:16:59 UTC561INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:16:59 GMT
                                                    Content-Type: text/plain
                                                    Content-Length: 218853
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public
                                                    Last-Modified: Mon, 30 Sep 2024 13:16:38 GMT
                                                    ETag: "0x8DCE1521DF74B57"
                                                    x-ms-request-id: 90766f9b-701e-006f-578c-15afc4000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161659Z-15767c5fc55whfstvfw43u8fp40000000bag00000000req1
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:16:59 UTC15823INData Raw: 31 30 30 30 76 35 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 22 20 56 3d 22 35 22 20 44 43 3d 22 45 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 52 75 6c 65 45 72 72 6f 72 73 41 67 67 72 65 67 61 74 65 64 22 20 41 54 54 3d 22 66 39 39 38 63 63 35 62 61 34 64 34 34 38 64 36 61 31 65 38 65 39 31 33 66 66 31 38 62 65 39 34 2d 64 64 31 32 32 65 30 61 2d 66 63 66 38 2d 34 64 63 35 2d 39 64 62 62 2d 36 61 66 61 63 35 33 32 35 31 38 33 2d 37 34 30 35 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 53 3d 22 37 30 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 20 50 53 55 22 20
                                                    Data Ascii: 1000v5+<?xml version="1.0" encoding="utf-8"?><R Id="1000" V="5" DC="ESM" EN="Office.Telemetry.RuleErrorsAggregated" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" S="70" DL="A" DCa="PSP PSU"
                                                    2024-10-03 16:16:59 UTC16384INData Raw: 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 42 22 20 49 3d 22 35 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20
                                                    Data Ascii: <S T="1" F="0" /> </L> <R> <V V="400" T="I32" /> </R> </O> </R> </O> </C> <C T="B" I="5" O="false"> <O T="AND"> <L> <O T="GE"> <L>
                                                    2024-10-03 16:16:59 UTC16384INData Raw: 3c 53 20 54 3d 22 33 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 20 20 3c 53 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 53 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 38 32 30 76 33 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 38 32 30 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 43 6f 6e 74 61 63 74 43 61 72 64 50 72 6f 70 65 72 74 69 65 73 43 6f 75 6e 74 73 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d
                                                    Data Ascii: <S T="3" /> </T> <ST> <S T="1" /> </ST></R><$!#>10820v3+<?xml version="1.0" encoding="utf-8"?><R Id="10820" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardPropertiesCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-
                                                    2024-10-03 16:16:59 UTC16384INData Raw: 6e 74 73 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 36 34 22 20 49 3d 22 38 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 45 76 65 6e 74 73 5f 41 76 67 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 41 76 65 72 61 67 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 39 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 41 67 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 30 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a
                                                    Data Ascii: nts" /> </C> <C T="U64" I="8" O="false" N="Events_Avg"> <S T="2" F="Average" /> </C> <C T="U32" I="9" O="true" N="Purged_Age"> <S T="4" F="Count" /> </C> <C T="U32" I="10" O="true" N="Purged_Count"> <S T="5" F="Count" />
                                                    2024-10-03 16:16:59 UTC16384INData Raw: 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 43 61 72 64 5f 56 61 6c 69 64 50 65 72 73 6f 6e 61 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 43 61 72 64 5f 56 61 6c 69 64 4d 61 6e 61 67 65 72 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20
                                                    Data Ascii: </S> <C T="U32" I="0" O="false" N="Count_CreateCard_ValidPersona_False"> <C> <S T="10" /> </C> </C> <C T="U32" I="1" O="false" N="Count_CreateCard_ValidManager_False"> <C> <S T="11" /> </C> </C> <C T="U32"
                                                    2024-10-03 16:16:59 UTC16384INData Raw: 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 39 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 57 61 73 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20
                                                    Data Ascii: _Count"> <C> <S T="31" /> </C> </C> <C T="U32" I="19" O="false" N="Paint_IMsoPersona_WasNull_Count"> <C> <S T="32" /> </C> </C> <C T="U32" I="20" O="false" N="Paint_IMsoPersona_Null_Count"> <C> <S
                                                    2024-10-03 16:16:59 UTC16384INData Raw: 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 52 65 74 72 69 65 76 61 6c 4d 69 6c 6c 69 73 65 63 6f 6e 64 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 32 30 30 22 20 54 3d 22 49 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22
                                                    Data Ascii: <L> <S T="3" F="RetrievalMilliseconds" /> </L> <R> <V V="200" T="I64" /> </R> </O> </L> <R> <O T="LT"> <L> <S T="3"
                                                    2024-10-03 16:17:00 UTC16384INData Raw: 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e 74 65 67 72 61 74 69 6f 6e 46 69 72 73 74 43 61 6c 6c 53 75 63 63 65 73 73 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65
                                                    Data Ascii: </L> <R> <V V="0" T="I32" /> </R> </O> </F> </S> <C T="U32" I="0" O="false" N="Ocom2IUCOfficeIntegrationFirstCallSuccessCount"> <C> <S T="9" /> </C> </C> <C T="U32" I="1" O="false
                                                    2024-10-03 16:17:00 UTC16384INData Raw: 20 54 3d 22 42 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 36 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 54 65 6e 61 6e 74 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 55 73 65 72 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20
                                                    Data Ascii: T="B" /> </R> </O> </F> <F T="6"> <O T="AND"> <L> <S T="3" F="Tenant enabled" /> </L> <R> <O T="EQ"> <L> <S T="3" F="User enabled" />
                                                    2024-10-03 16:17:00 UTC16384INData Raw: 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 36 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 48 74 74 70 53 74 61 74 75 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 34 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54
                                                    Data Ascii: O> </F> <F T="6"> <O T="EQ"> <L> <S T="2" F="HttpStatus" /> </L> <R> <V V="404" T="U32" /> </R> </O> </F> <F T="7"> <O T="AND"> <L> <O T


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    8192.168.2.44978713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:00 UTC192OUTGET /rules/rule120600v4s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:00 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:00 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 2980
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:10 GMT
                                                    ETag: "0x8DC582BA80D96A1"
                                                    x-ms-request-id: b9d87bc3-001e-008d-128c-15d91e000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161700Z-15767c5fc55lghvzbxktxfqntw0000000az000000000am7r
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:00 UTC2980INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 30 22 20 56 3d 22 34 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 44 65 76 69 63 65 43 6f 6e 73 6f 6c 69 64 61 74 65 64 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120600" V="4" DC="SM" EN="Office.System.SystemHealthMetadataDeviceConsolidated" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC"


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    9192.168.2.44978813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:00 UTC192OUTGET /rules/rule120608v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:00 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:00 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 2160
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                                                    ETag: "0x8DC582BA3B95D81"
                                                    x-ms-request-id: 39d43082-801e-00ac-658c-15fd65000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161700Z-15767c5fc55sdcjq8ksxt4n9mc00000000f0000000006zeu
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:00 UTC2160INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 37 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 33 22 20 52 3d 22 31 32 30 36 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 34 22 20 52 3d 22 31 32 30 36 31 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 35 22 20 52 3d 22 31 32 30 36 31 34 22 20 2f 3e 0d 0a 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120608" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <R T="1" R="120609" /> <R T="2" R="120679" /> <R T="3" R="120610" /> <R T="4" R="120612" /> <R T="5" R="120614" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    10192.168.2.44978913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:00 UTC192OUTGET /rules/rule120609v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:00 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:00 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 408
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                                                    ETag: "0x8DC582BB56D3AFB"
                                                    x-ms-request-id: 4b0a31e7-c01e-00ad-448c-15a2b9000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161700Z-15767c5fc55fdfx81a30vtr1fw0000000bng000000009ehv
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:00 UTC408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 38 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 44 64 5d 5b 45 65 5d 5b 4c 6c 5d 5b 4c 6c 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120609" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120682" /> <SR T="2" R="^([Dd][Ee][Ll][Ll])"> <S T="1" F="0" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    11192.168.2.44978513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:00 UTC193OUTGET /rules/rule120402v21s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:00 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:00 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 3788
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
                                                    ETag: "0x8DC582BAC2126A6"
                                                    x-ms-request-id: 1cc2ff82-e01e-0071-478c-1508e7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161700Z-15767c5fc55gq5fmm10nm5qqr80000000bag00000000n17z
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:00 UTC3788INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 34 30 32 22 20 56 3d 22 32 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 55 6e 67 72 61 63 65 66 75 6c 41 70 70 45 78 69 74 44 65 73 6b 74 6f 70 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 43 65 6e 73 75 73 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 22 20 78 6d 6c 6e 73 3d 22 22
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120402" V="21" DC="SM" EN="Office.System.SystemHealthUngracefulAppExitDesktop" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSP" xmlns=""


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    12192.168.2.44978613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:00 UTC192OUTGET /rules/rule224902v2s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:00 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:00 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 450
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:25 GMT
                                                    ETag: "0x8DC582BD4C869AE"
                                                    x-ms-request-id: b9d87bc4-001e-008d-138c-15d91e000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161700Z-15767c5fc55sdcjq8ksxt4n9mc00000000eg000000007qhw
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:00 UTC450INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 32 32 34 39 30 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 62 72 35 71 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 33 22 20 47 3d 22 7b 61 33 36 61 39 37 30 64 2d 34 35 61 39 2d 34 65 30 64 2d 39 63 61 62 2d 32 61 32 33 35 63 63 39 64 37 63 36 7d 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 47 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 4e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="224902" V="2" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120100" /> <UTS T="2" Id="bbr5q" /> <SS T="3" G="{a36a970d-45a9-4e0d-9cab-2a235cc9d7c6}" /> </S> <C T="G" I="0" O="falseN


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    13192.168.2.44979213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:01 UTC192OUTGET /rules/rule120612v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:01 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:01 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 471
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:25 GMT
                                                    ETag: "0x8DC582BB10C598B"
                                                    x-ms-request-id: 24b39cfc-301e-0096-2a8c-15e71d000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161701Z-15767c5fc55xsgnlxyxy40f4m00000000b4g00000000hg2m
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:01 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120612" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    14192.168.2.44979013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:01 UTC192OUTGET /rules/rule120610v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:01 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:01 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 474
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:46 GMT
                                                    ETag: "0x8DC582B9964B277"
                                                    x-ms-request-id: aa8826a4-b01e-0053-608c-15cdf8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161701Z-15767c5fc55fdfx81a30vtr1fw0000000bg000000000vcgk
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:01 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120610" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    15192.168.2.44979113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:01 UTC192OUTGET /rules/rule120611v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:01 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:01 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 415
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:56 GMT
                                                    ETag: "0x8DC582B9F6F3512"
                                                    x-ms-request-id: 757ce4f4-401e-000a-128c-154a7b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161701Z-15767c5fc55d6fcl6x6bw8cpdc0000000b1g00000000yttp
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:01 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4c 6c 5d 5b 45 65 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 56 76 5d 5b 4f 6f 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120611" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <SR T="2" R="([Ll][Ee][Nn][Oo][Vv][Oo])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    16192.168.2.44979313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:01 UTC192OUTGET /rules/rule120613v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:01 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:01 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 632
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                                    ETag: "0x8DC582BB6E3779E"
                                                    x-ms-request-id: 3a0dc1eb-601e-0032-608c-15eebb000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161701Z-15767c5fc55kg97hfq5uqyxxaw0000000b8g00000000fk01
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:01 UTC632INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 48 68 5d 5b 50 70 5d 28 5b 5e 45 5d 7c 24 29 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 33 22 20 52 3d 22 28 5b 48 68 5d 5b 45 65 5d 5b 57 77 5d 5b 4c 6c 5d 5b 45 65 5d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120613" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <SR T="2" R="^([Hh][Pp]([^E]|$))"> <S T="1" F="1" M="Ignore" /> </SR> <SR T="3" R="([Hh][Ee][Ww][Ll][Ee]


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    17192.168.2.44979413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:01 UTC192OUTGET /rules/rule120614v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:01 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:01 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 467
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:08 GMT
                                                    ETag: "0x8DC582BA6C038BC"
                                                    x-ms-request-id: b2393cc3-501e-005b-768c-15d7f7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161701Z-15767c5fc55tsfp92w7yna557w0000000b5g00000000vnn5
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:01 UTC467INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120614" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    18192.168.2.44979513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:02 UTC192OUTGET /rules/rule120615v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:02 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:02 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 407
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:42 GMT
                                                    ETag: "0x8DC582BBAD04B7B"
                                                    x-ms-request-id: 023e3708-a01e-003d-568c-1598d7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161702Z-15767c5fc55lghvzbxktxfqntw0000000awg00000000pk2w
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:02 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 53 73 5d 5b 55 75 5d 5b 53 73 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120615" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <SR T="2" R="([Aa][Ss][Uu][Ss])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    19192.168.2.44979813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:02 UTC192OUTGET /rules/rule120618v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:02 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:02 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 486
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:30 GMT
                                                    ETag: "0x8DC582B9018290B"
                                                    x-ms-request-id: e0871f45-901e-00a0-0d8c-156a6d000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161702Z-15767c5fc55qdcd62bsn50hd6s0000000b1g00000000f117
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:02 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120618" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    20192.168.2.44979713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:02 UTC192OUTGET /rules/rule120617v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:02 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:02 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 427
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:02 GMT
                                                    ETag: "0x8DC582BA310DA18"
                                                    x-ms-request-id: 1cc301ca-e01e-0071-6f8c-1508e7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161702Z-15767c5fc55lghvzbxktxfqntw0000000ayg00000000d5q4
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:02 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 5b 53 73 5d 5b 4f 6f 5d 5b 46 66 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120617" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo][Ss][Oo][Ff][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    21192.168.2.44979613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:02 UTC192OUTGET /rules/rule120616v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:02 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:02 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 486
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                                                    ETag: "0x8DC582BB344914B"
                                                    x-ms-request-id: 1cc301c6-e01e-0071-6b8c-1508e7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161702Z-15767c5fc55jdxmppy6cmd24bn00000003hg000000007rp3
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:02 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120616" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    22192.168.2.44979913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:02 UTC192OUTGET /rules/rule120619v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:02 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:02 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 407
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:41 GMT
                                                    ETag: "0x8DC582B9698189B"
                                                    x-ms-request-id: 023e3944-a01e-003d-708c-1598d7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161702Z-15767c5fc55whfstvfw43u8fp40000000b8g000000010adk
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:02 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 43 63 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120619" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <SR T="2" R="([Aa][Cc][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    23192.168.2.44980113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120621v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 415
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                                                    ETag: "0x8DC582BA41997E3"
                                                    x-ms-request-id: c54fb296-901e-008f-528c-1567a6000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161702Z-15767c5fc552g4w83buhsr3htc0000000bc0000000001auv
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 56 76 5d 5b 4d 6d 5d 5b 57 77 5d 5b 41 61 5d 5b 52 72 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120621" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <SR T="2" R="([Vv][Mm][Ww][Aa][Rr][Ee])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    24192.168.2.44980013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120620v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 469
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                                                    ETag: "0x8DC582BBA701121"
                                                    x-ms-request-id: a68dfe67-f01e-0052-588c-159224000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161703Z-15767c5fc5546rn6ch9zv310e0000000046g00000000k4d0
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC469INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120620" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    25192.168.2.44980313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120623v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 464
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:43 GMT
                                                    ETag: "0x8DC582B97FB6C3C"
                                                    x-ms-request-id: dc68ccfc-201e-006e-438c-15bbe3000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161703Z-15767c5fc55qdcd62bsn50hd6s0000000b2000000000dk2d
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC464INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 47 67 5d 5b 49 69 5d 5b 47 67 5d 5b 41 61 5d 5b 42 62 5d 5b 59 79 5d 5b 54 74 5d 5b 45 65 5d 20 5b 54 74 5d 5b 45 65 5d 5b 43 63 5d 5b 48 68 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 4c 6c 5d 5b 4f 6f 5d 5b 47 67 5d 5b 59 79 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120623" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <SR T="2" R="([Gg][Ii][Gg][Aa][Bb][Yy][Tt][Ee] [Tt][Ee][Cc][Hh][Nn][Oo][Ll][Oo][Gg][Yy])"> <S T="1" F="1" M="Ignor


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    26192.168.2.44980413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120624v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 494
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                                    ETag: "0x8DC582BB7010D66"
                                                    x-ms-request-id: 79ade187-001e-0065-788c-150b73000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161703Z-15767c5fc55gq5fmm10nm5qqr80000000bcg00000000c1wf
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120624" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    27192.168.2.44980213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120622v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 477
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
                                                    ETag: "0x8DC582BB8CEAC16"
                                                    x-ms-request-id: 24b39fc0-301e-0096-298c-15e71d000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161703Z-15767c5fc55sdcjq8ksxt4n9mc00000000hg000000007kpm
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120622" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    28192.168.2.44980513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120625v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 419
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:42 GMT
                                                    ETag: "0x8DC582B9748630E"
                                                    x-ms-request-id: 0da94923-701e-0097-168c-15b8c1000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161703Z-15767c5fc55sdcjq8ksxt4n9mc00000000p0000000004yt2
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 46 66 5d 5b 55 75 5d 5b 4a 6a 5d 5b 49 69 5d 5b 54 74 5d 5b 53 73 5d 5b 55 75 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120625" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <SR T="2" R="([Ff][Uu][Jj][Ii][Tt][Ss][Uu])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    29192.168.2.44980613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120626v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 472
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:53 GMT
                                                    ETag: "0x8DC582B9DACDF62"
                                                    x-ms-request-id: 8e9c869d-201e-000c-4b8c-1579c4000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161703Z-15767c5fc55ncqdn59ub6rndq00000000azg000000008bqx
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120626" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    30192.168.2.44980713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120627v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 404
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:54 GMT
                                                    ETag: "0x8DC582B9E8EE0F3"
                                                    x-ms-request-id: 4f10c824-e01e-0085-1c8c-15c311000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161703Z-15767c5fc55gq5fmm10nm5qqr80000000bf000000000305e
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC404INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4e 6e 5d 5b 45 65 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120627" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <SR T="2" R="^([Nn][Ee][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    31192.168.2.44980813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:03 UTC192OUTGET /rules/rule120628v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:03 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:03 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 468
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:51 GMT
                                                    ETag: "0x8DC582B9C8E04C8"
                                                    x-ms-request-id: 09e6f7ee-001e-0034-548c-15dd04000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161703Z-15767c5fc55rg5b7sh1vuv8t7n0000000bn000000000a0pc
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:03 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120628" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    32192.168.2.44981013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:04 UTC192OUTGET /rules/rule120629v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:04 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:04 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 428
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
                                                    ETag: "0x8DC582BAC4F34CA"
                                                    x-ms-request-id: 82f8b22c-c01e-0014-5a8c-15a6a3000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161704Z-15767c5fc55gq5fmm10nm5qqr80000000bd000000000axaq
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:04 UTC428INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 2d 5b 53 73 5d 5b 54 74 5d 5b 41 61 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120629" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo]-[Ss][Tt][Aa][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                    33192.168.2.4498094.245.163.56443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:04 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=UMfhhdA2rltUCLe&MD=zTzhemOD HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept: */*
                                                    User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                    Host: slscr.update.microsoft.com
                                                    2024-10-03 16:17:04 UTC560INHTTP/1.1 200 OK
                                                    Cache-Control: no-cache
                                                    Pragma: no-cache
                                                    Content-Type: application/octet-stream
                                                    Expires: -1
                                                    Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                    ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                                                    MS-CorrelationId: 99b99cd4-66e3-436f-ac79-0aa5819143ed
                                                    MS-RequestId: bbfefeea-f047-4ae7-b3d9-7e4ae3d7cf12
                                                    MS-CV: Rss7KmH5pESJUyix.0
                                                    X-Microsoft-SLSClientCache: 1440
                                                    Content-Disposition: attachment; filename=environment.cab
                                                    X-Content-Type-Options: nosniff
                                                    Date: Thu, 03 Oct 2024 16:17:04 GMT
                                                    Connection: close
                                                    Content-Length: 30005
                                                    2024-10-03 16:17:04 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                                                    Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                                                    2024-10-03 16:17:04 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                                                    Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    34192.168.2.44981413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:04 UTC192OUTGET /rules/rule120633v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:04 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:04 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 419
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                                                    ETag: "0x8DC582BB32BB5CB"
                                                    x-ms-request-id: c2ca9d4d-801e-0035-458c-15752a000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161704Z-15767c5fc55qdcd62bsn50hd6s0000000b4g000000003c3q
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:04 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 53 73 5d 5b 41 61 5d 5b 4d 6d 5d 5b 53 73 5d 5b 55 75 5d 5b 4e 6e 5d 5b 47 67 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120633" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <SR T="2" R="([Ss][Aa][Mm][Ss][Uu][Nn][Gg])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    35192.168.2.44981113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:04 UTC192OUTGET /rules/rule120630v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:04 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:04 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 499
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:45 GMT
                                                    ETag: "0x8DC582B98CEC9F6"
                                                    x-ms-request-id: 30fd46b0-d01e-00a1-368c-1535b1000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161704Z-15767c5fc55w69c2zvnrz0gmgw0000000bm0000000001h2w
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:04 UTC499INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120630" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    36192.168.2.44981513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:05 UTC192OUTGET /rules/rule120634v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:05 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:05 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 494
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
                                                    ETag: "0x8DC582BB8972972"
                                                    x-ms-request-id: 831ef799-b01e-0098-7b8c-15cead000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161705Z-15767c5fc5546rn6ch9zv310e0000000046000000000nxau
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:05 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120634" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120633" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    37192.168.2.44981613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:05 UTC192OUTGET /rules/rule120635v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:05 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:05 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 420
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:53 GMT
                                                    ETag: "0x8DC582B9DAE3EC0"
                                                    x-ms-request-id: a7623418-001e-00a2-348c-15d4d5000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161705Z-15767c5fc55w69c2zvnrz0gmgw0000000bk0000000005qm4
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:05 UTC420INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 54 74 5d 5b 4f 6f 5d 5b 53 73 5d 5b 48 68 5d 5b 49 69 5d 5b 42 62 5d 5b 41 61 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120635" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120633" /> <SR T="2" R="^([Tt][Oo][Ss][Hh][Ii][Bb][Aa])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    38192.168.2.44981713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:05 UTC192OUTGET /rules/rule120636v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:05 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:05 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 472
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:52 GMT
                                                    ETag: "0x8DC582B9D43097E"
                                                    x-ms-request-id: 4b0a3852-c01e-00ad-3b8c-15a2b9000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161705Z-15767c5fc55gs96cphvgp5f5vc0000000b2000000000xaur
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:05 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120636" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120635" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    39192.168.2.44981313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:06 UTC192OUTGET /rules/rule120632v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:06 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:06 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 471
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                                                    ETag: "0x8DC582BB5815C4C"
                                                    x-ms-request-id: 75493038-e01e-00aa-508c-15ceda000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161706Z-15767c5fc55fdfx81a30vtr1fw0000000bqg000000000mz0
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:06 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120632" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    40192.168.2.44981213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:06 UTC192OUTGET /rules/rule120631v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:06 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:06 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 415
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                    ETag: "0x8DC582B988EBD12"
                                                    x-ms-request-id: 6a901ce3-301e-005d-708c-15e448000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161706Z-15767c5fc55fdfx81a30vtr1fw0000000bqg000000000mz1
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:06 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 48 68 5d 5b 55 75 5d 5b 41 61 5d 5b 57 77 5d 5b 45 65 5d 5b 49 69 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120631" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <SR T="2" R="([Hh][Uu][Aa][Ww][Ee][Ii])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    41192.168.2.44981813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:06 UTC192OUTGET /rules/rule120637v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:06 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:06 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 427
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:12 GMT
                                                    ETag: "0x8DC582BA909FA21"
                                                    x-ms-request-id: eccf174e-001e-0079-238c-1512e8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161706Z-15767c5fc554wklc0x4mc5pq0w0000000bgg00000000u16a
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:06 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 41 61 5d 5b 4e 6e 5d 5b 41 61 5d 5b 53 73 5d 5b 4f 6f 5d 5b 4e 6e 5d 5b 49 69 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120637" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120635" /> <SR T="2" R="([Pp][Aa][Nn][Aa][Ss][Oo][Nn][Ii][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    42192.168.2.44982013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:06 UTC192OUTGET /rules/rule120639v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:06 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:06 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 423
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:36 GMT
                                                    ETag: "0x8DC582BB7564CE8"
                                                    x-ms-request-id: bb2e28bd-501e-0016-0b8c-15181b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161706Z-15767c5fc554w2fgapsyvy8ua00000000as000000000gw8f
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:06 UTC423INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 44 64 5d 5b 59 79 5d 5b 4e 6e 5d 5b 41 61 5d 5b 42 62 5d 5b 4f 6f 5d 5b 4f 6f 5d 5b 4b 6b 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120639" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120637" /> <SR T="2" R="([Dd][Yy][Nn][Aa][Bb][Oo][Oo][Kk])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    43192.168.2.44981913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:06 UTC192OUTGET /rules/rule120638v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:06 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:06 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 486
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:35 GMT
                                                    ETag: "0x8DC582B92FCB436"
                                                    x-ms-request-id: 76615707-c01e-0082-6a8c-15af72000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161706Z-15767c5fc55472x4k7dmphmadg0000000b00000000006py0
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:06 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120638" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120637" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    44192.168.2.44982213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:07 UTC192OUTGET /rules/rule120641v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:07 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:07 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 404
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:39 GMT
                                                    ETag: "0x8DC582B95C61A3C"
                                                    x-ms-request-id: 0dcb6c6d-e01e-0003-668c-150fa8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161707Z-15767c5fc55sdcjq8ksxt4n9mc00000000eg000000007qwx
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:07 UTC404INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4d 6d 5d 5b 53 73 5d 5b 49 69 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120641" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120639" /> <SR T="2" R="^([Mm][Ss][Ii])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    45192.168.2.44982113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:07 UTC192OUTGET /rules/rule120640v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:07 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:07 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 478
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:48 GMT
                                                    ETag: "0x8DC582B9B233827"
                                                    x-ms-request-id: 4da5bf60-a01e-0070-668c-15573b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161707Z-15767c5fc55lghvzbxktxfqntw0000000aug00000000xuxq
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:07 UTC478INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120640" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120639" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    46192.168.2.44982313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:07 UTC192OUTGET /rules/rule120642v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:07 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:07 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 468
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:24 GMT
                                                    ETag: "0x8DC582BB046B576"
                                                    x-ms-request-id: 8789ddbb-a01e-0084-6a8c-159ccd000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161707Z-15767c5fc554wklc0x4mc5pq0w0000000bhg00000000p98q
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:07 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120642" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120641" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    47192.168.2.44982413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:07 UTC192OUTGET /rules/rule120643v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:07 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:07 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 400
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:28 GMT
                                                    ETag: "0x8DC582BB2D62837"
                                                    x-ms-request-id: 9bed673a-001e-0046-278c-15da4b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161707Z-15767c5fc554l9xf959gp9cb1s00000005f0000000009a2w
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:07 UTC400INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4c 6c 5d 5b 47 67 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120643" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120641" /> <SR T="2" R="^([Ll][Gg])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S T="


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    48192.168.2.44982513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:07 UTC192OUTGET /rules/rule120644v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:07 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:07 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 479
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:37 GMT
                                                    ETag: "0x8DC582BB7D702D0"
                                                    x-ms-request-id: 772ea1ab-e01e-003c-188c-15c70b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161707Z-15767c5fc55w69c2zvnrz0gmgw0000000bgg00000000amf5
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:07 UTC479INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120644" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120643" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    49192.168.2.44982613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:07 UTC192OUTGET /rules/rule120645v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:07 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:07 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 425
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:40 GMT
                                                    ETag: "0x8DC582BBA25094F"
                                                    x-ms-request-id: 3a0dcc46-601e-0032-6c8c-15eebb000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161707Z-15767c5fc55xsgnlxyxy40f4m00000000b8g0000000021we
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:07 UTC425INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 4d 6d 5d 5b 41 61 5d 5b 5a 7a 5d 5b 4f 6f 5d 5b 4e 6e 5d 20 5b 45 65 5d 5b 43 63 5d 32 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120645" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120643" /> <SR T="2" R="([Aa][Mm][Aa][Zz][Oo][Nn] [Ee][Cc]2)"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    50192.168.2.44982713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:07 UTC192OUTGET /rules/rule120646v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:07 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:07 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 475
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:28 GMT
                                                    ETag: "0x8DC582BB2BE84FD"
                                                    x-ms-request-id: 15fe0b87-a01e-0002-3b8c-155074000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161707Z-15767c5fc55fdfx81a30vtr1fw0000000bqg000000000n2d
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:07 UTC475INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120646" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120645" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    51192.168.2.44982813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:07 UTC192OUTGET /rules/rule120647v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:08 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:07 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 448
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                                                    ETag: "0x8DC582BB389F49B"
                                                    x-ms-request-id: 1f480944-c01e-002b-018c-156e00000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161707Z-15767c5fc5546rn6ch9zv310e0000000048g00000000a6t1
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:08 UTC448INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 50 70 5d 5b 41 61 5d 5b 43 63 5d 5b 48 68 5d 5b 45 65 5d 20 5b 53 73 5d 5b 4f 6f 5d 5b 46 66 5d 5b 54 74 5d 5b 57 77 5d 5b 41 61 5d 5b 52 72 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120647" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120645" /> <SR T="2" R="([Aa][Pp][Aa][Cc][Hh][Ee] [Ss][Oo][Ff][Tt][Ww][Aa][Rr][Ee])"> <S T="1" F="1" M="Ignore" /> </SR>


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    52192.168.2.44982913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:08 UTC192OUTGET /rules/rule120648v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:08 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:08 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 491
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                    ETag: "0x8DC582B98B88612"
                                                    x-ms-request-id: c54fbac1-901e-008f-588c-1567a6000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161708Z-15767c5fc55v7j95gq2uzq37a00000000bc000000000xvep
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:08 UTC491INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120648" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120647" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    53192.168.2.44983013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:08 UTC192OUTGET /rules/rule120649v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:08 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:08 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 416
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:21 GMT
                                                    ETag: "0x8DC582BAEA4B445"
                                                    x-ms-request-id: 75858473-001e-000b-318c-1515a7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161708Z-15767c5fc55rg5b7sh1vuv8t7n0000000bgg00000000smsu
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:08 UTC416INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 46 66 5d 5b 45 65 5d 5b 44 64 5d 5b 4f 6f 5d 5b 52 72 5d 5b 41 61 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120649" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120647" /> <SR T="2" R="^([Ff][Ee][Dd][Oo][Rr][Aa])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tr


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    54192.168.2.44983113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:08 UTC192OUTGET /rules/rule120651v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:08 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:08 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 415
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:10 GMT
                                                    ETag: "0x8DC582BA80D96A1"
                                                    x-ms-request-id: b9a197f6-401e-0078-3b8c-154d34000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161708Z-15767c5fc554w2fgapsyvy8ua00000000au0000000008d86
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:08 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 47 67 5d 5b 4f 6f 5d 5b 4f 6f 5d 5b 47 67 5d 5b 4c 6c 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120651" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120649" /> <SR T="2" R="([Gg][Oo][Oo][Gg][Ll][Ee])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    55192.168.2.44983213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:08 UTC192OUTGET /rules/rule120650v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:08 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:08 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 479
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                    ETag: "0x8DC582B989EE75B"
                                                    x-ms-request-id: 76252b1b-c01e-0066-488c-15a1ec000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161708Z-15767c5fc55472x4k7dmphmadg0000000aug00000000xfue
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:08 UTC479INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120650" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120649" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    56192.168.2.44983313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:09 UTC192OUTGET /rules/rule120652v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:09 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:09 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 471
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:43 GMT
                                                    ETag: "0x8DC582B97E6FCDD"
                                                    x-ms-request-id: b83a8dc4-f01e-003f-308c-15d19d000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161709Z-15767c5fc55lghvzbxktxfqntw0000000av000000000w9tv
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:09 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120652" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120651" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    57192.168.2.44983413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:09 UTC192OUTGET /rules/rule120653v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:09 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:09 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 419
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:51 GMT
                                                    ETag: "0x8DC582B9C710B28"
                                                    x-ms-request-id: 2f8443ca-b01e-0070-308c-151cc0000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161709Z-15767c5fc55jdxmppy6cmd24bn00000003m00000000020gg
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:09 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 49 69 5d 5b 4e 6e 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 54 74 5d 5b 45 65 5d 5b 4b 6b 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120653" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120651" /> <SR T="2" R="([Ii][Nn][Nn][Oo][Tt][Ee][Kk])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    58192.168.2.44983513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:09 UTC192OUTGET /rules/rule120654v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:09 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:09 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 477
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:05 GMT
                                                    ETag: "0x8DC582BA54DCC28"
                                                    x-ms-request-id: 7be6812e-d01e-008e-528c-15387a000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161709Z-15767c5fc55qdcd62bsn50hd6s0000000b4g000000003cba
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:09 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120654" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120653" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    59192.168.2.44983613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:09 UTC192OUTGET /rules/rule120655v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:09 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:09 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 419
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:37 GMT
                                                    ETag: "0x8DC582BB7F164C3"
                                                    x-ms-request-id: 1f480aea-c01e-002b-028c-156e00000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161709Z-15767c5fc55dtdv4d4saq7t47n0000000b2000000000cg1m
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:09 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4e 6e 5d 5b 49 69 5d 5b 4d 6d 5d 5b 42 62 5d 5b 4f 6f 5d 5b 58 78 5d 5b 58 78 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120655" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120653" /> <SR T="2" R="([Nn][Ii][Mm][Bb][Oo][Xx][Xx])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    60192.168.2.44983713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:09 UTC192OUTGET /rules/rule120656v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:09 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:09 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 477
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                                                    ETag: "0x8DC582BA48B5BDD"
                                                    x-ms-request-id: 7be6821c-d01e-008e-398c-15387a000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161709Z-15767c5fc55n4msds84xh4z67w00000004v000000000z10v
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:09 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120656" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120655" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    61192.168.2.44983813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:09 UTC192OUTGET /rules/rule120657v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:09 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:09 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 419
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:57 GMT
                                                    ETag: "0x8DC582B9FF95F80"
                                                    x-ms-request-id: 16d3a614-701e-0032-288c-15a540000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161709Z-15767c5fc55472x4k7dmphmadg0000000b1g00000000182t
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:09 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4e 6e 5d 5b 55 75 5d 5b 54 74 5d 5b 41 61 5d 5b 4e 6e 5d 5b 49 69 5d 5b 58 78 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120657" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120655" /> <SR T="2" R="([Nn][Uu][Tt][Aa][Nn][Ii][Xx])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    62192.168.2.44983913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:10 UTC192OUTGET /rules/rule120658v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:10 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:10 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 472
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:34 GMT
                                                    ETag: "0x8DC582BB650C2EC"
                                                    x-ms-request-id: aa883537-b01e-0053-4c8c-15cdf8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161710Z-15767c5fc55xsgnlxyxy40f4m00000000b7g000000005ryq
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:10 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120658" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120657" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    63192.168.2.44984013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:10 UTC192OUTGET /rules/rule120659v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:10 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:10 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 468
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                                                    ETag: "0x8DC582BB3EAF226"
                                                    x-ms-request-id: cce0beff-001e-0082-398c-155880000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161710Z-15767c5fc55jdxmppy6cmd24bn00000003e000000000q8bw
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:10 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4f 6f 5d 5b 50 70 5d 5b 45 65 5d 5b 4e 6e 5d 5b 53 73 5d 5b 54 74 5d 5b 41 61 5d 5b 43 63 5d 5b 4b 6b 5d 20 5b 46 66 5d 5b 4f 6f 5d 5b 55 75 5d 5b 4e 6e 5d 5b 44 64 5d 5b 41 61 5d 5b 54 74 5d 5b 49 69 5d 5b 4f 6f 5d 5b 4e 6e 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120659" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120657" /> <SR T="2" R="([Oo][Pp][Ee][Nn][Ss][Tt][Aa][Cc][Kk] [Ff][Oo][Uu][Nn][Dd][Aa][Tt][Ii][Oo][Nn])"> <S T="1" F="1" M="I


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    64192.168.2.44984113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:10 UTC192OUTGET /rules/rule120660v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:10 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:10 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 485
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:39 GMT
                                                    ETag: "0x8DC582BB9769355"
                                                    x-ms-request-id: dc68dac5-201e-006e-298c-15bbe3000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161710Z-15767c5fc55whfstvfw43u8fp40000000bc000000000hfbm
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:10 UTC485INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120660" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120659" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    65192.168.2.44984213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:10 UTC192OUTGET /rules/rule120661v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:10 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:10 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 411
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                    ETag: "0x8DC582B989AF051"
                                                    x-ms-request-id: be018b72-401e-0035-7e8c-1582d8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161710Z-15767c5fc55d6fcl6x6bw8cpdc0000000b6g00000000996f
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:10 UTC411INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4f 6f 5d 5b 56 76 5d 5b 49 69 5d 5b 52 72 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120661" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120659" /> <SR T="2" R="([Oo][Vv][Ii][Rr][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    66192.168.2.44984313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:10 UTC192OUTGET /rules/rule120662v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:10 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:10 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 470
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:42 GMT
                                                    ETag: "0x8DC582BBB181F65"
                                                    x-ms-request-id: 4da5c699-a01e-0070-198c-15573b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161710Z-15767c5fc55rg5b7sh1vuv8t7n0000000bmg00000000cprp
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:10 UTC470INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120662" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120661" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    67192.168.2.44984413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:10 UTC192OUTGET /rules/rule120663v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:10 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:10 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 427
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:32 GMT
                                                    ETag: "0x8DC582BB556A907"
                                                    x-ms-request-id: be018b82-401e-0035-0c8c-1582d8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161710Z-15767c5fc55rg5b7sh1vuv8t7n0000000bh000000000sc8d
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:10 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 41 61 5d 5b 52 72 5d 5b 41 61 5d 5b 4c 6c 5d 5b 4c 6c 5d 5b 45 65 5d 5b 4c 6c 5d 5b 53 73 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120663" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120661" /> <SR T="2" R="([Pp][Aa][Rr][Aa][Ll][Ll][Ee][Ll][Ss])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    68192.168.2.44984513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:10 UTC192OUTGET /rules/rule120664v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:10 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:10 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 502
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                                    ETag: "0x8DC582BB6A0D312"
                                                    x-ms-request-id: 801e2bd2-b01e-0021-6a8c-15cab7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161710Z-15767c5fc55dtdv4d4saq7t47n0000000axg00000000y13z
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:10 UTC502INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120664" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120663" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    69192.168.2.44984713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:11 UTC192OUTGET /rules/rule120665v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:11 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:11 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 407
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:52 GMT
                                                    ETag: "0x8DC582B9D30478D"
                                                    x-ms-request-id: 285c7e33-c01e-008e-718c-157381000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161711Z-15767c5fc55852fxfeh7csa2dn0000000b6g00000000a2qf
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:11 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 53 73 5d 5b 53 73 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120665" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120663" /> <SR T="2" R="([Pp][Ss][Ss][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    70192.168.2.44984613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:11 UTC192OUTGET /rules/rule120666v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:11 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:11 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 474
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                                                    ETag: "0x8DC582BB3F48DAE"
                                                    x-ms-request-id: 1cc309a5-e01e-0071-358c-1508e7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161711Z-15767c5fc552g4w83buhsr3htc0000000bc0000000001bbm
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:11 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120666" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120665" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    71192.168.2.44984913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:11 UTC192OUTGET /rules/rule120668v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:11 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:11 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 469
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                                                    ETag: "0x8DC582BB3CAEBB8"
                                                    x-ms-request-id: 6a902a44-301e-005d-788c-15e448000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161711Z-15767c5fc55sdcjq8ksxt4n9mc00000000h0000000006ymb
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:11 UTC469INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120668" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120667" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    72192.168.2.44984813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:11 UTC192OUTGET /rules/rule120667v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:11 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:11 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 408
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:40 GMT
                                                    ETag: "0x8DC582BB9B6040B"
                                                    x-ms-request-id: 04c46130-501e-0064-028c-151f54000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161711Z-15767c5fc55472x4k7dmphmadg0000000aw000000000scwm
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:11 UTC408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 51 71 5d 5b 45 65 5d 5b 4d 6d 5d 5b 55 75 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120667" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120665" /> <SR T="2" R="^([Qq][Ee][Mm][Uu])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    73192.168.2.44985013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:11 UTC192OUTGET /rules/rule120669v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:11 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:11 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 416
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:32 GMT
                                                    ETag: "0x8DC582BB5284CCE"
                                                    x-ms-request-id: 15fe14b4-a01e-0002-638c-155074000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161711Z-15767c5fc55w69c2zvnrz0gmgw0000000bgg00000000amp7
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:11 UTC416INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 52 72 5d 5b 45 65 5d 5b 44 64 5d 20 5b 48 68 5d 5b 41 61 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120669" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120667" /> <SR T="2" R="([Rr][Ee][Dd] [Hh][Aa][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tr


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    74192.168.2.44985113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:12 UTC192OUTGET /rules/rule120670v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:12 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:12 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 472
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:33 GMT
                                                    ETag: "0x8DC582B91EAD002"
                                                    x-ms-request-id: 4da5c882-a01e-0070-628c-15573b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161712Z-15767c5fc55w69c2zvnrz0gmgw0000000bm0000000001hvn
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:12 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120670" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120669" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    75192.168.2.44985213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:12 UTC192OUTGET /rules/rule120671v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:12 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:12 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 432
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:15 GMT
                                                    ETag: "0x8DC582BAABA2A10"
                                                    x-ms-request-id: 15fe1592-a01e-0002-378c-155074000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161712Z-15767c5fc55n4msds84xh4z67w00000004wg00000000r7x3
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:12 UTC432INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 53 73 5d 5b 55 75 5d 5b 50 70 5d 5b 45 65 5d 5b 52 72 5d 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120671" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120669" /> <SR T="2" R="^([Ss][Uu][Pp][Ee][Rr][Mm][Ii][Cc][Rr][Oo])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    76192.168.2.44985413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:12 UTC192OUTGET /rules/rule120673v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:12 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:12 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 427
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:31 GMT
                                                    ETag: "0x8DC582BB464F255"
                                                    x-ms-request-id: 9bed6e8e-001e-0046-5b8c-15da4b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161712Z-15767c5fc55w69c2zvnrz0gmgw0000000bbg000000010zxy
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:12 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 54 74 5d 5b 48 68 5d 5b 49 69 5d 5b 4e 6e 5d 5b 50 70 5d 5b 55 75 5d 5b 54 74 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120673" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120671" /> <SR T="2" R="([Tt][Hh][Ii][Nn][Pp][Uu][Tt][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    77192.168.2.44985313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:12 UTC192OUTGET /rules/rule120672v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:12 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:12 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 475
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                                                    ETag: "0x8DC582BBA740822"
                                                    x-ms-request-id: b9a19b13-401e-0078-148c-154d34000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161712Z-15767c5fc55n4msds84xh4z67w00000004zg00000000aew0
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:12 UTC475INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120672" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120671" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    78192.168.2.44985513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:12 UTC192OUTGET /rules/rule120674v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:12 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:12 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 474
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                                                    ETag: "0x8DC582BA4037B0D"
                                                    x-ms-request-id: e08726cd-901e-00a0-738c-156a6d000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161712Z-15767c5fc55jdxmppy6cmd24bn00000003fg00000000fs8r
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:12 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120674" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120673" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    79192.168.2.44985713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:12 UTC192OUTGET /rules/rule120675v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:12 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:12 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 419
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:08 GMT
                                                    ETag: "0x8DC582BA6CF78C8"
                                                    x-ms-request-id: 766164d5-c01e-0082-668c-15af72000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161712Z-15767c5fc55w69c2zvnrz0gmgw0000000bk0000000005qwx
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:12 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 55 75 5d 5b 50 70 5d 5b 43 63 5d 5b 4c 6c 5d 5b 4f 6f 5d 5b 55 75 5d 5b 44 64 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120675" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120673" /> <SR T="2" R="([Uu][Pp][Cc][Ll][Oo][Uu][Dd])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    80192.168.2.44985813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:12 UTC192OUTGET /rules/rule120676v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:13 UTC491INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:12 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 472
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                    ETag: "0x8DC582B984BF177"
                                                    x-ms-request-id: dcc4dd0d-f01e-0099-7c8c-159171000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161712Z-15767c5fc55n4msds84xh4z67w00000004w000000000t4eh
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:13 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120676" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120675" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    81192.168.2.44986013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:13 UTC192OUTGET /rules/rule120678v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:13 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:13 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 468
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                                                    ETag: "0x8DC582BBA642BF4"
                                                    x-ms-request-id: 4a2177bf-401e-00a3-638c-158b09000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161713Z-15767c5fc554l9xf959gp9cb1s00000005d000000000hu9h
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:13 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120678" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120677" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    82192.168.2.44985913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:13 UTC192OUTGET /rules/rule120677v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:13 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:13 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 405
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:37 GMT
                                                    ETag: "0x8DC582B942B6AFF"
                                                    x-ms-request-id: d59d44fd-601e-003e-698c-153248000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161713Z-15767c5fc55gs96cphvgp5f5vc0000000b700000000089km
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:13 UTC405INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5e 5b 58 78 5d 5b 45 65 5d 5b 4e 6e 5d 24 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120677" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120675" /> <SR T="2" R="(^[Xx][Ee][Nn]$)"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    83192.168.2.44986113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:13 UTC192OUTGET /rules/rule120679v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:13 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:13 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 174
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:33 GMT
                                                    ETag: "0x8DC582B91D80E15"
                                                    x-ms-request-id: 4da5cae8-a01e-0070-0e8c-15573b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161713Z-15767c5fc55852fxfeh7csa2dn0000000b70000000008y74
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:13 UTC174INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 37 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120679" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120677" /> </S> <T> <S T="1" /> </T></R>


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    84192.168.2.44986213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:13 UTC192OUTGET /rules/rule120680v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:13 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:13 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1952
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:39 GMT
                                                    ETag: "0x8DC582B956B0F3D"
                                                    x-ms-request-id: 1cc30b66-e01e-0071-368c-1508e7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161713Z-15767c5fc554wklc0x4mc5pq0w0000000bqg000000000hg9
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:13 UTC1952INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 31 22 20 47 3d 22 7b 62 31 36 37 36 61 63 33 2d 37 66 65 65 2d 34 34 61 39 2d 39 61 30 65 2d 64 62 62 30 62 34 39 36 65 66 61 35 7d 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 38 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 33 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120680" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <SS T="1" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" /> <R T="2" R="120682" /> <F T="3"> <O T="LT"> <L>


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    85192.168.2.44986313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:13 UTC192OUTGET /rules/rule120681v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:13 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:13 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 958
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:58 GMT
                                                    ETag: "0x8DC582BA0A31B3B"
                                                    x-ms-request-id: 8e9c9a52-201e-000c-6b8c-1579c4000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161713Z-15767c5fc5546rn6ch9zv310e0000000047000000000gxbz
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:13 UTC958INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 38 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 38 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 33 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120681" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <R T="1" R="120608" /> <R T="2" R="120680" /> <TH T="3"> <O T="AND"> <L> <O T="EQ"> <L>


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    86192.168.2.44986413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:13 UTC192OUTGET /rules/rule120682v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:13 UTC470INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:13 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 501
                                                    Connection: close
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:18 GMT
                                                    ETag: "0x8DC582BACFDAACD"
                                                    x-ms-request-id: 0da9586c-701e-0097-318c-15b8c1000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161713Z-15767c5fc55ncqdn59ub6rndq00000000azg000000008c6g
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:13 UTC501INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 31 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 74 61 72 74 75 70 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 33 22 20 47 3d 22 7b 62 31 36 37 36 61 63 33 2d 37 66 65 65 2d 34 34 61 39 2d 39 61 30 65 2d 64 62 62 30 62 34 39 36 65 66 61 35 7d 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120682" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <A T="1" E="TelemetryStartup" /> <R T="2" R="120100" /> <SS T="3" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" /> </S> <C T="


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    87192.168.2.44986513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:13 UTC193OUTGET /rules/rule120602v10s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:14 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:13 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 2592
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                                                    ETag: "0x8DC582BB5B890DB"
                                                    x-ms-request-id: b9a19cb7-401e-0078-068c-154d34000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161713Z-15767c5fc55jdxmppy6cmd24bn00000003f000000000k322
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:14 UTC2592INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 32 22 20 56 3d 22 31 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 6e 64 4c 61 6e 67 75 61 67 65 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120602" V="10" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAndLanguage" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    88192.168.2.44986613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:14 UTC192OUTGET /rules/rule120601v3s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:14 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:14 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 3342
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:25:34 GMT
                                                    ETag: "0x8DC582B927E47E9"
                                                    x-ms-request-id: 1cc30bd5-e01e-0071-1a8c-1508e7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161714Z-15767c5fc552g4w83buhsr3htc0000000b9g00000000bgn7
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:14 UTC3342INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 31 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 4f 53 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120601" V="3" DC="SM" EN="Office.System.SystemHealthMetadataOS" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC" xmlns=""> <RI


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    89192.168.2.44986713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:14 UTC193OUTGET /rules/rule224901v11s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:14 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:14 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 2284
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:13 GMT
                                                    ETag: "0x8DC582BCD58BEEE"
                                                    x-ms-request-id: 82f8c3b9-c01e-0014-418c-15a6a3000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161714Z-15767c5fc554w2fgapsyvy8ua00000000ap000000000w31s
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:14 UTC2284INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 32 32 34 39 30 31 22 20 56 3d 22 31 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4c 69 63 65 6e 73 69 6e 67 2e 4f 66 66 69 63 65 43 6c 69 65 6e 74 4c 69 63 65 6e 73 69 6e 67 2e 44 6f 4c 69 63 65 6e 73 65 56 61 6c 69 64 61 74 69 6f 6e 22 20 41 54 54 3d 22 63 31 61 30 64 62 30 31 32 37 39 36 34 36 37 34 61 30 64 36 32 66 64 65 35 61 62 30 66 65 36 32 2d 36 65 63 34 61 63 34 35 2d 63 65 62 63 2d 34 66 38 30 2d 61 61 38 33 2d 62 36 62 39 64 33 61 38 36 65 64 37 2d 37 37 31 39 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 43 65 6e 73 75 73 22 20 54 3d 22 55 70 6c 6f 61 64 2d 4d 65 64 69 75 6d 22
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="224901" V="11" DC="SM" EN="Office.Licensing.OfficeClientLicensing.DoLicenseValidation" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalCensus" T="Upload-Medium"


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    90192.168.2.44986813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:14 UTC191OUTGET /rules/rule90401v3s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:14 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:14 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1250
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:41 GMT
                                                    ETag: "0x8DC582BDE4487AA"
                                                    x-ms-request-id: 09e7054a-001e-0034-1b8c-15dd04000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161714Z-15767c5fc55rv8zjq9dg0musxg0000000b5000000000y4x0
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:14 UTC1250INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 39 30 34 30 31 22 20 56 3d 22 33 22 20 44 43 3d 22 45 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 53 61 6d 70 6c 69 6e 67 50 6f 6c 69 63 79 22 20 41 54 54 3d 22 66 39 39 38 63 63 35 62 61 34 64 34 34 38 64 36 61 31 65 38 65 39 31 33 66 66 31 38 62 65 39 34 2d 64 64 31 32 32 65 30 61 2d 66 63 66 38 2d 34 64 63 35 2d 39 64 62 62 2d 36 61 66 61 63 35 33 32 35 31 38 33 2d 37 34 30 35 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 4d 65 74 61 64 61 74 61 22 20 2f 3e 0d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="90401" V="3" DC="ESM" EN="Office.Telemetry.SamplingPolicy" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" DL="A" DCa="PSP PSU" xmlns=""> <RIS> <RI N="Metadata" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    91192.168.2.44986913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:14 UTC192OUTGET /rules/rule701201v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:14 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:14 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1393
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:51 GMT
                                                    ETag: "0x8DC582BE3E55B6E"
                                                    x-ms-request-id: b23951fc-501e-005b-2a8c-15d7f7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161714Z-15767c5fc55gq5fmm10nm5qqr80000000b9000000000u37q
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:14 UTC1393INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 58 61 6d 6c 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 58 61 6d 6c 22
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Xaml.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenXaml"


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    92192.168.2.44987113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:15 UTC192OUTGET /rules/rule700201v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:15 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:15 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1393
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:50 GMT
                                                    ETag: "0x8DC582BE39DFC9B"
                                                    x-ms-request-id: 7afec079-601e-000d-468c-152618000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161715Z-15767c5fc554l9xf959gp9cb1s00000005c000000000neuf
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:15 UTC1393INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 32 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 57 6f 72 64 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 57 6f 72 64 22
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Word.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenWord"


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    93192.168.2.44987013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:15 UTC192OUTGET /rules/rule701200v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:15 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:15 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1356
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:38 GMT
                                                    ETag: "0x8DC582BDC681E17"
                                                    x-ms-request-id: b9a19e00-401e-0078-388c-154d34000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161715Z-15767c5fc55gs96cphvgp5f5vc0000000b5g00000000fukp
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:15 UTC1356INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 58 61 6d 6c 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 58 61 6d 6c 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Xaml" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenXaml" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    94192.168.2.44987313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:15 UTC192OUTGET /rules/rule702351v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:15 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:15 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1395
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                                                    ETag: "0x8DC582BE017CAD3"
                                                    x-ms-request-id: a68e09c4-f01e-0052-148c-159224000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161715Z-15767c5fc55tsfp92w7yna557w0000000b7000000000p81w
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:15 UTC1395INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 6f 69 63 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 6f 69 63
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Voice.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVoic


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    95192.168.2.44987413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:15 UTC192OUTGET /rules/rule702350v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:15 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:15 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1358
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:54 GMT
                                                    ETag: "0x8DC582BE6431446"
                                                    x-ms-request-id: 6a90313a-301e-005d-1a8c-15e448000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161715Z-15767c5fc55tsfp92w7yna557w0000000bag0000000072hz
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:15 UTC1358INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 6f 69 63 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 6f 69 63 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Voice" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVoice" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    96192.168.2.44987513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:15 UTC192OUTGET /rules/rule701251v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:15 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:15 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1395
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:41 GMT
                                                    ETag: "0x8DC582BDE12A98D"
                                                    x-ms-request-id: 1392789d-401e-0047-0e8c-158597000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161715Z-15767c5fc55tsfp92w7yna557w0000000b5g00000000vpvf
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:15 UTC1395INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 69 73 69 6f 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 69 73 69
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701251" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Visio.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVisi


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    97192.168.2.44987613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:15 UTC192OUTGET /rules/rule701250v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:15 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:15 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1358
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                                                    ETag: "0x8DC582BE022ECC5"
                                                    x-ms-request-id: a76247f8-001e-00a2-558c-15d4d5000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161715Z-15767c5fc55kg97hfq5uqyxxaw0000000b5g00000000tfr5
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:15 UTC1358INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 69 73 69 6f 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 69 73 69 6f 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701250" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Visio" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVisio" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    98192.168.2.44987713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:16 UTC192OUTGET /rules/rule700051v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:16 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:16 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1389
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                                                    ETag: "0x8DC582BE10A6BC1"
                                                    x-ms-request-id: 7afec1f8-601e-000d-328c-152618000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161716Z-15767c5fc55472x4k7dmphmadg0000000b00000000006qc4
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:16 UTC1389INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 30 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 55 58 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 55 58 22 20 53 3d 22
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700051" V="1" DC="SM" EN="Office.Telemetry.Event.Office.UX.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenUX" S="


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    99192.168.2.44987813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:16 UTC192OUTGET /rules/rule700050v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:16 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:16 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1352
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:01 GMT
                                                    ETag: "0x8DC582BE9DEEE28"
                                                    x-ms-request-id: 92784c80-801e-002a-088c-1531dc000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161716Z-15767c5fc55tsfp92w7yna557w0000000ba0000000008xpz
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:16 UTC1352INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 30 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 55 58 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 55 58 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700050" V="1" DC="SM" EN="Office.Telemetry.Event.Office.UX" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenUX" S="Medium" /> <F T="2"> <O T


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    100192.168.2.44987913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:16 UTC192OUTGET /rules/rule702951v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:16 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:16 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1405
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                                                    ETag: "0x8DC582BE12B5C71"
                                                    x-ms-request-id: 4a217eb8-401e-00a3-218c-158b09000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161716Z-15767c5fc55qdcd62bsn50hd6s0000000b3g0000000075e2
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:16 UTC1405INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 39 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 72 61 6e 73 6c 61 74 6f 72 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702951" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Translator.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToke


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    101192.168.2.44988013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:16 UTC192OUTGET /rules/rule702950v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:16 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:16 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1368
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:40 GMT
                                                    ETag: "0x8DC582BDDC22447"
                                                    x-ms-request-id: c825d9ef-901e-007b-278c-15ac50000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161716Z-15767c5fc55xsgnlxyxy40f4m00000000b5000000000ff7v
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:16 UTC1368INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 39 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 72 61 6e 73 6c 61 74 6f 72 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 72 61 6e 73 6c 61 74 6f 72 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702950" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Translator" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTranslator" S="Medium" /> <F T=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    102192.168.2.44988113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:17 UTC192OUTGET /rules/rule701151v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:17 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:17 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1401
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:45 GMT
                                                    ETag: "0x8DC582BE055B528"
                                                    x-ms-request-id: 6a90350a-301e-005d-348c-15e448000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161717Z-15767c5fc55jdxmppy6cmd24bn00000003m00000000021av
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:17 UTC1401INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 31 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 78 74 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 78 74 41
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701151" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Text.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTextA


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    103192.168.2.44988213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:17 UTC192OUTGET /rules/rule701150v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:17 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:17 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1364
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                                                    ETag: "0x8DC582BE1223606"
                                                    x-ms-request-id: ed356ac5-101e-0046-2b8c-1591b0000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161717Z-15767c5fc554w2fgapsyvy8ua00000000ar000000000n6gs
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:17 UTC1364INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 31 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 78 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 78 74 41 6e 64 46 6f 6e 74 73 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701150" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Text" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTextAndFonts" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    104192.168.2.44988413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:17 UTC192OUTGET /rules/rule702201v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:17 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:17 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1397
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:56 GMT
                                                    ETag: "0x8DC582BE7262739"
                                                    x-ms-request-id: 76616de5-c01e-0082-6f8c-15af72000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161717Z-15767c5fc55qdcd62bsn50hd6s0000000az000000000ut8r
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:17 UTC1397INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 32 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 6c 6c 4d 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 6c
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.TellMe.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTel


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    105192.168.2.44988513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:17 UTC192OUTGET /rules/rule702200v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:17 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:17 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1360
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:40 GMT
                                                    ETag: "0x8DC582BDDEB5124"
                                                    x-ms-request-id: 29534450-901e-0064-768c-15e8a6000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161717Z-15767c5fc55gq5fmm10nm5qqr80000000beg000000004umh
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:17 UTC1360INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 32 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 6c 6c 4d 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 6c 6c 4d 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.TellMe" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTellMe" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    106192.168.2.44988613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:17 UTC192OUTGET /rules/rule700401v2s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:17 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:17 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1403
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:38 GMT
                                                    ETag: "0x8DC582BDCB4853F"
                                                    x-ms-request-id: 6ec2e3f4-801e-007b-208c-15e7ab000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161717Z-15767c5fc55ncqdn59ub6rndq00000000au000000000z9sc
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:17 UTC1403INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 34 30 31 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700401" V="2" DC="SM" EN="Office.Telemetry.Event.Office.Telemetry.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToken


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    107192.168.2.44988713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:17 UTC192OUTGET /rules/rule700400v2s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:17 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:17 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1366
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:36 GMT
                                                    ETag: "0x8DC582BDB779FC3"
                                                    x-ms-request-id: 0da95f5c-701e-0097-318c-15b8c1000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161717Z-15767c5fc55tsfp92w7yna557w0000000b8g00000000gd96
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:17 UTC1366INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 34 30 30 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 6c 65 6d 65 74 72 79 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700400" V="2" DC="SM" EN="Office.Telemetry.Event.Office.Telemetry" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTelemetry" S="Medium" /> <F T="2


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    108192.168.2.44988813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:18 UTC192OUTGET /rules/rule700351v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:18 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:18 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1397
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                                                    ETag: "0x8DC582BDFD43C07"
                                                    x-ms-request-id: 704395e8-201e-005d-718c-15afb3000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161718Z-15767c5fc552g4w83buhsr3htc0000000b7000000000r71z
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:18 UTC1397INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 33 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 79 73
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.System.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSys


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    109192.168.2.44988913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:18 UTC192OUTGET /rules/rule700350v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:18 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:18 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1360
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:40 GMT
                                                    ETag: "0x8DC582BDD74D2EC"
                                                    x-ms-request-id: 8be9c1e7-301e-0052-678c-1565d6000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161718Z-15767c5fc55d6fcl6x6bw8cpdc0000000b7g0000000054gt
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:18 UTC1360INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 33 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 79 73 74 65 6d 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.System" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSystem" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    110192.168.2.44989013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:18 UTC192OUTGET /rules/rule703901v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:19 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:18 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1427
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:53 GMT
                                                    ETag: "0x8DC582BE56F6873"
                                                    x-ms-request-id: dc68e902-201e-006e-0d8c-15bbe3000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161718Z-15767c5fc55rv8zjq9dg0musxg0000000b5000000000y56q
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:19 UTC1427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 39 30 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 65 72 76 69 63 65 61 62 69 6c 69 74 79 4d 61 6e 61 67 65 72 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703901" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ServiceabilityManager.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="Nexu


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    111192.168.2.44989113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:18 UTC192OUTGET /rules/rule703900v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:19 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:18 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1390
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:49 GMT
                                                    ETag: "0x8DC582BE3002601"
                                                    x-ms-request-id: 21dfe39b-001e-0049-468c-155bd5000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161718Z-15767c5fc55sdcjq8ksxt4n9mc00000000f00000000070h5
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:19 UTC1390INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 39 30 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 65 72 76 69 63 65 61 62 69 6c 69 74 79 4d 61 6e 61 67 65 72 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 65 72 76 69 63 65 61 62 69 6c 69 74 79 4d 61 6e 61 67 65 72 22 20 53 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703900" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ServiceabilityManager" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenServiceabilityManager" S=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    112192.168.2.44989313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:19 UTC192OUTGET /rules/rule701500v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:19 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:19 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1364
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:03 GMT
                                                    ETag: "0x8DC582BEB6AD293"
                                                    x-ms-request-id: ba3c7a68-301e-0099-698c-156683000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161719Z-15767c5fc55n4msds84xh4z67w00000004xg00000000mu7p
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:19 UTC1364INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 35 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 65 63 75 72 69 74 79 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 65 63 75 72 69 74 79 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701500" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Security" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSecurity" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    113192.168.2.44989213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:19 UTC192OUTGET /rules/rule701501v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:19 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:19 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1401
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:48 GMT
                                                    ETag: "0x8DC582BE2A9D541"
                                                    x-ms-request-id: 82f8cc24-c01e-0014-3a8c-15a6a3000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161719Z-15767c5fc55852fxfeh7csa2dn0000000b80000000003yk6
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:19 UTC1401INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 35 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 65 63 75 72 69 74 79 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701501" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Security.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenS


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    114192.168.2.44989513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:19 UTC192OUTGET /rules/rule702800v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:19 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:19 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1354
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:45 GMT
                                                    ETag: "0x8DC582BE0662D7C"
                                                    x-ms-request-id: 76253f94-c01e-0066-328c-15a1ec000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161719Z-15767c5fc55dtdv4d4saq7t47n0000000b300000000089r9
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:19 UTC1354INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 38 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 44 58 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 44 58 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702800" V="1" DC="SM" EN="Office.Telemetry.Event.Office.SDX" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSDX" S="Medium" /> <F T="2"> <O


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    115192.168.2.44989413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:19 UTC192OUTGET /rules/rule702801v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:19 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:19 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1391
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:43 GMT
                                                    ETag: "0x8DC582BDF58DC7E"
                                                    x-ms-request-id: 023e591f-a01e-003d-618c-1598d7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161719Z-15767c5fc55dtdv4d4saq7t47n0000000b3g000000006q4v
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:19 UTC1391INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 38 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 44 58 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 44 58 22 20 53
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702801" V="1" DC="SM" EN="Office.Telemetry.Event.Office.SDX.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSDX" S


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    116192.168.2.44987213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:19 UTC192OUTGET /rules/rule700200v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:20 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:20 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1356
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:43 GMT
                                                    ETag: "0x8DC582BDF66E42D"
                                                    x-ms-request-id: 3ef81e2a-f01e-001f-3f8c-155dc8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161720Z-15767c5fc55rg5b7sh1vuv8t7n0000000bq0000000002bat
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:20 UTC1356INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 32 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 57 6f 72 64 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 57 6f 72 64 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Word" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenWord" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    117192.168.2.44989613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:19 UTC192OUTGET /rules/rule703351v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:20 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:20 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1403
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:39 GMT
                                                    ETag: "0x8DC582BDCDD6400"
                                                    x-ms-request-id: 819d4321-f01e-0020-6e8c-15956b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161720Z-15767c5fc55ncqdn59ub6rndq00000000b00000000006ctt
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:20 UTC1403INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 33 35 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 63 72 69 70 74 4c 61 62 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703351" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ScriptLab.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToken


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    118192.168.2.44989713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:20 UTC192OUTGET /rules/rule703350v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:20 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:20 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1366
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:42 GMT
                                                    ETag: "0x8DC582BDF1E2608"
                                                    x-ms-request-id: fb0d4061-601e-0050-198c-152c9c000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161720Z-15767c5fc55rg5b7sh1vuv8t7n0000000bng00000000887g
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:20 UTC1366INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 33 35 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 63 72 69 70 74 4c 61 62 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 63 72 69 70 74 4c 61 62 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703350" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ScriptLab" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenScriptLab" S="Medium" /> <F T="2


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    119192.168.2.44989813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:20 UTC192OUTGET /rules/rule703500v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:20 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:20 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1362
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:43 GMT
                                                    ETag: "0x8DC582BDF497570"
                                                    x-ms-request-id: 7585955c-001e-000b-518c-1515a7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161720Z-15767c5fc55w69c2zvnrz0gmgw0000000bcg00000000wfx1
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:20 UTC1362INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 35 30 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 61 6e 64 62 6f 78 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 61 6e 64 62 6f 78 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703500" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Sandbox" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSandbox" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    120192.168.2.44989913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:20 UTC192OUTGET /rules/rule703501v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:20 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:20 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1399
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:59 GMT
                                                    ETag: "0x8DC582BE8C605FF"
                                                    x-ms-request-id: 831f1653-b01e-0098-198c-15cead000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161720Z-15767c5fc55dtdv4d4saq7t47n0000000ay000000000wy4s
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:20 UTC1399INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 35 30 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 61 6e 64 62 6f 78 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 61
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703501" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Sandbox.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSa


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    121192.168.2.44990113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:20 UTC192OUTGET /rules/rule701800v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:20 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:20 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1366
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:01 GMT
                                                    ETag: "0x8DC582BEA414B16"
                                                    x-ms-request-id: a7582d38-101e-0028-528c-158f64000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161720Z-15767c5fc55jdxmppy6cmd24bn00000003mg000000000bbk
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:20 UTC1366INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 38 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 52 65 73 6f 75 72 63 65 73 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 52 65 73 6f 75 72 63 65 73 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701800" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Resources" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenResources" S="Medium" /> <F T="2


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    122192.168.2.44990013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:20 UTC192OUTGET /rules/rule701801v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:20 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:20 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1403
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:38 GMT
                                                    ETag: "0x8DC582BDC2EEE03"
                                                    x-ms-request-id: 89fd357a-501e-008f-758c-159054000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161720Z-15767c5fc55jdxmppy6cmd24bn00000003d000000000u9d1
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:20 UTC1403INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 38 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 52 65 73 6f 75 72 63 65 73 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701801" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Resources.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToken


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    123192.168.2.44990213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:21 UTC192OUTGET /rules/rule701051v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:21 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:21 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1399
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:47 GMT
                                                    ETag: "0x8DC582BE1CC18CD"
                                                    x-ms-request-id: a68e0dd8-f01e-0052-1d8c-159224000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161721Z-15767c5fc55kg97hfq5uqyxxaw0000000b7000000000n0up
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:21 UTC1399INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 30 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 52 65 6c 65 61 73 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 52 65
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701051" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Release.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenRe


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    124192.168.2.44990413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:21 UTC192OUTGET /rules/rule702751v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:22 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:21 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1403
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:03 GMT
                                                    ETag: "0x8DC582BEB866CDB"
                                                    x-ms-request-id: b2395a75-501e-005b-038c-15d7f7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161721Z-15767c5fc55852fxfeh7csa2dn0000000b4000000000r2rv
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:22 UTC1403INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 37 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 75 62 6c 69 73 68 65 72 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702751" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Publisher.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToken


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    125192.168.2.44990313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:21 UTC192OUTGET /rules/rule701050v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:22 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:21 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1362
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:03 GMT
                                                    ETag: "0x8DC582BEB256F43"
                                                    x-ms-request-id: 757cff4f-401e-000a-528c-154a7b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161721Z-15767c5fc55gs96cphvgp5f5vc0000000b3000000000tx89
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:22 UTC1362INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 30 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 52 65 6c 65 61 73 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 52 65 6c 65 61 73 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701050" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Release" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenRelease" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    126192.168.2.44990613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:22 UTC192OUTGET /rules/rule702301v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:22 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:22 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1399
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:00 GMT
                                                    ETag: "0x8DC582BE976026E"
                                                    x-ms-request-id: 7baaa16d-b01e-0097-4d8c-154f33000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161722Z-15767c5fc55tsfp92w7yna557w0000000b7g00000000n78p
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:22 UTC1399INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 6a 65 63 74 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 72
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702301" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Project.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPr


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    127192.168.2.44990513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:22 UTC192OUTGET /rules/rule702750v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:22 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:22 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1366
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:54 GMT
                                                    ETag: "0x8DC582BE5B7B174"
                                                    x-ms-request-id: 9bed7ce1-001e-0046-4f8c-15da4b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161722Z-15767c5fc55jdxmppy6cmd24bn00000003e000000000q90a
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:22 UTC1366INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 37 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 75 62 6c 69 73 68 65 72 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 75 62 6c 69 73 68 65 72 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702750" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Publisher" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPublisher" S="Medium" /> <F T="2


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    128192.168.2.44990713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:22 UTC192OUTGET /rules/rule702300v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:22 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:22 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1362
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:37 GMT
                                                    ETag: "0x8DC582BDC13EFEF"
                                                    x-ms-request-id: 819d44cb-f01e-0020-6f8c-15956b000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161722Z-15767c5fc55whfstvfw43u8fp40000000bag00000000rfwe
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:22 UTC1362INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 6a 65 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 72 6f 6a 65 63 74 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702300" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Project" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenProject" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    129192.168.2.44990813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule703400v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:23 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:23 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1388
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:37 GMT
                                                    ETag: "0x8DC582BDBD9126E"
                                                    x-ms-request-id: 9c5056bf-f01e-0003-548c-154453000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161723Z-15767c5fc55rv8zjq9dg0musxg0000000b5000000000y5f0
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:23 UTC1388INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 34 30 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 67 72 61 6d 6d 61 62 6c 65 53 75 72 66 61 63 65 73 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 72 6f 67 72 61 6d 6d 61 62 6c 65 53 75 72 66 61 63 65 73 22 20 53 3d 22 4d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703400" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ProgrammableSurfaces" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenProgrammableSurfaces" S="M


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    130192.168.2.44990913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule703401v0s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:23 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:23 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1425
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:55 GMT
                                                    ETag: "0x8DC582BE6BD89A1"
                                                    x-ms-request-id: 89fd37a1-501e-008f-6d8c-159054000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161723Z-15767c5fc55xsgnlxyxy40f4m00000000b1g00000000xx31
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:23 UTC1425INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 34 30 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 67 72 61 6d 6d 61 62 6c 65 53 75 72 66 61 63 65 73 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703401" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ProgrammableSurfaces.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="Nexus


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    131192.168.2.44991013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule702501v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:23 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:23 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1415
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:57 GMT
                                                    ETag: "0x8DC582BE7C66E85"
                                                    x-ms-request-id: 42bb1403-701e-005c-578c-15bb94000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161723Z-15767c5fc55472x4k7dmphmadg0000000azg000000008fey
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:23 UTC1415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 35 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 67 72 61 6d 6d 61 62 69 6c 69 74 79 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702501" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Programmability.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenan


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    132192.168.2.44991113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule702500v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:23 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:23 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1378
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:36 GMT
                                                    ETag: "0x8DC582BDB813B3F"
                                                    x-ms-request-id: be019976-401e-0035-5d8c-1582d8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161723Z-15767c5fc554wklc0x4mc5pq0w0000000bm000000000e0xa
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:23 UTC1378INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 35 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 67 72 61 6d 6d 61 62 69 6c 69 74 79 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 72 6f 67 72 61 6d 6d 61 62 69 6c 69 74 79 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702500" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Programmability" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenProgrammability" S="Medium" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    133192.168.2.44991213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule700501v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:23 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:23 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1405
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:58 GMT
                                                    ETag: "0x8DC582BE89A8F82"
                                                    x-ms-request-id: 56c891cb-f01e-0085-428c-1588ea000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161723Z-15767c5fc55sdcjq8ksxt4n9mc00000000h0000000006z4y
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:23 UTC1405INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 35 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 6f 77 65 72 50 6f 69 6e 74 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700501" V="1" DC="SM" EN="Office.Telemetry.Event.Office.PowerPoint.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToke


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    134192.168.2.44991313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule700500v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:23 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:23 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1368
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:53 GMT
                                                    ETag: "0x8DC582BE51CE7B3"
                                                    x-ms-request-id: 2f845d93-b01e-0070-2f8c-151cc0000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161723Z-15767c5fc55w69c2zvnrz0gmgw0000000be000000000r8bg
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:23 UTC1368INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 35 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 6f 77 65 72 50 6f 69 6e 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 6f 77 65 72 50 6f 69 6e 74 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700500" V="1" DC="SM" EN="Office.Telemetry.Event.Office.PowerPoint" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPowerPoint" S="Medium" /> <F T=


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    135192.168.2.44991413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule702551v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:23 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:23 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1415
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:39 GMT
                                                    ETag: "0x8DC582BDCE9703A"
                                                    x-ms-request-id: 5f7380a8-801e-0015-7b8c-15f97f000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161723Z-15767c5fc55lghvzbxktxfqntw0000000azg000000009t7y
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:23 UTC1415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 35 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 72 73 6f 6e 61 6c 69 7a 61 74 69 6f 6e 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702551" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Personalization.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenan


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    136192.168.2.44991513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule702550v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:24 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:23 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1378
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:53 GMT
                                                    ETag: "0x8DC582BE584C214"
                                                    x-ms-request-id: b612907a-401e-008c-278c-1586c2000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161723Z-15767c5fc55kg97hfq5uqyxxaw0000000b5000000000vap1
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:24 UTC1378INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 35 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 72 73 6f 6e 61 6c 69 7a 61 74 69 6f 6e 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 65 72 73 6f 6e 61 6c 69 7a 61 74 69 6f 6e 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702550" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Personalization" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPersonalization" S="Medium" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    137192.168.2.44991613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:23 UTC192OUTGET /rules/rule701351v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:24 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:24 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1407
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:55 GMT
                                                    ETag: "0x8DC582BE687B46A"
                                                    x-ms-request-id: 2d1829d7-b01e-001e-738c-150214000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161724Z-15767c5fc5546rn6ch9zv310e0000000043g00000000y3w3
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:24 UTC1407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 33 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 72 66 6f 72 6d 61 6e 63 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Performance.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTok


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    138192.168.2.44991713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:24 UTC192OUTGET /rules/rule701350v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:24 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:24 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1370
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:41 GMT
                                                    ETag: "0x8DC582BDE62E0AB"
                                                    x-ms-request-id: be019a9f-401e-0035-518c-1582d8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161724Z-15767c5fc55tsfp92w7yna557w0000000b4g000000010vcg
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:24 UTC1370INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 33 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 72 66 6f 72 6d 61 6e 63 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 65 72 66 6f 72 6d 61 6e 63 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Performance" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPerformance" S="Medium" /> <F


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    139192.168.2.44991913.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:24 UTC192OUTGET /rules/rule702151v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:24 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:24 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1397
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                                                    ETag: "0x8DC582BE156D2EE"
                                                    x-ms-request-id: 36a1620f-001e-0028-0f8c-15c49f000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161724Z-15767c5fc55lghvzbxktxfqntw0000000b20000000001u44
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:24 UTC1397INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 31 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 6f 70 6c 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 65 6f
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702151" V="1" DC="SM" EN="Office.Telemetry.Event.Office.People.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPeo


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    140192.168.2.44992013.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:24 UTC192OUTGET /rules/rule702150v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:24 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:24 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1360
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:07 GMT
                                                    ETag: "0x8DC582BEDC8193E"
                                                    x-ms-request-id: e360128a-801e-0083-498c-15f0ae000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161724Z-15767c5fc55fdfx81a30vtr1fw0000000bm000000000etux
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:24 UTC1360INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 31 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 6f 70 6c 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 65 6f 70 6c 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702150" V="1" DC="SM" EN="Office.Telemetry.Event.Office.People" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPeople" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    141192.168.2.44992113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:24 UTC192OUTGET /rules/rule703001v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:24 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:24 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1406
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:03 GMT
                                                    ETag: "0x8DC582BEB16F27E"
                                                    x-ms-request-id: 4b0a4db7-c01e-00ad-2d8c-15a2b9000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161724Z-15767c5fc55v7j95gq2uzq37a00000000bf000000000htmg
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:24 UTC1406INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 30 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 4d 61 63 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703001" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Outlook.Mac.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTok


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    142192.168.2.44992213.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:24 UTC192OUTGET /rules/rule703000v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:24 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:24 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1369
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:49 GMT
                                                    ETag: "0x8DC582BE32FE1A2"
                                                    x-ms-request-id: 1cc313a1-e01e-0071-4b8c-1508e7000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161724Z-15767c5fc55d6fcl6x6bw8cpdc0000000b5g00000000duqu
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:24 UTC1369INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 30 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 4d 61 63 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 4f 75 74 6c 6f 6f 6b 4d 61 63 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703000" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Outlook.Mac" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenOutlookMac" S="Medium" /> <F T


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    143192.168.2.44992313.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:25 UTC192OUTGET /rules/rule700751v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:25 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:25 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1414
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                                                    ETag: "0x8DC582BE03B051D"
                                                    x-ms-request-id: 4b0a4edd-c01e-00ad-438c-15a2b9000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161725Z-15767c5fc55tsfp92w7yna557w0000000b5g00000000vqn6
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:25 UTC1414INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 37 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700751" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Outlook.Desktop.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenan


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    144192.168.2.44992413.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:25 UTC192OUTGET /rules/rule700750v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:25 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:25 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1377
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:28:02 GMT
                                                    ETag: "0x8DC582BEAFF0125"
                                                    x-ms-request-id: 0dcb9a48-e01e-0003-1c8c-150fa8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161725Z-15767c5fc55d6fcl6x6bw8cpdc0000000b1g00000000yvht
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:25 UTC1377INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 37 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 4f 75 74 6c 6f 6f 6b 44 65 73 6b 74 6f 70 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700750" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Outlook.Desktop" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenOutlookDesktop" S="Medium" />


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    145192.168.2.44992513.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:25 UTC192OUTGET /rules/rule700151v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:25 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:25 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1399
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:45 GMT
                                                    ETag: "0x8DC582BE0A2434F"
                                                    x-ms-request-id: 4a218e36-401e-00a3-268c-158b09000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161725Z-15767c5fc55qdcd62bsn50hd6s0000000b50000000001dx0
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:25 UTC1399INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 31 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 6e 65 4e 6f 74 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 4f 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700151" V="1" DC="SM" EN="Office.Telemetry.Event.Office.OneNote.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenOn


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    146192.168.2.44992713.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:25 UTC192OUTGET /rules/rule703451v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:25 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:25 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1409
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                                                    ETag: "0x8DC582BDFC438CF"
                                                    x-ms-request-id: eccf31ce-001e-0079-3e8c-1512e8000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161725Z-15767c5fc554w2fgapsyvy8ua00000000ang00000000y677
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:25 UTC1409INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 34 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 66 66 69 63 65 4d 6f 62 69 6c 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703451" V="1" DC="SM" EN="Office.Telemetry.Event.Office.OfficeMobile.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTo


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    147192.168.2.44992613.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:25 UTC192OUTGET /rules/rule700150v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:25 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:25 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1362
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:53 GMT
                                                    ETag: "0x8DC582BE54CA33F"
                                                    x-ms-request-id: f1c85a61-d01e-007a-188c-15f38c000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161725Z-15767c5fc55472x4k7dmphmadg0000000azg000000008fn5
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:25 UTC1362INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 31 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 6e 65 4e 6f 74 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 4f 6e 65 4e 6f 74 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700150" V="1" DC="SM" EN="Office.Telemetry.Event.Office.OneNote" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenOneNote" S="Medium" /> <F T="2">


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    148192.168.2.44992813.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:25 UTC192OUTGET /rules/rule703450v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:25 UTC584INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:25 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1372
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:55 GMT
                                                    ETag: "0x8DC582BE6669CA7"
                                                    x-ms-request-id: b9a1a970-401e-0078-528c-154d34000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161725Z-15767c5fc55kg97hfq5uqyxxaw0000000b6000000000r4e1
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    X-Cache-Info: L1_T2
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:25 UTC1372INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 34 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 66 66 69 63 65 4d 6f 62 69 6c 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 4f 66 66 69 63 65 4d 6f 62 69 6c 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703450" V="1" DC="SM" EN="Office.Telemetry.Event.Office.OfficeMobile" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenOfficeMobile" S="Medium" /> <


                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                    149192.168.2.44993113.107.246.60443
                                                    TimestampBytes transferredDirectionData
                                                    2024-10-03 16:17:26 UTC192OUTGET /rules/rule700901v1s19.xml HTTP/1.1
                                                    Connection: Keep-Alive
                                                    Accept-Encoding: gzip
                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                    Host: otelrules.azureedge.net
                                                    2024-10-03 16:17:26 UTC563INHTTP/1.1 200 OK
                                                    Date: Thu, 03 Oct 2024 16:17:26 GMT
                                                    Content-Type: text/xml
                                                    Content-Length: 1408
                                                    Connection: close
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Vary: Accept-Encoding
                                                    Cache-Control: public, max-age=604800, immutable
                                                    Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                                                    ETag: "0x8DC582BE1038EF2"
                                                    x-ms-request-id: f40770c2-201e-0000-318c-15a537000000
                                                    x-ms-version: 2018-03-28
                                                    x-azure-ref: 20241003T161726Z-15767c5fc55whfstvfw43u8fp40000000bb000000000psxd
                                                    x-fd-int-roxy-purgeid: 0
                                                    X-Cache: TCP_HIT
                                                    Accept-Ranges: bytes
                                                    2024-10-03 16:17:26 UTC1408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 39 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4e 61 74 75 72 61 6c 4c 61 6e 67 75 61 67 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e
                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700901" V="1" DC="SM" EN="Office.Telemetry.Event.Office.NaturalLanguage.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenan


                                                    Click to jump to process

                                                    Click to jump to process

                                                    Click to dive into process behavior distribution

                                                    Click to jump to process

                                                    Target ID:0
                                                    Start time:12:16:07
                                                    Start date:03/10/2024
                                                    Path:C:\Users\user\Desktop\file.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Users\user\Desktop\file.exe"
                                                    Imagebase:0x7b0000
                                                    File size:919'040 bytes
                                                    MD5 hash:FEB3D620CDD56C7FBE1C54AE29328327
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:low
                                                    Has exited:true

                                                    Target ID:1
                                                    Start time:12:16:07
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\SysWOW64\taskkill.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:taskkill /F /IM chrome.exe /T
                                                    Imagebase:0x970000
                                                    File size:74'240 bytes
                                                    MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:moderate
                                                    Has exited:true

                                                    Target ID:2
                                                    Start time:12:16:07
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\System32\conhost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                    Imagebase:0x7ff7699e0000
                                                    File size:862'208 bytes
                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:3
                                                    Start time:12:16:07
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\SysWOW64\taskkill.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:taskkill /F /IM msedge.exe /T
                                                    Imagebase:0x970000
                                                    File size:74'240 bytes
                                                    MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:moderate
                                                    Has exited:true

                                                    Target ID:4
                                                    Start time:12:16:07
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\System32\conhost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                    Imagebase:0x7ff7699e0000
                                                    File size:862'208 bytes
                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:5
                                                    Start time:12:16:08
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\SysWOW64\taskkill.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:taskkill /F /IM firefox.exe /T
                                                    Imagebase:0x970000
                                                    File size:74'240 bytes
                                                    MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:moderate
                                                    Has exited:true

                                                    Target ID:6
                                                    Start time:12:16:08
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\System32\conhost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                    Imagebase:0x7ff7699e0000
                                                    File size:862'208 bytes
                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:7
                                                    Start time:12:16:08
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\SysWOW64\taskkill.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:taskkill /F /IM opera.exe /T
                                                    Imagebase:0x970000
                                                    File size:74'240 bytes
                                                    MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:moderate
                                                    Has exited:true

                                                    Target ID:8
                                                    Start time:12:16:08
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\System32\conhost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                    Imagebase:0x7ff7699e0000
                                                    File size:862'208 bytes
                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:9
                                                    Start time:12:16:08
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\SysWOW64\taskkill.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:taskkill /F /IM brave.exe /T
                                                    Imagebase:0x970000
                                                    File size:74'240 bytes
                                                    MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:moderate
                                                    Has exited:true

                                                    Target ID:10
                                                    Start time:12:16:08
                                                    Start date:03/10/2024
                                                    Path:C:\Windows\System32\conhost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                    Imagebase:0x7ff7699e0000
                                                    File size:862'208 bytes
                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:11
                                                    Start time:12:16:09
                                                    Start date:03/10/2024
                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobars
                                                    Imagebase:0x7ff76e190000
                                                    File size:3'242'272 bytes
                                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:false

                                                    Target ID:13
                                                    Start time:12:16:10
                                                    Start date:03/10/2024
                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2016 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8
                                                    Imagebase:0x7ff76e190000
                                                    File size:3'242'272 bytes
                                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:false

                                                    Target ID:14
                                                    Start time:12:16:21
                                                    Start date:03/10/2024
                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5084 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8
                                                    Imagebase:0x7ff76e190000
                                                    File size:3'242'272 bytes
                                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                    Has elevated privileges:false
                                                    Has administrator privileges:false
                                                    Programmed in:C, C++ or other language
                                                    Has exited:false

                                                    Target ID:15
                                                    Start time:12:16:21
                                                    Start date:03/10/2024
                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5576 --field-trial-handle=1956,i,17900587416320745061,351214968976735119,262144 /prefetch:8
                                                    Imagebase:0x7ff76e190000
                                                    File size:3'242'272 bytes
                                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Has exited:true

                                                    Reset < >

                                                      Execution Graph

                                                      Execution Coverage:2.2%
                                                      Dynamic/Decrypted Code Coverage:0%
                                                      Signature Coverage:4.9%
                                                      Total number of Nodes:1607
                                                      Total number of Limit Nodes:64
                                                      execution_graph 94822 7b105b 94827 7b344d 94822->94827 94824 7b106a 94858 7d00a3 29 API calls __onexit 94824->94858 94826 7b1074 94828 7b345d __wsopen_s 94827->94828 94859 7ba961 94828->94859 94832 7b351c 94871 7b3357 94832->94871 94839 7ba961 22 API calls 94840 7b354d 94839->94840 94892 7ba6c3 94840->94892 94843 7f3176 RegQueryValueExW 94844 7f320c RegCloseKey 94843->94844 94845 7f3193 94843->94845 94848 7b3578 94844->94848 94857 7f321e _wcslen 94844->94857 94898 7cfe0b 94845->94898 94847 7f31ac 94908 7b5722 94847->94908 94848->94824 94849 7b4c6d 22 API calls 94849->94857 94852 7f31d4 94911 7b6b57 94852->94911 94854 7f31ee messages 94854->94844 94856 7b515f 22 API calls 94856->94857 94857->94848 94857->94849 94857->94856 94923 7b9cb3 94857->94923 94858->94826 94860 7cfe0b 22 API calls 94859->94860 94861 7ba976 94860->94861 94929 7cfddb 94861->94929 94863 7b3513 94864 7b3a5a 94863->94864 94951 7f1f50 94864->94951 94867 7b9cb3 22 API calls 94868 7b3a8d 94867->94868 94953 7b3aa2 94868->94953 94870 7b3a97 94870->94832 94872 7f1f50 __wsopen_s 94871->94872 94873 7b3364 GetFullPathNameW 94872->94873 94874 7b3386 94873->94874 94875 7b6b57 22 API calls 94874->94875 94876 7b33a4 94875->94876 94877 7b33c6 94876->94877 94878 7f30bb 94877->94878 94879 7b33dd 94877->94879 94881 7cfddb 22 API calls 94878->94881 94977 7b33ee 94879->94977 94883 7f30c5 _wcslen 94881->94883 94882 7b33e8 94886 7b515f 94882->94886 94884 7cfe0b 22 API calls 94883->94884 94885 7f30fe __fread_nolock 94884->94885 94887 7b516e 94886->94887 94891 7b518f __fread_nolock 94886->94891 94890 7cfe0b 22 API calls 94887->94890 94888 7cfddb 22 API calls 94889 7b3544 94888->94889 94889->94839 94890->94891 94891->94888 94893 7ba6dd 94892->94893 94897 7b3556 RegOpenKeyExW 94892->94897 94894 7cfddb 22 API calls 94893->94894 94895 7ba6e7 94894->94895 94896 7cfe0b 22 API calls 94895->94896 94896->94897 94897->94843 94897->94848 94901 7cfddb 94898->94901 94899 7dea0c ___std_exception_copy 21 API calls 94899->94901 94900 7cfdfa 94900->94847 94901->94899 94901->94900 94904 7cfdfc 94901->94904 94992 7d4ead 7 API calls 2 library calls 94901->94992 94903 7d066d 94994 7d32a4 RaiseException 94903->94994 94904->94903 94993 7d32a4 RaiseException 94904->94993 94907 7d068a 94907->94847 94909 7cfddb 22 API calls 94908->94909 94910 7b5734 RegQueryValueExW 94909->94910 94910->94852 94910->94854 94912 7b6b67 _wcslen 94911->94912 94913 7f4ba1 94911->94913 94916 7b6b7d 94912->94916 94917 7b6ba2 94912->94917 94914 7b93b2 22 API calls 94913->94914 94915 7f4baa 94914->94915 94915->94915 94995 7b6f34 22 API calls 94916->94995 94919 7cfddb 22 API calls 94917->94919 94921 7b6bae 94919->94921 94920 7b6b85 __fread_nolock 94920->94854 94922 7cfe0b 22 API calls 94921->94922 94922->94920 94924 7b9cc2 _wcslen 94923->94924 94925 7cfe0b 22 API calls 94924->94925 94926 7b9cea __fread_nolock 94925->94926 94927 7cfddb 22 API calls 94926->94927 94928 7b9d00 94927->94928 94928->94857 94932 7cfde0 94929->94932 94931 7cfdfa 94931->94863 94932->94931 94935 7cfdfc 94932->94935 94939 7dea0c 94932->94939 94946 7d4ead 7 API calls 2 library calls 94932->94946 94934 7d066d 94948 7d32a4 RaiseException 94934->94948 94935->94934 94947 7d32a4 RaiseException 94935->94947 94938 7d068a 94938->94863 94944 7e3820 _abort 94939->94944 94940 7e385e 94950 7df2d9 20 API calls _abort 94940->94950 94941 7e3849 RtlAllocateHeap 94943 7e385c 94941->94943 94941->94944 94943->94932 94944->94940 94944->94941 94949 7d4ead 7 API calls 2 library calls 94944->94949 94946->94932 94947->94934 94948->94938 94949->94944 94950->94943 94952 7b3a67 GetModuleFileNameW 94951->94952 94952->94867 94954 7f1f50 __wsopen_s 94953->94954 94955 7b3aaf GetFullPathNameW 94954->94955 94956 7b3ae9 94955->94956 94957 7b3ace 94955->94957 94959 7ba6c3 22 API calls 94956->94959 94958 7b6b57 22 API calls 94957->94958 94960 7b3ada 94958->94960 94959->94960 94963 7b37a0 94960->94963 94964 7b37ae 94963->94964 94967 7b93b2 94964->94967 94966 7b37c2 94966->94870 94968 7b93c0 94967->94968 94969 7b93c9 __fread_nolock 94967->94969 94968->94969 94971 7baec9 94968->94971 94969->94966 94969->94969 94972 7baed9 __fread_nolock 94971->94972 94973 7baedc 94971->94973 94972->94969 94974 7cfddb 22 API calls 94973->94974 94975 7baee7 94974->94975 94976 7cfe0b 22 API calls 94975->94976 94976->94972 94978 7b33fe _wcslen 94977->94978 94979 7f311d 94978->94979 94980 7b3411 94978->94980 94982 7cfddb 22 API calls 94979->94982 94987 7ba587 94980->94987 94984 7f3127 94982->94984 94983 7b341e __fread_nolock 94983->94882 94985 7cfe0b 22 API calls 94984->94985 94986 7f3157 __fread_nolock 94985->94986 94988 7ba59d 94987->94988 94991 7ba598 __fread_nolock 94987->94991 94989 7ff80f 94988->94989 94990 7cfe0b 22 API calls 94988->94990 94990->94991 94991->94983 94992->94901 94993->94903 94994->94907 94995->94920 94996 802a00 95011 7bd7b0 messages 94996->95011 94997 7bdb11 PeekMessageW 94997->95011 94998 7bd807 GetInputState 94998->94997 94998->95011 95000 801cbe TranslateAcceleratorW 95000->95011 95001 7bdb8f PeekMessageW 95001->95011 95002 7bdb73 TranslateMessage DispatchMessageW 95002->95001 95003 7bda04 timeGetTime 95003->95011 95004 7bdbaf Sleep 95004->95011 95005 802b74 Sleep 95018 802aea 95005->95018 95007 801dda timeGetTime 95158 7ce300 23 API calls 95007->95158 95011->94997 95011->94998 95011->95000 95011->95001 95011->95002 95011->95003 95011->95004 95011->95005 95011->95007 95014 7bd9d5 95011->95014 95017 8429bf GetForegroundWindow 95011->95017 95011->95018 95028 7bdd50 95011->95028 95035 7c1310 95011->95035 95093 7bbf40 95011->95093 95151 7cedf6 95011->95151 95156 7bdfd0 349 API calls 3 library calls 95011->95156 95157 7ce551 timeGetTime 95011->95157 95159 823a2a 23 API calls 95011->95159 95160 7bec40 95011->95160 95184 82359c 82 API calls __wsopen_s 95011->95184 95012 802c0b GetExitCodeProcess 95015 802c21 WaitForSingleObject 95012->95015 95016 802c37 CloseHandle 95012->95016 95015->95011 95015->95016 95016->95018 95017->95011 95018->95011 95018->95012 95018->95014 95019 802ca9 Sleep 95018->95019 95185 835658 23 API calls 95018->95185 95186 81e97b QueryPerformanceCounter QueryPerformanceFrequency Sleep QueryPerformanceCounter Sleep 95018->95186 95187 7ce551 timeGetTime 95018->95187 95188 81d4dc 47 API calls 95018->95188 95019->95011 95029 7bdd6f 95028->95029 95030 7bdd83 95028->95030 95189 7bd260 95029->95189 95221 82359c 82 API calls __wsopen_s 95030->95221 95032 7bdd7a 95032->95011 95034 802f75 95034->95034 95036 7c1376 95035->95036 95037 7c17b0 95035->95037 95038 806331 95036->95038 95039 7c1390 95036->95039 95287 7d0242 5 API calls __Init_thread_wait 95037->95287 95301 83709c 349 API calls 95038->95301 95229 7c1940 95039->95229 95043 7c17ba 95046 7c17fb 95043->95046 95048 7b9cb3 22 API calls 95043->95048 95045 80633d 95045->95011 95050 806346 95046->95050 95052 7c182c 95046->95052 95047 7c1940 9 API calls 95049 7c13b6 95047->95049 95055 7c17d4 95048->95055 95049->95046 95051 7c13ec 95049->95051 95302 82359c 82 API calls __wsopen_s 95050->95302 95051->95050 95075 7c1408 __fread_nolock 95051->95075 95289 7baceb 95052->95289 95288 7d01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent 95055->95288 95056 7c1839 95299 7cd217 349 API calls 95056->95299 95059 80636e 95303 82359c 82 API calls __wsopen_s 95059->95303 95060 7c152f 95062 7c153c 95060->95062 95063 8063d1 95060->95063 95065 7c1940 9 API calls 95062->95065 95305 835745 54 API calls _wcslen 95063->95305 95066 7c1549 95065->95066 95070 8064fa 95066->95070 95072 7c1940 9 API calls 95066->95072 95067 7cfddb 22 API calls 95067->95075 95068 7c1872 95300 7cfaeb 23 API calls 95068->95300 95069 7cfe0b 22 API calls 95069->95075 95079 806369 95070->95079 95307 82359c 82 API calls __wsopen_s 95070->95307 95077 7c1563 95072->95077 95074 7bec40 349 API calls 95074->95075 95075->95056 95075->95059 95075->95060 95075->95067 95075->95069 95075->95074 95076 8063b2 95075->95076 95075->95079 95304 82359c 82 API calls __wsopen_s 95076->95304 95077->95070 95082 7c15c7 messages 95077->95082 95306 7ba8c7 22 API calls __fread_nolock 95077->95306 95079->95011 95081 7c1940 9 API calls 95081->95082 95082->95068 95082->95070 95082->95079 95082->95081 95084 7c167b messages 95082->95084 95239 8429bf 95082->95239 95243 83abf7 95082->95243 95248 83ab67 95082->95248 95251 825c5a 95082->95251 95256 8419bc 95082->95256 95259 7cf645 95082->95259 95266 83a67c CreateToolhelp32Snapshot Process32FirstW 95082->95266 95083 7c171d 95083->95011 95084->95083 95286 7cce17 22 API calls messages 95084->95286 95583 7badf0 95093->95583 95095 7bbf9d 95096 7bbfa9 95095->95096 95097 8004b6 95095->95097 95099 7bc01e 95096->95099 95100 8004c6 95096->95100 95601 82359c 82 API calls __wsopen_s 95097->95601 95588 7bac91 95099->95588 95602 82359c 82 API calls __wsopen_s 95100->95602 95103 8009bf 95150 7bc603 95103->95150 95615 82359c 82 API calls __wsopen_s 95103->95615 95105 817120 22 API calls 95138 7bc039 __fread_nolock messages 95105->95138 95106 7bc7da 95109 7cfe0b 22 API calls 95106->95109 95114 7bc808 __fread_nolock 95109->95114 95111 8004f5 95115 80055a 95111->95115 95603 7cd217 349 API calls 95111->95603 95117 7cfe0b 22 API calls 95114->95117 95115->95150 95604 82359c 82 API calls __wsopen_s 95115->95604 95116 7cfddb 22 API calls 95116->95138 95135 7bc350 __fread_nolock messages 95117->95135 95118 7baf8a 22 API calls 95118->95138 95119 80091a 95613 823209 23 API calls 95119->95613 95122 7bec40 349 API calls 95122->95138 95123 8008a5 95124 7bec40 349 API calls 95123->95124 95125 8008cf 95124->95125 95125->95150 95611 7ba81b 41 API calls 95125->95611 95127 800591 95605 82359c 82 API calls __wsopen_s 95127->95605 95131 8008f6 95612 82359c 82 API calls __wsopen_s 95131->95612 95133 7bc3ac 95133->95011 95134 7baceb 23 API calls 95134->95138 95135->95133 95600 7cce17 22 API calls messages 95135->95600 95136 7bc237 95137 7bc253 95136->95137 95614 7ba8c7 22 API calls __fread_nolock 95136->95614 95140 800976 95137->95140 95143 7bc297 messages 95137->95143 95138->95103 95138->95105 95138->95106 95138->95111 95138->95114 95138->95115 95138->95116 95138->95118 95138->95119 95138->95122 95138->95123 95138->95127 95138->95131 95138->95134 95138->95136 95146 7bbbe0 40 API calls 95138->95146 95149 7cfe0b 22 API calls 95138->95149 95138->95150 95592 7bad81 95138->95592 95606 817099 22 API calls __fread_nolock 95138->95606 95607 835745 54 API calls _wcslen 95138->95607 95608 7caa42 22 API calls messages 95138->95608 95609 81f05c 40 API calls 95138->95609 95610 7ba993 41 API calls 95138->95610 95142 7baceb 23 API calls 95140->95142 95142->95103 95143->95103 95144 7baceb 23 API calls 95143->95144 95145 7bc335 95144->95145 95145->95103 95147 7bc342 95145->95147 95146->95138 95599 7ba704 22 API calls messages 95147->95599 95149->95138 95150->95011 95152 7cee12 95151->95152 95154 7cee09 95151->95154 95153 7cee36 IsDialogMessageW 95152->95153 95152->95154 95155 80efaf GetClassLongW 95152->95155 95153->95152 95153->95154 95154->95011 95155->95152 95155->95153 95156->95011 95157->95011 95158->95011 95159->95011 95182 7bec76 messages 95160->95182 95161 7d0242 EnterCriticalSection LeaveCriticalSection LeaveCriticalSection WaitForSingleObjectEx EnterCriticalSection 95161->95182 95162 7d01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent __Init_thread_footer 95162->95182 95163 7cfddb 22 API calls 95163->95182 95164 7bfef7 95177 7bed9d messages 95164->95177 95628 7ba8c7 22 API calls __fread_nolock 95164->95628 95167 804b0b 95630 82359c 82 API calls __wsopen_s 95167->95630 95168 804600 95168->95177 95627 7ba8c7 22 API calls __fread_nolock 95168->95627 95172 7ba8c7 22 API calls 95172->95182 95175 7bfbe3 95175->95177 95178 804bdc 95175->95178 95183 7bf3ae messages 95175->95183 95176 7ba961 22 API calls 95176->95182 95177->95011 95631 82359c 82 API calls __wsopen_s 95178->95631 95180 7d00a3 29 API calls pre_c_initialization 95180->95182 95181 804beb 95632 82359c 82 API calls __wsopen_s 95181->95632 95182->95161 95182->95162 95182->95163 95182->95164 95182->95167 95182->95168 95182->95172 95182->95175 95182->95176 95182->95177 95182->95180 95182->95181 95182->95183 95625 7c01e0 349 API calls 2 library calls 95182->95625 95626 7c06a0 41 API calls messages 95182->95626 95183->95177 95629 82359c 82 API calls __wsopen_s 95183->95629 95184->95011 95185->95018 95186->95018 95187->95018 95188->95018 95190 7bec40 349 API calls 95189->95190 95211 7bd29d 95190->95211 95191 801bc4 95228 82359c 82 API calls __wsopen_s 95191->95228 95193 7bd30b messages 95193->95032 95194 7bd3c3 95196 7bd3ce 95194->95196 95197 7bd6d5 95194->95197 95195 7bd5ff 95198 801bb5 95195->95198 95199 7bd614 95195->95199 95201 7cfddb 22 API calls 95196->95201 95197->95193 95206 7cfe0b 22 API calls 95197->95206 95227 835705 23 API calls 95198->95227 95204 7cfddb 22 API calls 95199->95204 95200 7bd4b8 95208 7cfe0b 22 API calls 95200->95208 95202 7bd3d5 __fread_nolock 95201->95202 95209 7cfddb 22 API calls 95202->95209 95210 7bd3f6 95202->95210 95214 7bd46a 95204->95214 95205 7cfddb 22 API calls 95205->95211 95206->95202 95207 7bd429 __fread_nolock messages 95207->95195 95213 801ba4 95207->95213 95207->95214 95217 801b7f 95207->95217 95219 801b5d 95207->95219 95223 7b1f6f 349 API calls 95207->95223 95208->95207 95209->95210 95210->95207 95222 7bbec0 349 API calls 95210->95222 95211->95191 95211->95193 95211->95194 95211->95197 95211->95200 95211->95205 95211->95207 95226 82359c 82 API calls __wsopen_s 95213->95226 95214->95032 95225 82359c 82 API calls __wsopen_s 95217->95225 95224 82359c 82 API calls __wsopen_s 95219->95224 95221->95034 95222->95207 95223->95207 95224->95214 95225->95214 95226->95214 95227->95191 95228->95193 95230 7c1981 95229->95230 95235 7c195d 95229->95235 95308 7d0242 5 API calls __Init_thread_wait 95230->95308 95232 7c13a0 95232->95047 95233 7c198b 95233->95235 95309 7d01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent 95233->95309 95235->95232 95310 7d0242 5 API calls __Init_thread_wait 95235->95310 95236 7c8727 95236->95232 95311 7d01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent 95236->95311 95240 8429cb 95239->95240 95241 842a01 GetForegroundWindow 95240->95241 95242 8429d1 95240->95242 95241->95242 95242->95082 95312 83aff9 95243->95312 95245 83ac54 95245->95082 95246 83ac0c 95246->95245 95247 7baceb 23 API calls 95246->95247 95247->95245 95249 83aff9 217 API calls 95248->95249 95250 83ab79 95249->95250 95250->95082 95252 7b7510 53 API calls 95251->95252 95253 825c6d 95252->95253 95467 81dbbe lstrlenW 95253->95467 95255 825c77 95255->95082 95472 842ad8 95256->95472 95258 8419cb 95258->95082 95260 7bb567 39 API calls 95259->95260 95261 7cf659 95260->95261 95262 80f2dc Sleep 95261->95262 95263 7cf661 timeGetTime 95261->95263 95264 7bb567 39 API calls 95263->95264 95265 7cf677 95264->95265 95265->95082 95270 83a6c3 95266->95270 95267 7ba961 22 API calls 95267->95270 95268 7b9cb3 22 API calls 95268->95270 95270->95267 95270->95268 95272 7b7510 53 API calls 95270->95272 95275 83a796 Process32NextW 95270->95275 95483 7b525f 95270->95483 95525 7b6350 95270->95525 95540 7cce60 41 API calls 95270->95540 95541 83b574 22 API calls __fread_nolock 95270->95541 95272->95270 95275->95270 95276 83a7aa CloseHandle 95275->95276 95534 7b63eb 95276->95534 95280 83a7cd 95543 7c04f0 22 API calls 95280->95543 95282 83a87d 95282->95082 95284 7c04f0 22 API calls 95285 83a7d9 95284->95285 95285->95282 95285->95284 95544 7b62b5 22 API calls 95285->95544 95286->95084 95287->95043 95288->95046 95290 7bacf9 95289->95290 95298 7bad2a messages 95289->95298 95291 7bad55 95290->95291 95292 7bad01 messages 95290->95292 95291->95298 95581 7ba8c7 22 API calls __fread_nolock 95291->95581 95294 7ffa48 95292->95294 95295 7bad21 95292->95295 95292->95298 95294->95298 95582 7cce17 22 API calls messages 95294->95582 95296 7ffa3a VariantClear 95295->95296 95295->95298 95296->95298 95298->95056 95299->95068 95300->95068 95301->95045 95302->95079 95303->95079 95304->95079 95305->95077 95306->95082 95307->95079 95308->95233 95309->95235 95310->95236 95311->95232 95313 83b01d ___scrt_fastfail 95312->95313 95314 83b094 95313->95314 95315 83b058 95313->95315 95319 7bb567 39 API calls 95314->95319 95320 83b08b 95314->95320 95433 7bb567 95315->95433 95317 83b063 95317->95320 95323 7bb567 39 API calls 95317->95323 95318 83b0ed 95403 7b7510 95318->95403 95322 83b0a5 95319->95322 95320->95318 95324 7bb567 39 API calls 95320->95324 95326 7bb567 39 API calls 95322->95326 95327 83b078 95323->95327 95324->95318 95326->95320 95329 7bb567 39 API calls 95327->95329 95329->95320 95330 83b115 95331 83b1d8 95330->95331 95332 83b11f 95330->95332 95334 83b20a GetCurrentDirectoryW 95331->95334 95337 7b7510 53 API calls 95331->95337 95333 7b7510 53 API calls 95332->95333 95335 83b130 95333->95335 95336 7cfe0b 22 API calls 95334->95336 95338 7b7620 22 API calls 95335->95338 95339 83b22f GetCurrentDirectoryW 95336->95339 95340 83b1ef 95337->95340 95341 83b13a 95338->95341 95342 83b23c 95339->95342 95343 7b7620 22 API calls 95340->95343 95344 7b7510 53 API calls 95341->95344 95347 83b275 95342->95347 95438 7b9c6e 22 API calls 95342->95438 95345 83b1f9 _wcslen 95343->95345 95346 83b14b 95344->95346 95345->95334 95345->95347 95348 7b7620 22 API calls 95346->95348 95354 83b287 95347->95354 95355 83b28b 95347->95355 95350 83b155 95348->95350 95352 7b7510 53 API calls 95350->95352 95351 83b255 95439 7b9c6e 22 API calls 95351->95439 95357 83b166 95352->95357 95360 83b39a CreateProcessW 95354->95360 95361 83b2f8 95354->95361 95441 8207c0 10 API calls 95355->95441 95362 7b7620 22 API calls 95357->95362 95358 83b265 95440 7b9c6e 22 API calls 95358->95440 95359 83b294 95442 8206e6 10 API calls 95359->95442 95380 83b32f _wcslen 95360->95380 95444 8111c8 39 API calls 95361->95444 95366 83b170 95362->95366 95369 83b1a6 GetSystemDirectoryW 95366->95369 95374 7b7510 53 API calls 95366->95374 95367 83b2aa 95443 8205a7 8 API calls 95367->95443 95368 83b2fd 95372 83b323 95368->95372 95373 83b32a 95368->95373 95371 7cfe0b 22 API calls 95369->95371 95376 83b1cb GetSystemDirectoryW 95371->95376 95445 811201 128 API calls 2 library calls 95372->95445 95446 8114ce 6 API calls 95373->95446 95378 83b187 95374->95378 95375 83b2d0 95375->95354 95376->95342 95382 7b7620 22 API calls 95378->95382 95384 83b3d6 GetLastError 95380->95384 95385 83b42f CloseHandle 95380->95385 95381 83b328 95381->95380 95383 83b191 _wcslen 95382->95383 95383->95342 95383->95369 95393 83b41a 95384->95393 95386 83b43f 95385->95386 95394 83b49a 95385->95394 95387 83b451 95386->95387 95388 83b446 CloseHandle 95386->95388 95391 83b463 95387->95391 95392 83b458 CloseHandle 95387->95392 95388->95387 95390 83b4a6 95390->95393 95395 83b475 95391->95395 95396 83b46a CloseHandle 95391->95396 95392->95391 95430 820175 95393->95430 95394->95390 95399 83b4d2 CloseHandle 95394->95399 95447 8209d9 34 API calls 95395->95447 95396->95395 95399->95393 95401 83b486 95448 83b536 25 API calls 95401->95448 95404 7b7522 95403->95404 95405 7b7525 95403->95405 95426 7b7620 95404->95426 95406 7b755b 95405->95406 95407 7b752d 95405->95407 95409 7f50f6 95406->95409 95412 7b756d 95406->95412 95417 7f500f 95406->95417 95449 7d51c6 26 API calls 95407->95449 95452 7d5183 26 API calls 95409->95452 95410 7b753d 95416 7cfddb 22 API calls 95410->95416 95450 7cfb21 51 API calls 95412->95450 95413 7f510e 95413->95413 95418 7b7547 95416->95418 95420 7cfe0b 22 API calls 95417->95420 95421 7f5088 95417->95421 95419 7b9cb3 22 API calls 95418->95419 95419->95404 95422 7f5058 95420->95422 95451 7cfb21 51 API calls 95421->95451 95423 7cfddb 22 API calls 95422->95423 95424 7f507f 95423->95424 95425 7b9cb3 22 API calls 95424->95425 95425->95421 95427 7b762a _wcslen 95426->95427 95428 7cfe0b 22 API calls 95427->95428 95429 7b763f 95428->95429 95429->95330 95453 82030f 95430->95453 95434 7bb578 95433->95434 95435 7bb57f 95433->95435 95434->95435 95466 7d62d1 39 API calls 95434->95466 95435->95317 95437 7bb5c2 95437->95317 95438->95351 95439->95358 95440->95347 95441->95359 95442->95367 95443->95375 95444->95368 95445->95381 95446->95380 95447->95401 95448->95394 95449->95410 95450->95410 95451->95409 95452->95413 95454 820321 CloseHandle 95453->95454 95455 820329 95453->95455 95454->95455 95456 820336 95455->95456 95457 82032e CloseHandle 95455->95457 95458 820343 95456->95458 95459 82033b CloseHandle 95456->95459 95457->95456 95460 820350 95458->95460 95461 820348 CloseHandle 95458->95461 95459->95458 95462 820355 CloseHandle 95460->95462 95463 82035d 95460->95463 95461->95460 95462->95463 95464 820362 CloseHandle 95463->95464 95465 82017d 95463->95465 95464->95465 95465->95246 95466->95437 95468 81dc06 95467->95468 95469 81dbdc GetFileAttributesW 95467->95469 95468->95255 95469->95468 95470 81dbe8 FindFirstFileW 95469->95470 95470->95468 95471 81dbf9 FindClose 95470->95471 95471->95468 95473 7baceb 23 API calls 95472->95473 95474 842af3 95473->95474 95475 842b1d 95474->95475 95476 842aff 95474->95476 95477 7b6b57 22 API calls 95475->95477 95478 7b7510 53 API calls 95476->95478 95480 842b1b 95477->95480 95479 842b0c 95478->95479 95479->95480 95482 7ba8c7 22 API calls __fread_nolock 95479->95482 95480->95258 95482->95480 95484 7ba961 22 API calls 95483->95484 95485 7b5275 95484->95485 95486 7ba961 22 API calls 95485->95486 95487 7b527d 95486->95487 95488 7ba961 22 API calls 95487->95488 95489 7b5285 95488->95489 95490 7ba961 22 API calls 95489->95490 95491 7b528d 95490->95491 95492 7f3df5 95491->95492 95493 7b52c1 95491->95493 95563 7ba8c7 22 API calls __fread_nolock 95492->95563 95495 7b6d25 22 API calls 95493->95495 95497 7b52cf 95495->95497 95496 7f3dfe 95498 7ba6c3 22 API calls 95496->95498 95499 7b93b2 22 API calls 95497->95499 95501 7b5304 95498->95501 95500 7b52d9 95499->95500 95500->95501 95502 7b6d25 22 API calls 95500->95502 95503 7b5325 95501->95503 95517 7b5349 95501->95517 95523 7f3e20 95501->95523 95505 7b52fa 95502->95505 95503->95517 95558 7b4c6d 95503->95558 95506 7b93b2 22 API calls 95505->95506 95506->95501 95508 7b6b57 22 API calls 95521 7f3ee0 95508->95521 95509 7b535a 95510 7b5370 95509->95510 95561 7ba8c7 22 API calls __fread_nolock 95509->95561 95511 7b5384 95510->95511 95562 7ba8c7 22 API calls __fread_nolock 95510->95562 95512 7b538f 95511->95512 95565 7ba8c7 22 API calls __fread_nolock 95511->95565 95524 7b539a 95512->95524 95566 7ba8c7 22 API calls __fread_nolock 95512->95566 95516 7b6d25 22 API calls 95516->95517 95545 7b6d25 95517->95545 95520 7b4c6d 22 API calls 95520->95521 95521->95517 95521->95520 95564 7b49bd 22 API calls __fread_nolock 95521->95564 95523->95508 95524->95270 95526 7b6362 95525->95526 95527 7f4a51 95525->95527 95568 7b6373 95526->95568 95578 7b4a88 22 API calls __fread_nolock 95527->95578 95530 7f4a5b 95532 7f4a67 95530->95532 95579 7ba8c7 22 API calls __fread_nolock 95530->95579 95531 7b636e 95531->95270 95535 7b63f3 95534->95535 95536 7cfddb 22 API calls 95535->95536 95537 7b6401 95536->95537 95580 7b6a26 22 API calls 95537->95580 95539 7b6409 95542 7b6a50 22 API calls 95539->95542 95540->95270 95541->95270 95542->95280 95543->95285 95544->95285 95546 7b6d91 95545->95546 95547 7b6d34 95545->95547 95548 7b93b2 22 API calls 95546->95548 95547->95546 95549 7b6d3f 95547->95549 95554 7b6d62 __fread_nolock 95548->95554 95550 7b6d5a 95549->95550 95551 7f4c9d 95549->95551 95567 7b6f34 22 API calls 95550->95567 95553 7cfddb 22 API calls 95551->95553 95555 7f4ca7 95553->95555 95554->95509 95556 7cfe0b 22 API calls 95555->95556 95557 7f4cda 95556->95557 95559 7baec9 22 API calls 95558->95559 95560 7b4c78 95559->95560 95560->95516 95560->95517 95561->95510 95562->95511 95563->95496 95564->95521 95565->95512 95566->95524 95567->95554 95569 7b6382 95568->95569 95574 7b63b6 __fread_nolock 95568->95574 95570 7f4a82 95569->95570 95571 7b63a9 95569->95571 95569->95574 95572 7cfddb 22 API calls 95570->95572 95573 7ba587 22 API calls 95571->95573 95575 7f4a91 95572->95575 95573->95574 95574->95531 95576 7cfe0b 22 API calls 95575->95576 95577 7f4ac5 __fread_nolock 95576->95577 95578->95530 95579->95532 95580->95539 95581->95298 95582->95298 95584 7bae01 95583->95584 95587 7bae1c messages 95583->95587 95585 7baec9 22 API calls 95584->95585 95586 7bae09 CharUpperBuffW 95585->95586 95586->95587 95587->95095 95589 7bacae 95588->95589 95590 7bacd1 95589->95590 95616 82359c 82 API calls __wsopen_s 95589->95616 95590->95138 95593 7ffadb 95592->95593 95594 7bad92 95592->95594 95595 7cfddb 22 API calls 95594->95595 95596 7bad99 95595->95596 95617 7badcd 95596->95617 95599->95135 95600->95135 95601->95100 95602->95150 95603->95115 95604->95150 95605->95150 95606->95138 95607->95138 95608->95138 95609->95138 95610->95138 95611->95131 95612->95150 95613->95136 95614->95137 95615->95150 95616->95590 95621 7baddd 95617->95621 95618 7badb6 95618->95138 95619 7cfddb 22 API calls 95619->95621 95620 7ba961 22 API calls 95620->95621 95621->95618 95621->95619 95621->95620 95622 7badcd 22 API calls 95621->95622 95624 7ba8c7 22 API calls __fread_nolock 95621->95624 95622->95621 95624->95621 95625->95182 95626->95182 95627->95177 95628->95177 95629->95177 95630->95177 95631->95181 95632->95177 95633 7b1098 95638 7b42de 95633->95638 95637 7b10a7 95639 7ba961 22 API calls 95638->95639 95640 7b42f5 GetVersionExW 95639->95640 95641 7b6b57 22 API calls 95640->95641 95642 7b4342 95641->95642 95643 7b93b2 22 API calls 95642->95643 95652 7b4378 95642->95652 95644 7b436c 95643->95644 95646 7b37a0 22 API calls 95644->95646 95645 7b441b GetCurrentProcess IsWow64Process 95647 7b4437 95645->95647 95646->95652 95648 7b444f LoadLibraryA 95647->95648 95649 7f3824 GetSystemInfo 95647->95649 95650 7b449c GetSystemInfo 95648->95650 95651 7b4460 GetProcAddress 95648->95651 95655 7b4476 95650->95655 95651->95650 95654 7b4470 GetNativeSystemInfo 95651->95654 95652->95645 95653 7f37df 95652->95653 95654->95655 95656 7b447a FreeLibrary 95655->95656 95657 7b109d 95655->95657 95656->95657 95658 7d00a3 29 API calls __onexit 95657->95658 95658->95637 95659 7bf7bf 95660 7bf7d3 95659->95660 95661 7bfcb6 95659->95661 95663 7bfcc2 95660->95663 95664 7cfddb 22 API calls 95660->95664 95662 7baceb 23 API calls 95661->95662 95662->95663 95665 7baceb 23 API calls 95663->95665 95666 7bf7e5 95664->95666 95667 7bfd3d 95665->95667 95666->95663 95666->95667 95668 7bf83e 95666->95668 95696 821155 22 API calls 95667->95696 95670 7c1310 349 API calls 95668->95670 95675 7bed9d messages 95668->95675 95677 7bec76 messages 95670->95677 95671 7cfddb 22 API calls 95671->95677 95672 804beb 95702 82359c 82 API calls __wsopen_s 95672->95702 95673 7bfef7 95673->95675 95698 7ba8c7 22 API calls __fread_nolock 95673->95698 95677->95671 95677->95672 95677->95673 95677->95675 95678 804b0b 95677->95678 95679 7ba8c7 22 API calls 95677->95679 95680 7bf3ae messages 95677->95680 95681 804600 95677->95681 95687 7d0242 EnterCriticalSection LeaveCriticalSection LeaveCriticalSection WaitForSingleObjectEx EnterCriticalSection 95677->95687 95688 7bfbe3 95677->95688 95689 7ba961 22 API calls 95677->95689 95692 7d00a3 29 API calls pre_c_initialization 95677->95692 95693 7d01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent __Init_thread_footer 95677->95693 95694 7c01e0 349 API calls 2 library calls 95677->95694 95695 7c06a0 41 API calls messages 95677->95695 95700 82359c 82 API calls __wsopen_s 95678->95700 95679->95677 95680->95675 95699 82359c 82 API calls __wsopen_s 95680->95699 95681->95675 95697 7ba8c7 22 API calls __fread_nolock 95681->95697 95687->95677 95688->95675 95688->95680 95690 804bdc 95688->95690 95689->95677 95701 82359c 82 API calls __wsopen_s 95690->95701 95692->95677 95693->95677 95694->95677 95695->95677 95696->95675 95697->95675 95698->95675 95699->95675 95700->95675 95701->95672 95702->95675 95703 7d03fb 95704 7d0407 ___BuildCatchObject 95703->95704 95732 7cfeb1 95704->95732 95706 7d040e 95707 7d0561 95706->95707 95710 7d0438 95706->95710 95762 7d083f IsProcessorFeaturePresent IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter ___scrt_fastfail 95707->95762 95709 7d0568 95755 7d4e52 95709->95755 95721 7d0477 ___scrt_is_nonwritable_in_current_image ___scrt_release_startup_lock 95710->95721 95743 7e247d 95710->95743 95717 7d0457 95719 7d04d8 95751 7d0959 95719->95751 95721->95719 95758 7d4e1a 38 API calls 2 library calls 95721->95758 95723 7d04de 95724 7d04f3 95723->95724 95759 7d0992 GetModuleHandleW 95724->95759 95726 7d04fa 95726->95709 95727 7d04fe 95726->95727 95728 7d0507 95727->95728 95760 7d4df5 28 API calls _abort 95727->95760 95761 7d0040 13 API calls 2 library calls 95728->95761 95731 7d050f 95731->95717 95733 7cfeba 95732->95733 95764 7d0698 IsProcessorFeaturePresent 95733->95764 95735 7cfec6 95765 7d2c94 10 API calls 3 library calls 95735->95765 95737 7cfecb 95742 7cfecf 95737->95742 95766 7e2317 IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 95737->95766 95739 7cfed8 95740 7cfee6 95739->95740 95767 7d2cbd 8 API calls 3 library calls 95739->95767 95740->95706 95742->95706 95744 7e2494 95743->95744 95768 7d0a8c 95744->95768 95746 7d0451 95746->95717 95747 7e2421 95746->95747 95748 7e2450 95747->95748 95749 7d0a8c CatchGuardHandler 5 API calls 95748->95749 95750 7e2479 95749->95750 95750->95721 95776 7d2340 95751->95776 95754 7d097f 95754->95723 95778 7d4bcf 95755->95778 95758->95719 95759->95726 95760->95728 95761->95731 95762->95709 95764->95735 95765->95737 95766->95739 95767->95742 95769 7d0a95 95768->95769 95770 7d0a97 IsProcessorFeaturePresent 95768->95770 95769->95746 95772 7d0c5d 95770->95772 95775 7d0c21 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 95772->95775 95774 7d0d40 95774->95746 95775->95774 95777 7d096c GetStartupInfoW 95776->95777 95777->95754 95779 7d4bdb _abort 95778->95779 95780 7d4bf4 95779->95780 95781 7d4be2 95779->95781 95802 7e2f5e EnterCriticalSection 95780->95802 95817 7d4d29 GetModuleHandleW 95781->95817 95784 7d4be7 95784->95780 95818 7d4d6d GetModuleHandleExW 95784->95818 95787 7d4bfb 95798 7d4c70 95787->95798 95801 7d4c99 95787->95801 95803 7e21a8 95787->95803 95790 7d4cb6 95809 7d4ce8 95790->95809 95791 7d4ce2 95826 7f1d29 5 API calls CatchGuardHandler 95791->95826 95795 7e2421 _abort 5 API calls 95800 7d4c88 95795->95800 95796 7e2421 _abort 5 API calls 95796->95801 95798->95795 95798->95800 95800->95796 95806 7d4cd9 95801->95806 95802->95787 95827 7e1ee1 95803->95827 95853 7e2fa6 LeaveCriticalSection 95806->95853 95808 7d4cb2 95808->95790 95808->95791 95854 7e360c 95809->95854 95812 7d4d16 95815 7d4d6d _abort 8 API calls 95812->95815 95813 7d4cf6 GetPEB 95813->95812 95814 7d4d06 GetCurrentProcess TerminateProcess 95813->95814 95814->95812 95816 7d4d1e ExitProcess 95815->95816 95817->95784 95819 7d4dba 95818->95819 95820 7d4d97 GetProcAddress 95818->95820 95821 7d4dc9 95819->95821 95822 7d4dc0 FreeLibrary 95819->95822 95823 7d4dac 95820->95823 95824 7d0a8c CatchGuardHandler 5 API calls 95821->95824 95822->95821 95823->95819 95825 7d4bf3 95824->95825 95825->95780 95830 7e1e90 95827->95830 95829 7e1f05 95829->95798 95831 7e1e9c ___BuildCatchObject 95830->95831 95838 7e2f5e EnterCriticalSection 95831->95838 95833 7e1eaa 95839 7e1f31 95833->95839 95837 7e1ec8 __wsopen_s 95837->95829 95838->95833 95842 7e1f59 95839->95842 95844 7e1f51 95839->95844 95840 7d0a8c CatchGuardHandler 5 API calls 95841 7e1eb7 95840->95841 95845 7e1ed5 LeaveCriticalSection _abort 95841->95845 95842->95844 95846 7e29c8 95842->95846 95844->95840 95845->95837 95847 7e29d3 RtlFreeHeap 95846->95847 95848 7e29fc _free 95846->95848 95847->95848 95849 7e29e8 95847->95849 95848->95844 95852 7df2d9 20 API calls _abort 95849->95852 95851 7e29ee GetLastError 95851->95848 95852->95851 95853->95808 95855 7e3631 95854->95855 95856 7e3627 95854->95856 95861 7e2fd7 5 API calls 2 library calls 95855->95861 95858 7d0a8c CatchGuardHandler 5 API calls 95856->95858 95859 7d4cf2 95858->95859 95859->95812 95859->95813 95860 7e3648 95860->95856 95861->95860 95862 7bdddc 95865 7bb710 95862->95865 95866 7bb72b 95865->95866 95867 800146 95866->95867 95868 8000f8 95866->95868 95891 7bb750 95866->95891 95907 8358a2 349 API calls 2 library calls 95867->95907 95871 800102 95868->95871 95874 80010f 95868->95874 95868->95891 95905 835d33 349 API calls 95871->95905 95887 7bba20 95874->95887 95906 8361d0 349 API calls 2 library calls 95874->95906 95877 7bbbe0 40 API calls 95877->95891 95878 8003d9 95878->95878 95881 7bba4e 95883 800322 95910 835c0c 82 API calls 95883->95910 95887->95881 95911 82359c 82 API calls __wsopen_s 95887->95911 95889 7baceb 23 API calls 95889->95891 95891->95877 95891->95881 95891->95883 95891->95887 95891->95889 95892 7bec40 349 API calls 95891->95892 95893 7cd336 40 API calls 95891->95893 95896 7ba81b 41 API calls 95891->95896 95897 7cd2f0 40 API calls 95891->95897 95898 7ca01b 349 API calls 95891->95898 95899 7d0242 5 API calls __Init_thread_wait 95891->95899 95900 7cedcd 22 API calls 95891->95900 95901 7d00a3 29 API calls __onexit 95891->95901 95902 7d01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent 95891->95902 95903 7cee53 82 API calls 95891->95903 95904 7ce5ca 349 API calls 95891->95904 95908 80f6bf 23 API calls 95891->95908 95909 7ba8c7 22 API calls __fread_nolock 95891->95909 95892->95891 95893->95891 95896->95891 95897->95891 95898->95891 95899->95891 95900->95891 95901->95891 95902->95891 95903->95891 95904->95891 95905->95874 95906->95887 95907->95891 95908->95891 95909->95891 95910->95887 95911->95878 95912 7b1033 95917 7b4c91 95912->95917 95916 7b1042 95918 7ba961 22 API calls 95917->95918 95919 7b4cff 95918->95919 95925 7b3af0 95919->95925 95922 7b4d9c 95923 7b1038 95922->95923 95928 7b51f7 22 API calls __fread_nolock 95922->95928 95924 7d00a3 29 API calls __onexit 95923->95924 95924->95916 95929 7b3b1c 95925->95929 95928->95922 95930 7b3b29 95929->95930 95931 7b3b0f 95929->95931 95930->95931 95932 7b3b30 RegOpenKeyExW 95930->95932 95931->95922 95932->95931 95933 7b3b4a RegQueryValueExW 95932->95933 95934 7b3b6b 95933->95934 95935 7b3b80 RegCloseKey 95933->95935 95934->95935 95935->95931 95936 7b2e37 95937 7ba961 22 API calls 95936->95937 95938 7b2e4d 95937->95938 96015 7b4ae3 95938->96015 95940 7b2e6b 95941 7b3a5a 24 API calls 95940->95941 95942 7b2e7f 95941->95942 95943 7b9cb3 22 API calls 95942->95943 95944 7b2e8c 95943->95944 96029 7b4ecb 95944->96029 95947 7b2ead 96051 7ba8c7 22 API calls __fread_nolock 95947->96051 95948 7f2cb0 96068 822cf9 95948->96068 95950 7f2cc3 95951 7f2ccf 95950->95951 96094 7b4f39 95950->96094 95957 7b4f39 68 API calls 95951->95957 95954 7b2ec3 96052 7b6f88 22 API calls 95954->96052 95956 7b2ecf 95958 7b9cb3 22 API calls 95956->95958 95959 7f2ce5 95957->95959 95960 7b2edc 95958->95960 96100 7b3084 22 API calls 95959->96100 96053 7ba81b 41 API calls 95960->96053 95962 7b2eec 95965 7b9cb3 22 API calls 95962->95965 95964 7f2d02 96101 7b3084 22 API calls 95964->96101 95967 7b2f12 95965->95967 96054 7ba81b 41 API calls 95967->96054 95968 7f2d1e 95970 7b3a5a 24 API calls 95968->95970 95971 7f2d44 95970->95971 96102 7b3084 22 API calls 95971->96102 95972 7b2f21 95975 7ba961 22 API calls 95972->95975 95974 7f2d50 96103 7ba8c7 22 API calls __fread_nolock 95974->96103 95976 7b2f3f 95975->95976 96055 7b3084 22 API calls 95976->96055 95979 7f2d5e 96104 7b3084 22 API calls 95979->96104 95980 7b2f4b 96056 7d4a28 40 API calls 3 library calls 95980->96056 95983 7f2d6d 96105 7ba8c7 22 API calls __fread_nolock 95983->96105 95984 7b2f59 95984->95959 95985 7b2f63 95984->95985 96057 7d4a28 40 API calls 3 library calls 95985->96057 95988 7f2d83 96106 7b3084 22 API calls 95988->96106 95989 7b2f6e 95989->95964 95991 7b2f78 95989->95991 96058 7d4a28 40 API calls 3 library calls 95991->96058 95992 7f2d90 95994 7b2f83 95994->95968 95995 7b2f8d 95994->95995 96059 7d4a28 40 API calls 3 library calls 95995->96059 95997 7b2f98 95998 7b2fdc 95997->95998 96060 7b3084 22 API calls 95997->96060 95998->95983 95999 7b2fe8 95998->95999 95999->95992 96002 7b63eb 22 API calls 95999->96002 96001 7b2fbf 96061 7ba8c7 22 API calls __fread_nolock 96001->96061 96004 7b2ff8 96002->96004 96063 7b6a50 22 API calls 96004->96063 96005 7b2fcd 96062 7b3084 22 API calls 96005->96062 96008 7b3006 96064 7b70b0 23 API calls 96008->96064 96012 7b3021 96013 7b3065 96012->96013 96065 7b6f88 22 API calls 96012->96065 96066 7b70b0 23 API calls 96012->96066 96067 7b3084 22 API calls 96012->96067 96016 7b4af0 __wsopen_s 96015->96016 96017 7b6b57 22 API calls 96016->96017 96018 7b4b22 96016->96018 96017->96018 96019 7b4c6d 22 API calls 96018->96019 96025 7b4b58 96018->96025 96019->96018 96020 7b4c6d 22 API calls 96020->96025 96021 7b4c29 96022 7b9cb3 22 API calls 96021->96022 96028 7b4c5e 96021->96028 96024 7b4c52 96022->96024 96023 7b9cb3 22 API calls 96023->96025 96026 7b515f 22 API calls 96024->96026 96025->96020 96025->96021 96025->96023 96027 7b515f 22 API calls 96025->96027 96026->96028 96027->96025 96028->95940 96107 7b4e90 LoadLibraryA 96029->96107 96034 7f3ccf 96036 7b4f39 68 API calls 96034->96036 96035 7b4ef6 LoadLibraryExW 96115 7b4e59 LoadLibraryA 96035->96115 96038 7f3cd6 96036->96038 96040 7b4e59 3 API calls 96038->96040 96042 7f3cde 96040->96042 96137 7b50f5 96042->96137 96043 7b4f20 96043->96042 96044 7b4f2c 96043->96044 96046 7b4f39 68 API calls 96044->96046 96048 7b2ea5 96046->96048 96048->95947 96048->95948 96050 7f3d05 96051->95954 96052->95956 96053->95962 96054->95972 96055->95980 96056->95984 96057->95989 96058->95994 96059->95997 96060->96001 96061->96005 96062->95998 96063->96008 96064->96012 96065->96012 96066->96012 96067->96012 96069 822d15 96068->96069 96070 7b511f 64 API calls 96069->96070 96071 822d29 96070->96071 96270 822e66 96071->96270 96074 7b50f5 40 API calls 96075 822d56 96074->96075 96076 7b50f5 40 API calls 96075->96076 96077 822d66 96076->96077 96078 7b50f5 40 API calls 96077->96078 96079 822d81 96078->96079 96080 7b50f5 40 API calls 96079->96080 96081 822d9c 96080->96081 96082 7b511f 64 API calls 96081->96082 96083 822db3 96082->96083 96084 7dea0c ___std_exception_copy 21 API calls 96083->96084 96085 822dba 96084->96085 96086 7dea0c ___std_exception_copy 21 API calls 96085->96086 96087 822dc4 96086->96087 96088 7b50f5 40 API calls 96087->96088 96089 822dd8 96088->96089 96090 8228fe 27 API calls 96089->96090 96091 822dee 96090->96091 96092 822d3f 96091->96092 96276 8222ce 79 API calls 96091->96276 96092->95950 96095 7b4f4a 96094->96095 96096 7b4f43 96094->96096 96098 7b4f6a FreeLibrary 96095->96098 96099 7b4f59 96095->96099 96277 7de678 96096->96277 96098->96099 96099->95951 96100->95964 96101->95968 96102->95974 96103->95979 96104->95983 96105->95988 96106->95992 96108 7b4ea8 GetProcAddress 96107->96108 96109 7b4ec6 96107->96109 96110 7b4eb8 96108->96110 96112 7de5eb 96109->96112 96110->96109 96111 7b4ebf FreeLibrary 96110->96111 96111->96109 96145 7de52a 96112->96145 96114 7b4eea 96114->96034 96114->96035 96116 7b4e6e GetProcAddress 96115->96116 96117 7b4e8d 96115->96117 96118 7b4e7e 96116->96118 96120 7b4f80 96117->96120 96118->96117 96119 7b4e86 FreeLibrary 96118->96119 96119->96117 96121 7cfe0b 22 API calls 96120->96121 96122 7b4f95 96121->96122 96123 7b5722 22 API calls 96122->96123 96124 7b4fa1 __fread_nolock 96123->96124 96125 7f3d1d 96124->96125 96126 7b50a5 96124->96126 96136 7b4fdc 96124->96136 96210 82304d 74 API calls 96125->96210 96199 7b42a2 CreateStreamOnHGlobal 96126->96199 96129 7f3d22 96131 7b511f 64 API calls 96129->96131 96130 7b50f5 40 API calls 96130->96136 96132 7f3d45 96131->96132 96133 7b50f5 40 API calls 96132->96133 96135 7b506e messages 96133->96135 96135->96043 96136->96129 96136->96130 96136->96135 96205 7b511f 96136->96205 96138 7b5107 96137->96138 96139 7f3d70 96137->96139 96232 7de8c4 96138->96232 96142 8228fe 96253 82274e 96142->96253 96144 822919 96144->96050 96148 7de536 ___BuildCatchObject 96145->96148 96146 7de544 96170 7df2d9 20 API calls _abort 96146->96170 96148->96146 96150 7de574 96148->96150 96149 7de549 96171 7e27ec 26 API calls __wsopen_s 96149->96171 96152 7de579 96150->96152 96153 7de586 96150->96153 96172 7df2d9 20 API calls _abort 96152->96172 96162 7e8061 96153->96162 96156 7de554 __wsopen_s 96156->96114 96157 7de58f 96158 7de595 96157->96158 96159 7de5a2 96157->96159 96173 7df2d9 20 API calls _abort 96158->96173 96174 7de5d4 LeaveCriticalSection __fread_nolock 96159->96174 96163 7e806d ___BuildCatchObject 96162->96163 96175 7e2f5e EnterCriticalSection 96163->96175 96165 7e807b 96176 7e80fb 96165->96176 96169 7e80ac __wsopen_s 96169->96157 96170->96149 96171->96156 96172->96156 96173->96156 96174->96156 96175->96165 96179 7e811e 96176->96179 96177 7e8177 96195 7e4c7d 20 API calls 2 library calls 96177->96195 96179->96177 96185 7e8088 96179->96185 96193 7d918d EnterCriticalSection 96179->96193 96194 7d91a1 LeaveCriticalSection 96179->96194 96180 7e8180 96182 7e29c8 _free 20 API calls 96180->96182 96183 7e8189 96182->96183 96183->96185 96196 7e3405 11 API calls 2 library calls 96183->96196 96190 7e80b7 96185->96190 96186 7e81a8 96197 7d918d EnterCriticalSection 96186->96197 96189 7e81bb 96189->96185 96198 7e2fa6 LeaveCriticalSection 96190->96198 96192 7e80be 96192->96169 96193->96179 96194->96179 96195->96180 96196->96186 96197->96189 96198->96192 96200 7b42bc FindResourceExW 96199->96200 96204 7b42d9 96199->96204 96201 7f35ba LoadResource 96200->96201 96200->96204 96202 7f35cf SizeofResource 96201->96202 96201->96204 96203 7f35e3 LockResource 96202->96203 96202->96204 96203->96204 96204->96136 96206 7b512e 96205->96206 96207 7f3d90 96205->96207 96211 7dece3 96206->96211 96210->96129 96214 7deaaa 96211->96214 96213 7b513c 96213->96136 96217 7deab6 ___BuildCatchObject 96214->96217 96215 7deac2 96227 7df2d9 20 API calls _abort 96215->96227 96217->96215 96218 7deae8 96217->96218 96229 7d918d EnterCriticalSection 96218->96229 96220 7deac7 96228 7e27ec 26 API calls __wsopen_s 96220->96228 96221 7deaf4 96230 7dec0a 62 API calls 2 library calls 96221->96230 96224 7deb08 96231 7deb27 LeaveCriticalSection __fread_nolock 96224->96231 96225 7dead2 __wsopen_s 96225->96213 96227->96220 96228->96225 96229->96221 96230->96224 96231->96225 96235 7de8e1 96232->96235 96234 7b5118 96234->96142 96236 7de8ed ___BuildCatchObject 96235->96236 96237 7de92d 96236->96237 96238 7de900 ___scrt_fastfail 96236->96238 96239 7de925 __wsopen_s 96236->96239 96250 7d918d EnterCriticalSection 96237->96250 96248 7df2d9 20 API calls _abort 96238->96248 96239->96234 96242 7de937 96251 7de6f8 38 API calls 4 library calls 96242->96251 96244 7de91a 96249 7e27ec 26 API calls __wsopen_s 96244->96249 96245 7de94e 96252 7de96c LeaveCriticalSection __fread_nolock 96245->96252 96248->96244 96249->96239 96250->96242 96251->96245 96252->96239 96256 7de4e8 96253->96256 96255 82275d 96255->96144 96259 7de469 96256->96259 96258 7de505 96258->96255 96260 7de48c 96259->96260 96261 7de478 96259->96261 96265 7de488 __alldvrm 96260->96265 96269 7e333f 11 API calls 2 library calls 96260->96269 96267 7df2d9 20 API calls _abort 96261->96267 96264 7de47d 96268 7e27ec 26 API calls __wsopen_s 96264->96268 96265->96258 96267->96264 96268->96265 96269->96265 96275 822e7a 96270->96275 96271 822d3b 96271->96074 96271->96092 96272 7b50f5 40 API calls 96272->96275 96273 8228fe 27 API calls 96273->96275 96274 7b511f 64 API calls 96274->96275 96275->96271 96275->96272 96275->96273 96275->96274 96276->96092 96278 7de684 ___BuildCatchObject 96277->96278 96279 7de6aa 96278->96279 96280 7de695 96278->96280 96289 7de6a5 __wsopen_s 96279->96289 96290 7d918d EnterCriticalSection 96279->96290 96307 7df2d9 20 API calls _abort 96280->96307 96283 7de69a 96308 7e27ec 26 API calls __wsopen_s 96283->96308 96284 7de6c6 96291 7de602 96284->96291 96287 7de6d1 96309 7de6ee LeaveCriticalSection __fread_nolock 96287->96309 96289->96095 96290->96284 96292 7de60f 96291->96292 96293 7de624 96291->96293 96342 7df2d9 20 API calls _abort 96292->96342 96299 7de61f 96293->96299 96310 7ddc0b 96293->96310 96295 7de614 96343 7e27ec 26 API calls __wsopen_s 96295->96343 96299->96287 96303 7de646 96327 7e862f 96303->96327 96306 7e29c8 _free 20 API calls 96306->96299 96307->96283 96308->96289 96309->96289 96311 7ddc23 96310->96311 96312 7ddc1f 96310->96312 96311->96312 96313 7dd955 __fread_nolock 26 API calls 96311->96313 96316 7e4d7a 96312->96316 96314 7ddc43 96313->96314 96344 7e59be 62 API calls 4 library calls 96314->96344 96317 7de640 96316->96317 96318 7e4d90 96316->96318 96320 7dd955 96317->96320 96318->96317 96319 7e29c8 _free 20 API calls 96318->96319 96319->96317 96321 7dd976 96320->96321 96322 7dd961 96320->96322 96321->96303 96345 7df2d9 20 API calls _abort 96322->96345 96324 7dd966 96346 7e27ec 26 API calls __wsopen_s 96324->96346 96326 7dd971 96326->96303 96328 7e863e 96327->96328 96331 7e8653 96327->96331 96350 7df2c6 20 API calls _abort 96328->96350 96330 7e868e 96352 7df2c6 20 API calls _abort 96330->96352 96331->96330 96336 7e867a 96331->96336 96332 7e8643 96351 7df2d9 20 API calls _abort 96332->96351 96334 7e8693 96353 7df2d9 20 API calls _abort 96334->96353 96347 7e8607 96336->96347 96339 7e869b 96354 7e27ec 26 API calls __wsopen_s 96339->96354 96340 7de64c 96340->96299 96340->96306 96342->96295 96343->96299 96344->96312 96345->96324 96346->96326 96355 7e8585 96347->96355 96349 7e862b 96349->96340 96350->96332 96351->96340 96352->96334 96353->96339 96354->96340 96356 7e8591 ___BuildCatchObject 96355->96356 96366 7e5147 EnterCriticalSection 96356->96366 96358 7e859f 96359 7e85c6 96358->96359 96360 7e85d1 96358->96360 96367 7e86ae 96359->96367 96382 7df2d9 20 API calls _abort 96360->96382 96363 7e85cc 96383 7e85fb LeaveCriticalSection __wsopen_s 96363->96383 96365 7e85ee __wsopen_s 96365->96349 96366->96358 96384 7e53c4 96367->96384 96369 7e86c4 96397 7e5333 21 API calls 3 library calls 96369->96397 96371 7e86be 96371->96369 96372 7e86f6 96371->96372 96375 7e53c4 __wsopen_s 26 API calls 96371->96375 96372->96369 96373 7e53c4 __wsopen_s 26 API calls 96372->96373 96376 7e8702 CloseHandle 96373->96376 96374 7e871c 96377 7e873e 96374->96377 96398 7df2a3 20 API calls 2 library calls 96374->96398 96378 7e86ed 96375->96378 96376->96369 96380 7e870e GetLastError 96376->96380 96377->96363 96379 7e53c4 __wsopen_s 26 API calls 96378->96379 96379->96372 96380->96369 96382->96363 96383->96365 96385 7e53d1 96384->96385 96387 7e53e6 96384->96387 96399 7df2c6 20 API calls _abort 96385->96399 96392 7e540b 96387->96392 96401 7df2c6 20 API calls _abort 96387->96401 96389 7e53d6 96400 7df2d9 20 API calls _abort 96389->96400 96390 7e5416 96402 7df2d9 20 API calls _abort 96390->96402 96392->96371 96394 7e53de 96394->96371 96395 7e541e 96403 7e27ec 26 API calls __wsopen_s 96395->96403 96397->96374 96398->96377 96399->96389 96400->96394 96401->96390 96402->96395 96403->96394 96404 7b3156 96407 7b3170 96404->96407 96408 7b3187 96407->96408 96409 7b31eb 96408->96409 96410 7b318c 96408->96410 96445 7b31e9 96408->96445 96414 7f2dfb 96409->96414 96415 7b31f1 96409->96415 96411 7b3199 96410->96411 96412 7b3265 PostQuitMessage 96410->96412 96417 7f2e7c 96411->96417 96418 7b31a4 96411->96418 96448 7b316a 96412->96448 96413 7b31d0 DefWindowProcW 96413->96448 96466 7b18e2 10 API calls 96414->96466 96419 7b31f8 96415->96419 96420 7b321d SetTimer RegisterWindowMessageW 96415->96420 96479 81bf30 34 API calls ___scrt_fastfail 96417->96479 96424 7b31ae 96418->96424 96425 7f2e68 96418->96425 96421 7f2d9c 96419->96421 96422 7b3201 KillTimer 96419->96422 96426 7b3246 CreatePopupMenu 96420->96426 96420->96448 96434 7f2dd7 MoveWindow 96421->96434 96435 7f2da1 96421->96435 96452 7b30f2 96422->96452 96423 7f2e1c 96467 7ce499 42 API calls 96423->96467 96431 7f2e4d 96424->96431 96432 7b31b9 96424->96432 96456 81c161 96425->96456 96426->96448 96431->96413 96478 810ad7 22 API calls 96431->96478 96437 7b3253 96432->96437 96443 7b31c4 96432->96443 96433 7f2e8e 96433->96413 96433->96448 96434->96448 96438 7f2da7 96435->96438 96439 7f2dc6 SetFocus 96435->96439 96464 7b326f 44 API calls ___scrt_fastfail 96437->96464 96438->96443 96444 7f2db0 96438->96444 96439->96448 96443->96413 96449 7b30f2 Shell_NotifyIconW 96443->96449 96465 7b18e2 10 API calls 96444->96465 96445->96413 96446 7b3263 96446->96448 96450 7f2e41 96449->96450 96468 7b3837 96450->96468 96453 7b3154 96452->96453 96454 7b3104 ___scrt_fastfail 96452->96454 96463 7b3c50 DeleteObject DestroyWindow 96453->96463 96455 7b3123 Shell_NotifyIconW 96454->96455 96455->96453 96457 81c276 96456->96457 96458 81c179 ___scrt_fastfail 96456->96458 96457->96448 96480 7b3923 96458->96480 96460 81c25f KillTimer SetTimer 96460->96457 96461 81c1a0 96461->96460 96462 81c251 Shell_NotifyIconW 96461->96462 96462->96460 96463->96448 96464->96446 96465->96448 96466->96423 96467->96443 96469 7b3862 ___scrt_fastfail 96468->96469 96508 7b4212 96469->96508 96472 7b38e8 96474 7f3386 Shell_NotifyIconW 96472->96474 96475 7b3906 Shell_NotifyIconW 96472->96475 96476 7b3923 24 API calls 96475->96476 96477 7b391c 96476->96477 96477->96445 96478->96445 96479->96433 96481 7b393f 96480->96481 96500 7b3a13 96480->96500 96502 7b6270 96481->96502 96484 7b395a 96486 7b6b57 22 API calls 96484->96486 96485 7f3393 LoadStringW 96487 7f33ad 96485->96487 96488 7b396f 96486->96488 96495 7b3994 ___scrt_fastfail 96487->96495 96507 7ba8c7 22 API calls __fread_nolock 96487->96507 96489 7f33c9 96488->96489 96490 7b397c 96488->96490 96493 7b6350 22 API calls 96489->96493 96490->96487 96492 7b3986 96490->96492 96494 7b6350 22 API calls 96492->96494 96496 7f33d7 96493->96496 96494->96495 96498 7b39f9 Shell_NotifyIconW 96495->96498 96496->96495 96497 7b33c6 22 API calls 96496->96497 96499 7f33f9 96497->96499 96498->96500 96501 7b33c6 22 API calls 96499->96501 96500->96461 96501->96495 96503 7cfe0b 22 API calls 96502->96503 96504 7b6295 96503->96504 96505 7cfddb 22 API calls 96504->96505 96506 7b394d 96505->96506 96506->96484 96506->96485 96507->96495 96509 7f35a4 96508->96509 96510 7b38b7 96508->96510 96509->96510 96511 7f35ad DestroyIcon 96509->96511 96510->96472 96512 81c874 42 API calls _strftime 96510->96512 96511->96510 96512->96472 96513 842a55 96521 821ebc 96513->96521 96516 842a70 96523 8139c0 22 API calls 96516->96523 96518 842a7c 96524 81417d 22 API calls __fread_nolock 96518->96524 96520 842a87 96522 821ec3 IsWindow 96521->96522 96522->96516 96522->96520 96523->96518 96524->96520 96525 803f75 96536 7cceb1 96525->96536 96527 803f8b 96528 804006 96527->96528 96545 7ce300 23 API calls 96527->96545 96531 7bbf40 349 API calls 96528->96531 96530 803fe6 96534 804052 96530->96534 96546 821abf 22 API calls 96530->96546 96531->96534 96533 804a88 96534->96533 96547 82359c 82 API calls __wsopen_s 96534->96547 96537 7ccebf 96536->96537 96538 7cced2 96536->96538 96539 7baceb 23 API calls 96537->96539 96540 7ccf05 96538->96540 96541 7cced7 96538->96541 96544 7ccec9 96539->96544 96543 7baceb 23 API calls 96540->96543 96542 7cfddb 22 API calls 96541->96542 96542->96544 96543->96544 96544->96527 96545->96530 96546->96528 96547->96533 96548 7b1cad SystemParametersInfoW 96549 7b2de3 96550 7b2df0 __wsopen_s 96549->96550 96551 7b2e09 96550->96551 96552 7f2c2b ___scrt_fastfail 96550->96552 96553 7b3aa2 23 API calls 96551->96553 96554 7f2c47 GetOpenFileNameW 96552->96554 96555 7b2e12 96553->96555 96556 7f2c96 96554->96556 96565 7b2da5 96555->96565 96558 7b6b57 22 API calls 96556->96558 96560 7f2cab 96558->96560 96560->96560 96562 7b2e27 96583 7b44a8 96562->96583 96566 7f1f50 __wsopen_s 96565->96566 96567 7b2db2 GetLongPathNameW 96566->96567 96568 7b6b57 22 API calls 96567->96568 96569 7b2dda 96568->96569 96570 7b3598 96569->96570 96571 7ba961 22 API calls 96570->96571 96572 7b35aa 96571->96572 96573 7b3aa2 23 API calls 96572->96573 96574 7b35b5 96573->96574 96575 7b35c0 96574->96575 96578 7f32eb 96574->96578 96577 7b515f 22 API calls 96575->96577 96579 7b35cc 96577->96579 96580 7f330d 96578->96580 96618 7cce60 41 API calls 96578->96618 96612 7b35f3 96579->96612 96582 7b35df 96582->96562 96584 7b4ecb 94 API calls 96583->96584 96585 7b44cd 96584->96585 96586 7f3833 96585->96586 96587 7b4ecb 94 API calls 96585->96587 96588 822cf9 80 API calls 96586->96588 96589 7b44e1 96587->96589 96590 7f3848 96588->96590 96589->96586 96591 7b44e9 96589->96591 96592 7f384c 96590->96592 96593 7f3869 96590->96593 96596 7f3854 96591->96596 96597 7b44f5 96591->96597 96594 7b4f39 68 API calls 96592->96594 96595 7cfe0b 22 API calls 96593->96595 96594->96596 96605 7f38ae 96595->96605 96620 81da5a 82 API calls 96596->96620 96619 7b940c 136 API calls 2 library calls 96597->96619 96600 7f3862 96600->96593 96601 7b2e31 96602 7b4f39 68 API calls 96604 7f3a5f 96602->96604 96604->96602 96626 81989b 82 API calls __wsopen_s 96604->96626 96605->96604 96609 7b9cb3 22 API calls 96605->96609 96621 81967e 22 API calls __fread_nolock 96605->96621 96622 8195ad 42 API calls _wcslen 96605->96622 96623 820b5a 22 API calls 96605->96623 96624 7ba4a1 22 API calls __fread_nolock 96605->96624 96625 7b3ff7 22 API calls 96605->96625 96609->96605 96613 7b3605 96612->96613 96617 7b3624 __fread_nolock 96612->96617 96615 7cfe0b 22 API calls 96613->96615 96614 7cfddb 22 API calls 96616 7b363b 96614->96616 96615->96617 96616->96582 96617->96614 96618->96578 96619->96601 96620->96600 96621->96605 96622->96605 96623->96605 96624->96605 96625->96605 96626->96604 96627 7f2ba5 96628 7f2baf 96627->96628 96629 7b2b25 96627->96629 96631 7b3a5a 24 API calls 96628->96631 96655 7b2b83 7 API calls 96629->96655 96633 7f2bb8 96631->96633 96635 7b9cb3 22 API calls 96633->96635 96637 7f2bc6 96635->96637 96636 7b2b2f 96642 7b3837 49 API calls 96636->96642 96643 7b2b44 96636->96643 96638 7f2bce 96637->96638 96639 7f2bf5 96637->96639 96641 7b33c6 22 API calls 96638->96641 96640 7b33c6 22 API calls 96639->96640 96644 7f2bf1 GetForegroundWindow ShellExecuteW 96640->96644 96645 7f2bd9 96641->96645 96642->96643 96646 7b2b5f 96643->96646 96649 7b30f2 Shell_NotifyIconW 96643->96649 96650 7f2c26 96644->96650 96648 7b6350 22 API calls 96645->96648 96652 7b2b66 SetCurrentDirectoryW 96646->96652 96651 7f2be7 96648->96651 96649->96646 96650->96646 96653 7b33c6 22 API calls 96651->96653 96654 7b2b7a 96652->96654 96653->96644 96659 7b2cd4 7 API calls 96655->96659 96657 7b2b2a 96658 7b2c63 CreateWindowExW CreateWindowExW ShowWindow ShowWindow 96657->96658 96658->96636 96659->96657 96660 7e8402 96665 7e81be 96660->96665 96663 7e842a 96670 7e81ef try_get_first_available_module 96665->96670 96667 7e83ee 96684 7e27ec 26 API calls __wsopen_s 96667->96684 96669 7e8343 96669->96663 96677 7f0984 96669->96677 96670->96670 96673 7e8338 96670->96673 96680 7d8e0b 40 API calls 2 library calls 96670->96680 96672 7e838c 96672->96673 96681 7d8e0b 40 API calls 2 library calls 96672->96681 96673->96669 96683 7df2d9 20 API calls _abort 96673->96683 96675 7e83ab 96675->96673 96682 7d8e0b 40 API calls 2 library calls 96675->96682 96685 7f0081 96677->96685 96679 7f099f 96679->96663 96680->96672 96681->96675 96682->96673 96683->96667 96684->96669 96687 7f008d ___BuildCatchObject 96685->96687 96686 7f009b 96742 7df2d9 20 API calls _abort 96686->96742 96687->96686 96689 7f00d4 96687->96689 96696 7f065b 96689->96696 96690 7f00a0 96743 7e27ec 26 API calls __wsopen_s 96690->96743 96694 7f00aa __wsopen_s 96694->96679 96697 7f0678 96696->96697 96698 7f068d 96697->96698 96699 7f06a6 96697->96699 96759 7df2c6 20 API calls _abort 96698->96759 96745 7e5221 96699->96745 96702 7f06ab 96704 7f06cb 96702->96704 96705 7f06b4 96702->96705 96703 7f0692 96760 7df2d9 20 API calls _abort 96703->96760 96758 7f039a CreateFileW 96704->96758 96761 7df2c6 20 API calls _abort 96705->96761 96709 7f06b9 96762 7df2d9 20 API calls _abort 96709->96762 96710 7f00f8 96744 7f0121 LeaveCriticalSection __wsopen_s 96710->96744 96712 7f0781 GetFileType 96713 7f078c GetLastError 96712->96713 96714 7f07d3 96712->96714 96765 7df2a3 20 API calls 2 library calls 96713->96765 96767 7e516a 21 API calls 3 library calls 96714->96767 96715 7f0756 GetLastError 96764 7df2a3 20 API calls 2 library calls 96715->96764 96718 7f0704 96718->96712 96718->96715 96763 7f039a CreateFileW 96718->96763 96719 7f079a CloseHandle 96719->96703 96721 7f07c3 96719->96721 96766 7df2d9 20 API calls _abort 96721->96766 96723 7f0749 96723->96712 96723->96715 96725 7f07f4 96726 7f0840 96725->96726 96768 7f05ab 72 API calls 4 library calls 96725->96768 96731 7f086d 96726->96731 96769 7f014d 72 API calls 4 library calls 96726->96769 96727 7f07c8 96727->96703 96730 7f0866 96730->96731 96732 7f087e 96730->96732 96733 7e86ae __wsopen_s 29 API calls 96731->96733 96732->96710 96734 7f08fc CloseHandle 96732->96734 96733->96710 96770 7f039a CreateFileW 96734->96770 96736 7f0927 96737 7f0931 GetLastError 96736->96737 96741 7f095d 96736->96741 96771 7df2a3 20 API calls 2 library calls 96737->96771 96739 7f093d 96772 7e5333 21 API calls 3 library calls 96739->96772 96741->96710 96742->96690 96743->96694 96744->96694 96746 7e522d ___BuildCatchObject 96745->96746 96773 7e2f5e EnterCriticalSection 96746->96773 96748 7e527b 96774 7e532a 96748->96774 96749 7e5234 96749->96748 96750 7e5259 96749->96750 96755 7e52c7 EnterCriticalSection 96749->96755 96777 7e5000 21 API calls 3 library calls 96750->96777 96753 7e52a4 __wsopen_s 96753->96702 96754 7e525e 96754->96748 96778 7e5147 EnterCriticalSection 96754->96778 96755->96748 96756 7e52d4 LeaveCriticalSection 96755->96756 96756->96749 96758->96718 96759->96703 96760->96710 96761->96709 96762->96703 96763->96723 96764->96703 96765->96719 96766->96727 96767->96725 96768->96726 96769->96730 96770->96736 96771->96739 96772->96741 96773->96749 96779 7e2fa6 LeaveCriticalSection 96774->96779 96776 7e5331 96776->96753 96777->96754 96778->96748 96779->96776 96780 7f2402 96783 7b1410 96780->96783 96784 7b144f mciSendStringW 96783->96784 96785 7f24b8 DestroyWindow 96783->96785 96786 7b146b 96784->96786 96787 7b16c6 96784->96787 96798 7f24c4 96785->96798 96789 7b1479 96786->96789 96786->96798 96787->96786 96788 7b16d5 UnregisterHotKey 96787->96788 96788->96787 96816 7b182e 96789->96816 96792 7f2509 96797 7f252d 96792->96797 96799 7f251c FreeLibrary 96792->96799 96793 7f24d8 96793->96798 96822 7b6246 CloseHandle 96793->96822 96794 7f24e2 FindClose 96794->96798 96795 7b148e 96795->96797 96804 7b149c 96795->96804 96800 7f2541 VirtualFree 96797->96800 96807 7b1509 96797->96807 96798->96792 96798->96793 96798->96794 96799->96792 96800->96797 96801 7b14f8 CoUninitialize 96801->96807 96802 7f2589 96809 7f2598 messages 96802->96809 96823 8232eb 6 API calls messages 96802->96823 96803 7b1514 96806 7b1524 96803->96806 96804->96801 96820 7b1944 VirtualFreeEx CloseHandle 96806->96820 96807->96802 96807->96803 96811 7f2627 96809->96811 96824 8164d4 22 API calls messages 96809->96824 96812 7b153a 96812->96809 96813 7b161f 96812->96813 96813->96811 96821 7b1876 CloseHandle InternetCloseHandle InternetCloseHandle WaitForSingleObject 96813->96821 96815 7b16c1 96818 7b183b 96816->96818 96817 7b1480 96817->96792 96817->96795 96818->96817 96825 81702a 22 API calls 96818->96825 96820->96812 96821->96815 96822->96793 96823->96802 96824->96809 96825->96818 96826 7b1044 96831 7b10f3 96826->96831 96828 7b104a 96867 7d00a3 29 API calls __onexit 96828->96867 96830 7b1054 96868 7b1398 96831->96868 96835 7b116a 96836 7ba961 22 API calls 96835->96836 96837 7b1174 96836->96837 96838 7ba961 22 API calls 96837->96838 96839 7b117e 96838->96839 96840 7ba961 22 API calls 96839->96840 96841 7b1188 96840->96841 96842 7ba961 22 API calls 96841->96842 96843 7b11c6 96842->96843 96844 7ba961 22 API calls 96843->96844 96845 7b1292 96844->96845 96878 7b171c 96845->96878 96849 7b12c4 96850 7ba961 22 API calls 96849->96850 96851 7b12ce 96850->96851 96852 7c1940 9 API calls 96851->96852 96853 7b12f9 96852->96853 96899 7b1aab 96853->96899 96855 7b1315 96856 7b1325 GetStdHandle 96855->96856 96857 7b137a 96856->96857 96858 7f2485 96856->96858 96861 7b1387 OleInitialize 96857->96861 96858->96857 96859 7f248e 96858->96859 96860 7cfddb 22 API calls 96859->96860 96862 7f2495 96860->96862 96861->96828 96906 82011d InitializeCriticalSectionAndSpinCount InterlockedExchange GetCurrentProcess GetCurrentProcess DuplicateHandle 96862->96906 96864 7f249e 96907 820944 CreateThread 96864->96907 96866 7f24aa CloseHandle 96866->96857 96867->96830 96908 7b13f1 96868->96908 96871 7b13f1 22 API calls 96872 7b13d0 96871->96872 96873 7ba961 22 API calls 96872->96873 96874 7b13dc 96873->96874 96875 7b6b57 22 API calls 96874->96875 96876 7b1129 96875->96876 96877 7b1bc3 6 API calls 96876->96877 96877->96835 96879 7ba961 22 API calls 96878->96879 96880 7b172c 96879->96880 96881 7ba961 22 API calls 96880->96881 96882 7b1734 96881->96882 96883 7ba961 22 API calls 96882->96883 96884 7b174f 96883->96884 96885 7cfddb 22 API calls 96884->96885 96886 7b129c 96885->96886 96887 7b1b4a 96886->96887 96888 7b1b58 96887->96888 96889 7ba961 22 API calls 96888->96889 96890 7b1b63 96889->96890 96891 7ba961 22 API calls 96890->96891 96892 7b1b6e 96891->96892 96893 7ba961 22 API calls 96892->96893 96894 7b1b79 96893->96894 96895 7ba961 22 API calls 96894->96895 96896 7b1b84 96895->96896 96897 7cfddb 22 API calls 96896->96897 96898 7b1b96 RegisterWindowMessageW 96897->96898 96898->96849 96900 7b1abb 96899->96900 96901 7f272d 96899->96901 96903 7cfddb 22 API calls 96900->96903 96915 823209 23 API calls 96901->96915 96905 7b1ac3 96903->96905 96904 7f2738 96905->96855 96906->96864 96907->96866 96916 82092a 28 API calls 96907->96916 96909 7ba961 22 API calls 96908->96909 96910 7b13fc 96909->96910 96911 7ba961 22 API calls 96910->96911 96912 7b1404 96911->96912 96913 7ba961 22 API calls 96912->96913 96914 7b13c6 96913->96914 96914->96871 96915->96904

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 394 7b42de-7b434d call 7ba961 GetVersionExW call 7b6b57 399 7f3617-7f362a 394->399 400 7b4353 394->400 402 7f362b-7f362f 399->402 401 7b4355-7b4357 400->401 403 7b435d-7b43bc call 7b93b2 call 7b37a0 401->403 404 7f3656 401->404 405 7f3632-7f363e 402->405 406 7f3631 402->406 423 7f37df-7f37e6 403->423 424 7b43c2-7b43c4 403->424 409 7f365d-7f3660 404->409 405->402 408 7f3640-7f3642 405->408 406->405 408->401 411 7f3648-7f364f 408->411 413 7b441b-7b4435 GetCurrentProcess IsWow64Process 409->413 414 7f3666-7f36a8 409->414 411->399 412 7f3651 411->412 412->404 416 7b4437 413->416 417 7b4494-7b449a 413->417 414->413 418 7f36ae-7f36b1 414->418 420 7b443d-7b4449 416->420 417->420 421 7f36db-7f36e5 418->421 422 7f36b3-7f36bd 418->422 425 7b444f-7b445e LoadLibraryA 420->425 426 7f3824-7f3828 GetSystemInfo 420->426 430 7f36f8-7f3702 421->430 431 7f36e7-7f36f3 421->431 427 7f36bf-7f36c5 422->427 428 7f36ca-7f36d6 422->428 432 7f37e8 423->432 433 7f3806-7f3809 423->433 424->409 429 7b43ca-7b43dd 424->429 436 7b449c-7b44a6 GetSystemInfo 425->436 437 7b4460-7b446e GetProcAddress 425->437 427->413 428->413 438 7b43e3-7b43e5 429->438 439 7f3726-7f372f 429->439 441 7f3715-7f3721 430->441 442 7f3704-7f3710 430->442 431->413 440 7f37ee 432->440 434 7f380b-7f381a 433->434 435 7f37f4-7f37fc 433->435 434->440 445 7f381c-7f3822 434->445 435->433 447 7b4476-7b4478 436->447 437->436 446 7b4470-7b4474 GetNativeSystemInfo 437->446 448 7b43eb-7b43ee 438->448 449 7f374d-7f3762 438->449 443 7f373c-7f3748 439->443 444 7f3731-7f3737 439->444 440->435 441->413 442->413 443->413 444->413 445->435 446->447 452 7b447a-7b447b FreeLibrary 447->452 453 7b4481-7b4493 447->453 454 7f3791-7f3794 448->454 455 7b43f4-7b440f 448->455 450 7f376f-7f377b 449->450 451 7f3764-7f376a 449->451 450->413 451->413 452->453 454->413 456 7f379a-7f37c1 454->456 457 7b4415 455->457 458 7f3780-7f378c 455->458 459 7f37ce-7f37da 456->459 460 7f37c3-7f37c9 456->460 457->413 458->413 459->413 460->413
                                                      APIs
                                                      • GetVersionExW.KERNEL32(?), ref: 007B430D
                                                        • Part of subcall function 007B6B57: _wcslen.LIBCMT ref: 007B6B6A
                                                      • GetCurrentProcess.KERNEL32(?,0084CB64,00000000,?,?), ref: 007B4422
                                                      • IsWow64Process.KERNEL32(00000000,?,?), ref: 007B4429
                                                      • LoadLibraryA.KERNEL32(kernel32.dll,?,?), ref: 007B4454
                                                      • GetProcAddress.KERNEL32(00000000,GetNativeSystemInfo), ref: 007B4466
                                                      • GetNativeSystemInfo.KERNELBASE(?,?,?), ref: 007B4474
                                                      • FreeLibrary.KERNEL32(00000000,?,?), ref: 007B447B
                                                      • GetSystemInfo.KERNEL32(?,?,?), ref: 007B44A0
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: InfoLibraryProcessSystem$AddressCurrentFreeLoadNativeProcVersionWow64_wcslen
                                                      • String ID: GetNativeSystemInfo$kernel32.dll$|O
                                                      • API String ID: 3290436268-3101561225
                                                      • Opcode ID: 31c10f58583c204bf89f278d7d2773f985706a9e11b57451ca549c14679100e9
                                                      • Instruction ID: 61ec2583f1aaf40ba2d2d5b8f74cc5127ade140d97c6b80256baa2f274d974ae
                                                      • Opcode Fuzzy Hash: 31c10f58583c204bf89f278d7d2773f985706a9e11b57451ca549c14679100e9
                                                      • Instruction Fuzzy Hash: A7A1737690A2C4DFCF12D76D7C8D6E67FAC7B26740B184899D18193B23DE6C460ACB21

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 798 7b42a2-7b42ba CreateStreamOnHGlobal 799 7b42da-7b42dd 798->799 800 7b42bc-7b42d3 FindResourceExW 798->800 801 7b42d9 800->801 802 7f35ba-7f35c9 LoadResource 800->802 801->799 802->801 803 7f35cf-7f35dd SizeofResource 802->803 803->801 804 7f35e3-7f35ee LockResource 803->804 804->801 805 7f35f4-7f3612 804->805 805->801
                                                      APIs
                                                      • CreateStreamOnHGlobal.COMBASE(00000000,00000001,?,?,?,?,?,007B50AA,?,?,00000000,00000000), ref: 007B42B2
                                                      • FindResourceExW.KERNEL32(?,0000000A,SCRIPT,00000000,?,?,007B50AA,?,?,00000000,00000000), ref: 007B42C9
                                                      • LoadResource.KERNEL32(?,00000000,?,?,007B50AA,?,?,00000000,00000000,?,?,?,?,?,?,007B4F20), ref: 007F35BE
                                                      • SizeofResource.KERNEL32(?,00000000,?,?,007B50AA,?,?,00000000,00000000,?,?,?,?,?,?,007B4F20), ref: 007F35D3
                                                      • LockResource.KERNEL32(007B50AA,?,?,007B50AA,?,?,00000000,00000000,?,?,?,?,?,?,007B4F20,?), ref: 007F35E6
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Resource$CreateFindGlobalLoadLockSizeofStream
                                                      • String ID: SCRIPT
                                                      • API String ID: 3051347437-3967369404
                                                      • Opcode ID: cf4bbba20324b258387833fd08b62981aea744ae5bb7e1d5baaf0f0c933de58b
                                                      • Instruction ID: 9dc274f03fe5e6c1ad48d25770722103672931bd6b9fee83b357adfcf5360853
                                                      • Opcode Fuzzy Hash: cf4bbba20324b258387833fd08b62981aea744ae5bb7e1d5baaf0f0c933de58b
                                                      • Instruction Fuzzy Hash: 41117C75201700BFEB218FA5DC49FA77BBDFBC6B51F104169B412D6260DBB1D800D620

                                                      Control-flow Graph

                                                      APIs
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 007B2B6B
                                                        • Part of subcall function 007B3A5A: GetModuleFileNameW.KERNEL32(00000000,?,00007FFF,00881418,?,007B2E7F,?,?,?,00000000), ref: 007B3A78
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • GetForegroundWindow.USER32(runas,?,?,?,?,?,00872224), ref: 007F2C10
                                                      • ShellExecuteW.SHELL32(00000000,?,?,00872224), ref: 007F2C17
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CurrentDirectoryExecuteFileForegroundModuleNameShellWindow_wcslen
                                                      • String ID: runas
                                                      • API String ID: 448630720-4000483414
                                                      • Opcode ID: 2694e82f5ba4045dbc9d9f64798f5717c707d6bab01aa909cc4224f7c2f580bd
                                                      • Instruction ID: 7ac80b73e449079be8b94949505e84ee727149f2b9ca01b8cbae699e9eb4802c
                                                      • Opcode Fuzzy Hash: 2694e82f5ba4045dbc9d9f64798f5717c707d6bab01aa909cc4224f7c2f580bd
                                                      • Instruction Fuzzy Hash: 1611D571209305EAC704FF60D859BEEBBA9AB91700F44042DF256431A3DF2C898AC712

                                                      Control-flow Graph

                                                      APIs
                                                      • CreateToolhelp32Snapshot.KERNEL32 ref: 0083A6AC
                                                      • Process32FirstW.KERNEL32(00000000,?), ref: 0083A6BA
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • Process32NextW.KERNEL32(00000000,?), ref: 0083A79C
                                                      • CloseHandle.KERNELBASE(00000000), ref: 0083A7AB
                                                        • Part of subcall function 007CCE60: CompareStringW.KERNEL32(00000409,00000001,?,00000000,00000000,?,?,00000000,?,007F3303,?), ref: 007CCE8A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process32$CloseCompareCreateFirstHandleNextSnapshotStringToolhelp32_wcslen
                                                      • String ID:
                                                      • API String ID: 1991900642-0
                                                      • Opcode ID: b836cd6ace204ea59cfb14b6be409f65f59ec5a4f58a017f2e7934811dbb0a88
                                                      • Instruction ID: f8582203b07980ea2a3d63e398105691cbf7a9e247aae5b9f8a1441f5ff7c530
                                                      • Opcode Fuzzy Hash: b836cd6ace204ea59cfb14b6be409f65f59ec5a4f58a017f2e7934811dbb0a88
                                                      • Instruction Fuzzy Hash: 2E51F975508300AFD714EF24C88AAABBBE8FF89754F40892DF695D7251EB34D904CB92

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1024 81dbbe-81dbda lstrlenW 1025 81dc06 1024->1025 1026 81dbdc-81dbe6 GetFileAttributesW 1024->1026 1027 81dc09-81dc0d 1025->1027 1026->1027 1028 81dbe8-81dbf7 FindFirstFileW 1026->1028 1028->1025 1029 81dbf9-81dc04 FindClose 1028->1029 1029->1027
                                                      APIs
                                                      • lstrlenW.KERNEL32(?,007F5222), ref: 0081DBCE
                                                      • GetFileAttributesW.KERNELBASE(?), ref: 0081DBDD
                                                      • FindFirstFileW.KERNEL32(?,?), ref: 0081DBEE
                                                      • FindClose.KERNEL32(00000000), ref: 0081DBFA
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FileFind$AttributesCloseFirstlstrlen
                                                      • String ID:
                                                      • API String ID: 2695905019-0
                                                      • Opcode ID: 3d48c97496f11d05d3582c45ee4bc749237b0d9ad5c021e5b7f5f790f585a59f
                                                      • Instruction ID: 36c2b104dfb7976c156c182724837bb5210a72e3bfd13ab95c398a7b0f847fa2
                                                      • Opcode Fuzzy Hash: 3d48c97496f11d05d3582c45ee4bc749237b0d9ad5c021e5b7f5f790f585a59f
                                                      • Instruction Fuzzy Hash: BAF0A038811A245782206B78AC0D9EA376CFF02334B104B02F936C22E0FBF05994C6D5
                                                      APIs
                                                      • GetCurrentProcess.KERNEL32(007E28E9,?,007D4CBE,007E28E9,008788B8,0000000C,007D4E15,007E28E9,00000002,00000000,?,007E28E9), ref: 007D4D09
                                                      • TerminateProcess.KERNEL32(00000000,?,007D4CBE,007E28E9,008788B8,0000000C,007D4E15,007E28E9,00000002,00000000,?,007E28E9), ref: 007D4D10
                                                      • ExitProcess.KERNEL32 ref: 007D4D22
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process$CurrentExitTerminate
                                                      • String ID:
                                                      • API String ID: 1703294689-0
                                                      • Opcode ID: dce429a0df2e16f58f25ba3119464e8b76d42070d0f0f1a3e67919aedbaa87bb
                                                      • Instruction ID: a2c2ab1ec915e69465f933999e2f24e945c0cb0d0ed57f2f6f8fe7142d9bc3c6
                                                      • Opcode Fuzzy Hash: dce429a0df2e16f58f25ba3119464e8b76d42070d0f0f1a3e67919aedbaa87bb
                                                      • Instruction Fuzzy Hash: 8CE0B635101588ABCF61AF64DD0DA583B7EFB46785B144015FD058B222CB39DD42CA90

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 0 83aff9-83b056 call 7d2340 3 83b094-83b098 0->3 4 83b058-83b06b call 7bb567 0->4 6 83b09a-83b0bb call 7bb567 * 2 3->6 7 83b0dd-83b0e0 3->7 12 83b0c8 4->12 13 83b06d-83b092 call 7bb567 * 2 4->13 30 83b0bf-83b0c4 6->30 9 83b0e2-83b0e5 7->9 10 83b0f5-83b119 call 7b7510 call 7b7620 7->10 14 83b0e8-83b0ed call 7bb567 9->14 33 83b1d8-83b1e0 10->33 34 83b11f-83b178 call 7b7510 call 7b7620 call 7b7510 call 7b7620 call 7b7510 call 7b7620 10->34 17 83b0cb-83b0cf 12->17 13->30 14->10 22 83b0d1-83b0d7 17->22 23 83b0d9-83b0db 17->23 22->14 23->7 23->10 30->7 31 83b0c6 30->31 31->17 36 83b1e2-83b1fd call 7b7510 call 7b7620 33->36 37 83b20a-83b238 GetCurrentDirectoryW call 7cfe0b GetCurrentDirectoryW 33->37 82 83b1a6-83b1d6 GetSystemDirectoryW call 7cfe0b GetSystemDirectoryW 34->82 83 83b17a-83b195 call 7b7510 call 7b7620 34->83 36->37 53 83b1ff-83b208 call 7d4963 36->53 45 83b23c 37->45 48 83b240-83b244 45->48 51 83b246-83b270 call 7b9c6e * 3 48->51 52 83b275-83b285 call 8200d9 48->52 51->52 64 83b287-83b289 52->64 65 83b28b-83b2e1 call 8207c0 call 8206e6 call 8205a7 52->65 53->37 53->52 69 83b2ee-83b2f2 64->69 65->69 97 83b2e3 65->97 71 83b39a-83b3be CreateProcessW 69->71 72 83b2f8-83b321 call 8111c8 69->72 76 83b3c1-83b3d4 call 7cfe14 * 2 71->76 87 83b323-83b328 call 811201 72->87 88 83b32a call 8114ce 72->88 103 83b3d6-83b3e8 76->103 104 83b42f-83b43d CloseHandle 76->104 82->45 83->82 105 83b197-83b1a0 call 7d4963 83->105 96 83b32f-83b33c call 7d4963 87->96 88->96 112 83b347-83b357 call 7d4963 96->112 113 83b33e-83b345 96->113 97->69 109 83b3ea 103->109 110 83b3ed-83b3fc 103->110 107 83b43f-83b444 104->107 108 83b49c 104->108 105->48 105->82 114 83b451-83b456 107->114 115 83b446-83b44c CloseHandle 107->115 118 83b4a0-83b4a4 108->118 109->110 116 83b401-83b42a GetLastError call 7b630c call 7bcfa0 110->116 117 83b3fe 110->117 136 83b362-83b372 call 7d4963 112->136 137 83b359-83b360 112->137 113->112 113->113 123 83b463-83b468 114->123 124 83b458-83b45e CloseHandle 114->124 115->114 126 83b4e5-83b4f6 call 820175 116->126 117->116 119 83b4b2-83b4bc 118->119 120 83b4a6-83b4b0 118->120 127 83b4c4-83b4e3 call 7bcfa0 CloseHandle 119->127 128 83b4be 119->128 120->126 130 83b475-83b49a call 8209d9 call 83b536 123->130 131 83b46a-83b470 CloseHandle 123->131 124->123 127->126 128->127 130->118 131->130 146 83b374-83b37b 136->146 147 83b37d-83b398 call 7cfe14 * 3 136->147 137->136 137->137 146->146 146->147 147->76
                                                      APIs
                                                      • _wcslen.LIBCMT ref: 0083B198
                                                      • GetSystemDirectoryW.KERNEL32(00000000,00000000), ref: 0083B1B0
                                                      • GetSystemDirectoryW.KERNEL32(00000000,00000000), ref: 0083B1D4
                                                      • _wcslen.LIBCMT ref: 0083B200
                                                      • GetCurrentDirectoryW.KERNEL32(00000000,00000000), ref: 0083B214
                                                      • GetCurrentDirectoryW.KERNEL32(00000000,00000000), ref: 0083B236
                                                      • _wcslen.LIBCMT ref: 0083B332
                                                        • Part of subcall function 008205A7: GetStdHandle.KERNEL32(000000F6), ref: 008205C6
                                                      • _wcslen.LIBCMT ref: 0083B34B
                                                      • _wcslen.LIBCMT ref: 0083B366
                                                      • CreateProcessW.KERNELBASE(00000000,?,00000000,00000000,?,?,00000000,?,?,?), ref: 0083B3B6
                                                      • GetLastError.KERNEL32(00000000), ref: 0083B407
                                                      • CloseHandle.KERNEL32(?), ref: 0083B439
                                                      • CloseHandle.KERNEL32(00000000), ref: 0083B44A
                                                      • CloseHandle.KERNEL32(00000000), ref: 0083B45C
                                                      • CloseHandle.KERNEL32(00000000), ref: 0083B46E
                                                      • CloseHandle.KERNEL32(?), ref: 0083B4E3
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Handle$Close_wcslen$Directory$CurrentSystem$CreateErrorLastProcess
                                                      • String ID:
                                                      • API String ID: 2178637699-0
                                                      • Opcode ID: 230adcc91a068a44d8dc80fca3fc6cab5d8e81137f9015f1bb7613c248007a66
                                                      • Instruction ID: bfba125c42c2d90b8d22faba33be38814aadcdcf8a012eabf3d6b031a481c1b6
                                                      • Opcode Fuzzy Hash: 230adcc91a068a44d8dc80fca3fc6cab5d8e81137f9015f1bb7613c248007a66
                                                      • Instruction Fuzzy Hash: A9F17871608200DFC724EF24C895B6ABBE5FF85314F14855DF99A8B2A2DB35EC40CB92
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Sleep$InputStateTimetime
                                                      • String ID:
                                                      • API String ID: 2764417729-0
                                                      • Opcode ID: bca6950407a01a4529a3a603c2322ec31c301eef10c0668b6367b1fd33ca1abe
                                                      • Instruction ID: 4125d85a3dc46137871eff63ddfb2b394bf8149a8ea515fa9fc83bf85e5de62c
                                                      • Opcode Fuzzy Hash: bca6950407a01a4529a3a603c2322ec31c301eef10c0668b6367b1fd33ca1abe
                                                      • Instruction Fuzzy Hash: 6342F170608241DFDB78CF28C898BAABBA5FF45314F14855DE456C7291EBB8EC44CB92

                                                      Control-flow Graph

                                                      APIs
                                                      • GetSysColorBrush.USER32(0000000F), ref: 007B2D07
                                                      • RegisterClassExW.USER32(00000030), ref: 007B2D31
                                                      • RegisterWindowMessageW.USER32(TaskbarCreated), ref: 007B2D42
                                                      • InitCommonControlsEx.COMCTL32(?), ref: 007B2D5F
                                                      • ImageList_Create.COMCTL32(00000010,00000010,00000021,00000001,00000001), ref: 007B2D6F
                                                      • LoadIconW.USER32(000000A9), ref: 007B2D85
                                                      • ImageList_ReplaceIcon.COMCTL32(000000FF,00000000), ref: 007B2D94
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: IconImageList_Register$BrushClassColorCommonControlsCreateInitLoadMessageReplaceWindow
                                                      • String ID: +$0$AutoIt v3 GUI$TaskbarCreated
                                                      • API String ID: 2914291525-1005189915
                                                      • Opcode ID: 5c9c7066c3ee1da42398b0de6f60ee8415a81a220b1ad89d780fe10640f7be95
                                                      • Instruction ID: 8879d03ee50ffe2237a71d7ec4411db2416d1c514cb5eaa59a6f2174bf05b97b
                                                      • Opcode Fuzzy Hash: 5c9c7066c3ee1da42398b0de6f60ee8415a81a220b1ad89d780fe10640f7be95
                                                      • Instruction Fuzzy Hash: F421BFB5912318AFDF40DFA8EC89BDDBFB8FB09700F00811AE611A62A0DBB55545CF91

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 462 7f065b-7f068b call 7f042f 465 7f068d-7f0698 call 7df2c6 462->465 466 7f06a6-7f06b2 call 7e5221 462->466 473 7f069a-7f06a1 call 7df2d9 465->473 471 7f06cb-7f0714 call 7f039a 466->471 472 7f06b4-7f06c9 call 7df2c6 call 7df2d9 466->472 481 7f0716-7f071f 471->481 482 7f0781-7f078a GetFileType 471->482 472->473 483 7f097d-7f0983 473->483 487 7f0756-7f077c GetLastError call 7df2a3 481->487 488 7f0721-7f0725 481->488 484 7f078c-7f07bd GetLastError call 7df2a3 CloseHandle 482->484 485 7f07d3-7f07d6 482->485 484->473 499 7f07c3-7f07ce call 7df2d9 484->499 491 7f07df-7f07e5 485->491 492 7f07d8-7f07dd 485->492 487->473 488->487 493 7f0727-7f0754 call 7f039a 488->493 496 7f07e9-7f0837 call 7e516a 491->496 497 7f07e7 491->497 492->496 493->482 493->487 504 7f0839-7f0845 call 7f05ab 496->504 505 7f0847-7f086b call 7f014d 496->505 497->496 499->473 504->505 511 7f086f-7f0879 call 7e86ae 504->511 512 7f087e-7f08c1 505->512 513 7f086d 505->513 511->483 515 7f08c3-7f08c7 512->515 516 7f08e2-7f08f0 512->516 513->511 515->516 518 7f08c9-7f08dd 515->518 519 7f097b 516->519 520 7f08f6-7f08fa 516->520 518->516 519->483 520->519 521 7f08fc-7f092f CloseHandle call 7f039a 520->521 524 7f0963-7f0977 521->524 525 7f0931-7f095d GetLastError call 7df2a3 call 7e5333 521->525 524->519 525->524
                                                      APIs
                                                        • Part of subcall function 007F039A: CreateFileW.KERNELBASE(00000000,00000000,?,007F0704,?,?,00000000,?,007F0704,00000000,0000000C), ref: 007F03B7
                                                      • GetLastError.KERNEL32 ref: 007F076F
                                                      • __dosmaperr.LIBCMT ref: 007F0776
                                                      • GetFileType.KERNELBASE(00000000), ref: 007F0782
                                                      • GetLastError.KERNEL32 ref: 007F078C
                                                      • __dosmaperr.LIBCMT ref: 007F0795
                                                      • CloseHandle.KERNEL32(00000000), ref: 007F07B5
                                                      • CloseHandle.KERNEL32(?), ref: 007F08FF
                                                      • GetLastError.KERNEL32 ref: 007F0931
                                                      • __dosmaperr.LIBCMT ref: 007F0938
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorLast__dosmaperr$CloseFileHandle$CreateType
                                                      • String ID: H
                                                      • API String ID: 4237864984-2852464175
                                                      • Opcode ID: d4680d2a229a141b0ed13f6f578cfc159a766640b16e3c78f19a6708fe1e7274
                                                      • Instruction ID: 8a588d23177dece8688b7e48c3c2da8e2802d26e9bc10e0f19c3715b25a87639
                                                      • Opcode Fuzzy Hash: d4680d2a229a141b0ed13f6f578cfc159a766640b16e3c78f19a6708fe1e7274
                                                      • Instruction Fuzzy Hash: 00A12136A001088FDF19EF68D855BBE7BA0AB06320F14419EF9159F3D2DB399912CB91

                                                      Control-flow Graph

                                                      APIs
                                                        • Part of subcall function 007B3A5A: GetModuleFileNameW.KERNEL32(00000000,?,00007FFF,00881418,?,007B2E7F,?,?,?,00000000), ref: 007B3A78
                                                        • Part of subcall function 007B3357: GetFullPathNameW.KERNEL32(?,00007FFF,?,?), ref: 007B3379
                                                      • RegOpenKeyExW.KERNELBASE(80000001,Software\AutoIt v3\AutoIt,00000000,00000001,?,?,\Include\), ref: 007B356A
                                                      • RegQueryValueExW.ADVAPI32(?,Include,00000000,00000000,00000000,?), ref: 007F318D
                                                      • RegQueryValueExW.ADVAPI32(?,Include,00000000,00000000,?,?,00000000), ref: 007F31CE
                                                      • RegCloseKey.ADVAPI32(?), ref: 007F3210
                                                      • _wcslen.LIBCMT ref: 007F3277
                                                      • _wcslen.LIBCMT ref: 007F3286
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: NameQueryValue_wcslen$CloseFileFullModuleOpenPath
                                                      • String ID: Include$Software\AutoIt v3\AutoIt$\$\Include\
                                                      • API String ID: 98802146-2727554177
                                                      • Opcode ID: 9a636b756947fba5c2e75dd64258a8ce1ba7e49f0183d785d84f2727e2b5991d
                                                      • Instruction ID: 1236ad3a734e0ee10517d16f7ea4996bb8f5b3dd570e88656f6d5a9256f23afd
                                                      • Opcode Fuzzy Hash: 9a636b756947fba5c2e75dd64258a8ce1ba7e49f0183d785d84f2727e2b5991d
                                                      • Instruction Fuzzy Hash: FD716A71405305EEC314EF69EC95AABBBE8FF85740B40042EF655C3271EB389A48CB62

                                                      Control-flow Graph

                                                      APIs
                                                      • GetSysColorBrush.USER32(0000000F), ref: 007B2B8E
                                                      • LoadCursorW.USER32(00000000,00007F00), ref: 007B2B9D
                                                      • LoadIconW.USER32(00000063), ref: 007B2BB3
                                                      • LoadIconW.USER32(000000A4), ref: 007B2BC5
                                                      • LoadIconW.USER32(000000A2), ref: 007B2BD7
                                                      • LoadImageW.USER32(00000063,00000001,00000010,00000010,00000000), ref: 007B2BEF
                                                      • RegisterClassExW.USER32(?), ref: 007B2C40
                                                        • Part of subcall function 007B2CD4: GetSysColorBrush.USER32(0000000F), ref: 007B2D07
                                                        • Part of subcall function 007B2CD4: RegisterClassExW.USER32(00000030), ref: 007B2D31
                                                        • Part of subcall function 007B2CD4: RegisterWindowMessageW.USER32(TaskbarCreated), ref: 007B2D42
                                                        • Part of subcall function 007B2CD4: InitCommonControlsEx.COMCTL32(?), ref: 007B2D5F
                                                        • Part of subcall function 007B2CD4: ImageList_Create.COMCTL32(00000010,00000010,00000021,00000001,00000001), ref: 007B2D6F
                                                        • Part of subcall function 007B2CD4: LoadIconW.USER32(000000A9), ref: 007B2D85
                                                        • Part of subcall function 007B2CD4: ImageList_ReplaceIcon.COMCTL32(000000FF,00000000), ref: 007B2D94
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Load$Icon$ImageRegister$BrushClassColorList_$CommonControlsCreateCursorInitMessageReplaceWindow
                                                      • String ID: #$0$AutoIt v3
                                                      • API String ID: 423443420-4155596026
                                                      • Opcode ID: d36d145775cf70a54cd6a93cdd3c0554e2b37fddffb127c3d916665bce99116b
                                                      • Instruction ID: e1a53c659e09ba698b868a48229e5b1025f05cc04d19d0575434c9adc7912632
                                                      • Opcode Fuzzy Hash: d36d145775cf70a54cd6a93cdd3c0554e2b37fddffb127c3d916665bce99116b
                                                      • Instruction Fuzzy Hash: 03211874E01318ABDF109FA9EC59BA97FB8FB48B50F00402AE600A67A0DBB90541CF90

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 603 7b3170-7b3185 604 7b3187-7b318a 603->604 605 7b31e5-7b31e7 603->605 606 7b31eb 604->606 607 7b318c-7b3193 604->607 605->604 608 7b31e9 605->608 612 7f2dfb-7f2e23 call 7b18e2 call 7ce499 606->612 613 7b31f1-7b31f6 606->613 609 7b3199-7b319e 607->609 610 7b3265-7b326d PostQuitMessage 607->610 611 7b31d0-7b31d8 DefWindowProcW 608->611 615 7f2e7c-7f2e90 call 81bf30 609->615 616 7b31a4-7b31a8 609->616 618 7b3219-7b321b 610->618 617 7b31de-7b31e4 611->617 648 7f2e28-7f2e2f 612->648 619 7b31f8-7b31fb 613->619 620 7b321d-7b3244 SetTimer RegisterWindowMessageW 613->620 615->618 642 7f2e96 615->642 624 7b31ae-7b31b3 616->624 625 7f2e68-7f2e72 call 81c161 616->625 618->617 621 7f2d9c-7f2d9f 619->621 622 7b3201-7b320f KillTimer call 7b30f2 619->622 620->618 626 7b3246-7b3251 CreatePopupMenu 620->626 634 7f2dd7-7f2df6 MoveWindow 621->634 635 7f2da1-7f2da5 621->635 637 7b3214 call 7b3c50 622->637 631 7f2e4d-7f2e54 624->631 632 7b31b9-7b31be 624->632 638 7f2e77 625->638 626->618 631->611 636 7f2e5a-7f2e63 call 810ad7 631->636 640 7b3253-7b3263 call 7b326f 632->640 641 7b31c4-7b31ca 632->641 634->618 643 7f2da7-7f2daa 635->643 644 7f2dc6-7f2dd2 SetFocus 635->644 636->611 637->618 638->618 640->618 641->611 641->648 642->611 643->641 649 7f2db0-7f2dc1 call 7b18e2 643->649 644->618 648->611 652 7f2e35-7f2e48 call 7b30f2 call 7b3837 648->652 649->618 652->611
                                                      APIs
                                                      • DefWindowProcW.USER32(?,?,?,?,?,?,?,?,?,007B316A,?,?), ref: 007B31D8
                                                      • KillTimer.USER32(?,00000001,?,?,?,?,?,007B316A,?,?), ref: 007B3204
                                                      • SetTimer.USER32(?,00000001,000002EE,00000000), ref: 007B3227
                                                      • RegisterWindowMessageW.USER32(TaskbarCreated,?,?,?,?,?,007B316A,?,?), ref: 007B3232
                                                      • CreatePopupMenu.USER32 ref: 007B3246
                                                      • PostQuitMessage.USER32(00000000), ref: 007B3267
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageTimerWindow$CreateKillMenuPopupPostProcQuitRegister
                                                      • String ID: TaskbarCreated
                                                      • API String ID: 129472671-2362178303
                                                      • Opcode ID: 1259b21afa4a67701613f79caa8e3dd8923d90c87be23ebc42326a5417029e3a
                                                      • Instruction ID: 5be5e475e4282f107cdbd0c368ab8e9007d225c3a477824adee4ca5d5b6b3240
                                                      • Opcode Fuzzy Hash: 1259b21afa4a67701613f79caa8e3dd8923d90c87be23ebc42326a5417029e3a
                                                      • Instruction Fuzzy Hash: C541DF3524060CABDF146BACDC1EBF93A5DFB06340F040125FA02C62A2DF7D9E8297A1

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 659 7b1410-7b1449 660 7b144f-7b1465 mciSendStringW 659->660 661 7f24b8-7f24b9 DestroyWindow 659->661 662 7b146b-7b1473 660->662 663 7b16c6-7b16d3 660->663 666 7f24c4-7f24d1 661->666 662->666 667 7b1479-7b1488 call 7b182e 662->667 664 7b16f8-7b16ff 663->664 665 7b16d5-7b16f0 UnregisterHotKey 663->665 664->662 669 7b1705 664->669 665->664 668 7b16f2-7b16f3 call 7b10d0 665->668 670 7f24d3-7f24d6 666->670 671 7f2500-7f2507 666->671 678 7f250e-7f251a 667->678 679 7b148e-7b1496 667->679 668->664 669->663 676 7f24d8-7f24e0 call 7b6246 670->676 677 7f24e2-7f24e5 FindClose 670->677 671->666 675 7f2509 671->675 675->678 680 7f24eb-7f24f8 676->680 677->680 685 7f251c-7f251e FreeLibrary 678->685 686 7f2524-7f252b 678->686 682 7b149c-7b14c1 call 7bcfa0 679->682 683 7f2532-7f253f 679->683 680->671 684 7f24fa-7f24fb call 8232b1 680->684 696 7b14f8-7b1503 CoUninitialize 682->696 697 7b14c3 682->697 691 7f2566-7f256d 683->691 692 7f2541-7f255e VirtualFree 683->692 684->671 685->686 686->678 690 7f252d 686->690 690->683 691->683 693 7f256f 691->693 692->691 695 7f2560-7f2561 call 823317 692->695 699 7f2574-7f2578 693->699 695->691 696->699 701 7b1509-7b150e 696->701 700 7b14c6-7b14f6 call 7b1a05 call 7b19ae 697->700 699->701 702 7f257e-7f2584 699->702 700->696 704 7f2589-7f2596 call 8232eb 701->704 705 7b1514-7b151e 701->705 702->701 718 7f2598 704->718 708 7b1707-7b1714 call 7cf80e 705->708 709 7b1524-7b15a5 call 7b988f call 7b1944 call 7b17d5 call 7cfe14 call 7b177c call 7b988f call 7bcfa0 call 7b17fe call 7cfe14 705->709 708->709 720 7b171a 708->720 722 7f259d-7f25bf call 7cfdcd 709->722 748 7b15ab-7b15cf call 7cfe14 709->748 718->722 720->708 728 7f25c1 722->728 730 7f25c6-7f25e8 call 7cfdcd 728->730 736 7f25ea 730->736 739 7f25ef-7f2611 call 7cfdcd 736->739 745 7f2613 739->745 749 7f2618-7f2625 call 8164d4 745->749 748->730 754 7b15d5-7b15f9 call 7cfe14 748->754 755 7f2627 749->755 754->739 760 7b15ff-7b1619 call 7cfe14 754->760 757 7f262c-7f2639 call 7cac64 755->757 763 7f263b 757->763 760->749 765 7b161f-7b1643 call 7b17d5 call 7cfe14 760->765 766 7f2640-7f264d call 823245 763->766 765->757 774 7b1649-7b1651 765->774 772 7f264f 766->772 776 7f2654-7f2661 call 8232cc 772->776 774->766 775 7b1657-7b1675 call 7b988f call 7b190a 774->775 775->776 784 7b167b-7b1689 775->784 782 7f2663 776->782 785 7f2668-7f2675 call 8232cc 782->785 784->785 787 7b168f-7b16c5 call 7b988f * 3 call 7b1876 784->787 790 7f2677 785->790 790->790
                                                      APIs
                                                      • mciSendStringW.WINMM(close all,00000000,00000000,00000000), ref: 007B1459
                                                      • CoUninitialize.COMBASE ref: 007B14F8
                                                      • UnregisterHotKey.USER32(?), ref: 007B16DD
                                                      • DestroyWindow.USER32(?), ref: 007F24B9
                                                      • FreeLibrary.KERNEL32(?), ref: 007F251E
                                                      • VirtualFree.KERNEL32(?,00000000,00008000), ref: 007F254B
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Free$DestroyLibrarySendStringUninitializeUnregisterVirtualWindow
                                                      • String ID: close all
                                                      • API String ID: 469580280-3243417748
                                                      • Opcode ID: 127190c25ec09b04c43add0718a6203979f3e6f4831d690662f3734253f1fce6
                                                      • Instruction ID: cc7d8b2197844ac0e58605ec304b2ea3c3872b41510639b8d0aa08ce5ba6b43c
                                                      • Opcode Fuzzy Hash: 127190c25ec09b04c43add0718a6203979f3e6f4831d690662f3734253f1fce6
                                                      • Instruction Fuzzy Hash: C8D15E31702212DFCB29DF14C4A9B69F7A5BF05700F9441ADE54AAB352DB38AD22CF51

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 808 7b2c63-7b2cd3 CreateWindowExW * 2 ShowWindow * 2
                                                      APIs
                                                      • CreateWindowExW.USER32(00000000,AutoIt v3,AutoIt v3,00CF0000,80000000,80000000,0000012C,00000064,00000000,00000000,00000000,00000001), ref: 007B2C91
                                                      • CreateWindowExW.USER32(00000000,edit,00000000,50B008C4,00000000,00000000,00000000,00000000,00000000,00000001,00000000), ref: 007B2CB2
                                                      • ShowWindow.USER32(00000000,?,?,?,?,?,?,007B1CAD,?), ref: 007B2CC6
                                                      • ShowWindow.USER32(00000000,?,?,?,?,?,?,007B1CAD,?), ref: 007B2CCF
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$CreateShow
                                                      • String ID: AutoIt v3$edit
                                                      • API String ID: 1584632944-3779509399
                                                      • Opcode ID: f8a239ab4a8b37928b49ee257c92cae3bc18d85d01d30a449f6b0c38a79a9260
                                                      • Instruction ID: 60fda538a2e8d333e4d7b47389421d17f7ca04c3680a8707d71cbaa5833db533
                                                      • Opcode Fuzzy Hash: f8a239ab4a8b37928b49ee257c92cae3bc18d85d01d30a449f6b0c38a79a9260
                                                      • Instruction Fuzzy Hash: 43F0DA755413947AEB71171BAC0CEB72EBDF7C7F50B00005AF900A26A0CA791852DBB0

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 959 7b3b1c-7b3b27 960 7b3b99-7b3b9b 959->960 961 7b3b29-7b3b2e 959->961 962 7b3b8c-7b3b8f 960->962 961->960 963 7b3b30-7b3b48 RegOpenKeyExW 961->963 963->960 964 7b3b4a-7b3b69 RegQueryValueExW 963->964 965 7b3b6b-7b3b76 964->965 966 7b3b80-7b3b8b RegCloseKey 964->966 967 7b3b78-7b3b7a 965->967 968 7b3b90-7b3b97 965->968 966->962 969 7b3b7e 967->969 968->969 969->966
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,Control Panel\Mouse,00000000,00000001,00000000,?,?,80000001,80000001,?,007B3B0F,SwapMouseButtons,00000004,?), ref: 007B3B40
                                                      • RegQueryValueExW.KERNELBASE(00000000,00000000,00000000,00000000,?,?,?,?,?,80000001,80000001,?,007B3B0F,SwapMouseButtons,00000004,?), ref: 007B3B61
                                                      • RegCloseKey.KERNELBASE(00000000,?,?,?,80000001,80000001,?,007B3B0F,SwapMouseButtons,00000004,?), ref: 007B3B83
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CloseOpenQueryValue
                                                      • String ID: Control Panel\Mouse
                                                      • API String ID: 3677997916-824357125
                                                      • Opcode ID: aaec3f81ff09898a84b9ad4fe0d4ea5fcafb8922b79fe6c25e47f39e2e0a5db9
                                                      • Instruction ID: 9d38b0f5344b554f51f5e0ab528a7cd7a5a17e3e46a56bf46c7cab4f0add6402
                                                      • Opcode Fuzzy Hash: aaec3f81ff09898a84b9ad4fe0d4ea5fcafb8922b79fe6c25e47f39e2e0a5db9
                                                      • Instruction Fuzzy Hash: 63112AB5511208FFDB208FA5DC44AEFB7BCEF05744B104559A805D7114E6359E809760
                                                      APIs
                                                      • LoadStringW.USER32(00000065,?,0000007F,00000104), ref: 007F33A2
                                                        • Part of subcall function 007B6B57: _wcslen.LIBCMT ref: 007B6B6A
                                                      • Shell_NotifyIconW.SHELL32(00000001,?), ref: 007B3A04
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: IconLoadNotifyShell_String_wcslen
                                                      • String ID: Line:
                                                      • API String ID: 2289894680-1585850449
                                                      • Opcode ID: b219c1129509365c63f19b04f35ea8d8f7d2bb6dbb4f070d5462fa94264963ec
                                                      • Instruction ID: c2d9a5d3c2a3724d77f4dce91b8d5b7178161273fced04ebf02d287a016a00d4
                                                      • Opcode Fuzzy Hash: b219c1129509365c63f19b04f35ea8d8f7d2bb6dbb4f070d5462fa94264963ec
                                                      • Instruction Fuzzy Hash: 8831A571408304AAD725EB14DC49BEBB7ECBF40714F10451AF59993291EF7CAA89C7C2
                                                      APIs
                                                      • __CxxThrowException@8.LIBVCRUNTIME ref: 007D0668
                                                        • Part of subcall function 007D32A4: RaiseException.KERNEL32(?,?,?,007D068A,?,00881444,?,?,?,?,?,?,007D068A,007B1129,00878738,007B1129), ref: 007D3304
                                                      • __CxxThrowException@8.LIBVCRUNTIME ref: 007D0685
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Exception@8Throw$ExceptionRaise
                                                      • String ID: Unknown exception
                                                      • API String ID: 3476068407-410509341
                                                      • Opcode ID: 1b916e7b150b9fe86b26d457ef1e31c6348c94ded555e2787d1db855c06a2be8
                                                      • Instruction ID: 2ba0eed18da7c6e991da94069f5c0a75968269e1c7b7ba0a096af79c6d66e1cc
                                                      • Opcode Fuzzy Hash: 1b916e7b150b9fe86b26d457ef1e31c6348c94ded555e2787d1db855c06a2be8
                                                      • Instruction Fuzzy Hash: 27F0F42490020DF38B04B664E84EE5D777CAE00350B60803AB929D6795EF38EA2585C0
                                                      APIs
                                                        • Part of subcall function 007B1BC3: MapVirtualKeyW.USER32(0000005B,00000000), ref: 007B1BF4
                                                        • Part of subcall function 007B1BC3: MapVirtualKeyW.USER32(00000010,00000000), ref: 007B1BFC
                                                        • Part of subcall function 007B1BC3: MapVirtualKeyW.USER32(000000A0,00000000), ref: 007B1C07
                                                        • Part of subcall function 007B1BC3: MapVirtualKeyW.USER32(000000A1,00000000), ref: 007B1C12
                                                        • Part of subcall function 007B1BC3: MapVirtualKeyW.USER32(00000011,00000000), ref: 007B1C1A
                                                        • Part of subcall function 007B1BC3: MapVirtualKeyW.USER32(00000012,00000000), ref: 007B1C22
                                                        • Part of subcall function 007B1B4A: RegisterWindowMessageW.USER32(00000004,?,007B12C4), ref: 007B1BA2
                                                      • GetStdHandle.KERNEL32(000000F6,00000000,00000000), ref: 007B136A
                                                      • OleInitialize.OLE32 ref: 007B1388
                                                      • CloseHandle.KERNEL32(00000000,00000000), ref: 007F24AB
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Virtual$Handle$CloseInitializeMessageRegisterWindow
                                                      • String ID:
                                                      • API String ID: 1986988660-0
                                                      • Opcode ID: c0dae7988f3bfd3e9336ec9da35489214642f4a51d118ac9ff2bba423e50abd2
                                                      • Instruction ID: 2a8378fe63216dd94af72982eb9a9d8d69743d40b6effe0dad25e46b102256fe
                                                      • Opcode Fuzzy Hash: c0dae7988f3bfd3e9336ec9da35489214642f4a51d118ac9ff2bba423e50abd2
                                                      • Instruction Fuzzy Hash: 1871A7B49122009ECB84EFBDE95EA953AEDFB88344794823AD10AC7262EF344447CF45
                                                      APIs
                                                        • Part of subcall function 007B3923: Shell_NotifyIconW.SHELL32(00000001,?), ref: 007B3A04
                                                      • Shell_NotifyIconW.SHELL32(00000001,000003A8), ref: 0081C259
                                                      • KillTimer.USER32(?,00000001,?,?), ref: 0081C261
                                                      • SetTimer.USER32(?,00000001,000002EE,00000000), ref: 0081C270
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: IconNotifyShell_Timer$Kill
                                                      • String ID:
                                                      • API String ID: 3500052701-0
                                                      • Opcode ID: 964d78b3f0c26f7d178fcfe11abdc4de4b65d45201251040ef2b621ed2325d75
                                                      • Instruction ID: 90a0d2653d503d4944459ea0177ef50b17e8cbcacc58fcd4569eec99e69304b6
                                                      • Opcode Fuzzy Hash: 964d78b3f0c26f7d178fcfe11abdc4de4b65d45201251040ef2b621ed2325d75
                                                      • Instruction Fuzzy Hash: D1318170944344AFEB629F648859BEABBECFF16308F00049AD59AD7241C7746AC5CB51
                                                      APIs
                                                      • CloseHandle.KERNELBASE(00000000,00000000,?,?,007E85CC,?,00878CC8,0000000C), ref: 007E8704
                                                      • GetLastError.KERNEL32(?,007E85CC,?,00878CC8,0000000C), ref: 007E870E
                                                      • __dosmaperr.LIBCMT ref: 007E8739
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CloseErrorHandleLast__dosmaperr
                                                      • String ID:
                                                      • API String ID: 2583163307-0
                                                      • Opcode ID: f5644c105a932bab965377306b92cbbe992053e6d738618300ba1049150bd1f2
                                                      • Instruction ID: 35639846571ea60e7556ceb2e599b3bc1fa38c7882d36c369d90a3c6c1a8ddcb
                                                      • Opcode Fuzzy Hash: f5644c105a932bab965377306b92cbbe992053e6d738618300ba1049150bd1f2
                                                      • Instruction Fuzzy Hash: 61018E326072E056C2E06376694977E67494B8E77CF390119F81C8B1D3DEACCC81C252
                                                      APIs
                                                      • TranslateMessage.USER32(?), ref: 007BDB7B
                                                      • DispatchMessageW.USER32(?), ref: 007BDB89
                                                      • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 007BDB9F
                                                      • Sleep.KERNELBASE(0000000A), ref: 007BDBB1
                                                      • TranslateAcceleratorW.USER32(?,?,?), ref: 00801CC9
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Message$Translate$AcceleratorDispatchPeekSleep
                                                      • String ID:
                                                      • API String ID: 3288985973-0
                                                      • Opcode ID: 813e0a7861990b16c54a5dac34dcf60ee2ce7a60d1a0886368226fcc9a72a924
                                                      • Instruction ID: e4f47c47336a62e1463a136132c0c43af8a71ea40d637dfeaaf6e5361819339e
                                                      • Opcode Fuzzy Hash: 813e0a7861990b16c54a5dac34dcf60ee2ce7a60d1a0886368226fcc9a72a924
                                                      • Instruction Fuzzy Hash: 2CF05E306453409BEB70CBA48C4DFEA73ACFB45310F104628E61AC30C0EB349848CB25
                                                      APIs
                                                      • __Init_thread_footer.LIBCMT ref: 007C17F6
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Init_thread_footer
                                                      • String ID: CALL
                                                      • API String ID: 1385522511-4196123274
                                                      • Opcode ID: 95b5cfb3c321b925622788916e1e918f0556e4f1756cde5ebda6e75a6550a79f
                                                      • Instruction ID: cafe3a304a03d0293577203725c671af39c01d09fbb21efc5572f62f5c856d8b
                                                      • Opcode Fuzzy Hash: 95b5cfb3c321b925622788916e1e918f0556e4f1756cde5ebda6e75a6550a79f
                                                      • Instruction Fuzzy Hash: 22226870608241DFC714DF14C894F2ABBE1FF86314F64896DE4968B3A2D739E961CB92
                                                      APIs
                                                      • GetOpenFileNameW.COMDLG32(?), ref: 007F2C8C
                                                        • Part of subcall function 007B3AA2: GetFullPathNameW.KERNEL32(?,00007FFF,?,00000000,?,?,007B3A97,?,?,007B2E7F,?,?,?,00000000), ref: 007B3AC2
                                                        • Part of subcall function 007B2DA5: GetLongPathNameW.KERNELBASE(?,?,00007FFF), ref: 007B2DC4
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Name$Path$FileFullLongOpen
                                                      • String ID: X
                                                      • API String ID: 779396738-3081909835
                                                      • Opcode ID: dd658ede7d605a0d6f10dc25efd02c48eacab03035d2efcaf562261b1b1f4ee4
                                                      • Instruction ID: 10f3d2c0e7e985bb5eb1991a23a38f256f952c6aee1e8d1ada9d2b0d514219f7
                                                      • Opcode Fuzzy Hash: dd658ede7d605a0d6f10dc25efd02c48eacab03035d2efcaf562261b1b1f4ee4
                                                      • Instruction Fuzzy Hash: 68218471A002589ACB419F94C8497EE7BF8AF49704F108059E505A7345EBB89A8A8F61
                                                      APIs
                                                      • Shell_NotifyIconW.SHELL32(00000000,?), ref: 007B3908
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: IconNotifyShell_
                                                      • String ID:
                                                      • API String ID: 1144537725-0
                                                      • Opcode ID: e3db5b9feb45201bc3323ffaae4b3365c3d8f94a2cd7344bbd0d8adb601a5007
                                                      • Instruction ID: df33565e570c24ec0ab75f2d69afd495e636fc64f8d39664cf9192ee67be9680
                                                      • Opcode Fuzzy Hash: e3db5b9feb45201bc3323ffaae4b3365c3d8f94a2cd7344bbd0d8adb601a5007
                                                      • Instruction Fuzzy Hash: 4E314B705047019FD761DF28D8897D7BBE8FB49708F00092EF59987250E779AA85CB52
                                                      APIs
                                                      • timeGetTime.WINMM ref: 007CF661
                                                        • Part of subcall function 007BD730: GetInputState.USER32 ref: 007BD807
                                                      • Sleep.KERNEL32(00000000), ref: 0080F2DE
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: InputSleepStateTimetime
                                                      • String ID:
                                                      • API String ID: 4149333218-0
                                                      • Opcode ID: 4970ad3803d86da19200ac83d54c2a3d649c6730887acee500e343d1fe9a05a0
                                                      • Instruction ID: dcbc74672a9ec7867914542cb0cd79649f38e54f84843ab70401282a19d0b591
                                                      • Opcode Fuzzy Hash: 4970ad3803d86da19200ac83d54c2a3d649c6730887acee500e343d1fe9a05a0
                                                      • Instruction Fuzzy Hash: 5EF08C352402059FD360EF69D849BAAB7E8FF4A760F004029E85AC72A1DBB0A800CB91
                                                      APIs
                                                      • __Init_thread_footer.LIBCMT ref: 007BBB4E
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Init_thread_footer
                                                      • String ID:
                                                      • API String ID: 1385522511-0
                                                      • Opcode ID: 4e5b91e8dcbe0bf839e167d67805089ac1d639b59a0447535a095a5e766b14a9
                                                      • Instruction ID: b61a0e4967b36d6e5eed055d0dabfac11e5c01df28b6a3ad162aba888f144e4a
                                                      • Opcode Fuzzy Hash: 4e5b91e8dcbe0bf839e167d67805089ac1d639b59a0447535a095a5e766b14a9
                                                      • Instruction Fuzzy Hash: 19327974A00209DFDB24CF58C898BBAB7B9FF44314F158059ED05AB3A1D7B8AD81CB91
                                                      APIs
                                                        • Part of subcall function 007B4E90: LoadLibraryA.KERNEL32(kernel32.dll,?,?,007B4EDD,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4E9C
                                                        • Part of subcall function 007B4E90: GetProcAddress.KERNEL32(00000000,Wow64DisableWow64FsRedirection), ref: 007B4EAE
                                                        • Part of subcall function 007B4E90: FreeLibrary.KERNEL32(00000000,?,?,007B4EDD,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4EC0
                                                      • LoadLibraryExW.KERNEL32(?,00000000,00000002,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4EFD
                                                        • Part of subcall function 007B4E59: LoadLibraryA.KERNEL32(kernel32.dll,?,?,007F3CDE,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4E62
                                                        • Part of subcall function 007B4E59: GetProcAddress.KERNEL32(00000000,Wow64RevertWow64FsRedirection), ref: 007B4E74
                                                        • Part of subcall function 007B4E59: FreeLibrary.KERNEL32(00000000,?,?,007F3CDE,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4E87
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Library$Load$AddressFreeProc
                                                      • String ID:
                                                      • API String ID: 2632591731-0
                                                      • Opcode ID: 635c82eb9184576e9e06d0f7ea5f5b9d0bdf1cb7005edcea2c48a96de9a469ef
                                                      • Instruction ID: f39bb18074390a2396b92a63e87437c692f9dd7d5700f41b38081963b2b192de
                                                      • Opcode Fuzzy Hash: 635c82eb9184576e9e06d0f7ea5f5b9d0bdf1cb7005edcea2c48a96de9a469ef
                                                      • Instruction Fuzzy Hash: 23119132610219EADB14BB64DC0ABFD77A5AF40B10F148429F542AB2D2EEB8DA459B50
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: __wsopen_s
                                                      • String ID:
                                                      • API String ID: 3347428461-0
                                                      • Opcode ID: 48cd4ce9dd3c3a9c8f2d37773703f26335cc45b27659d5aeb0d35d79e37b44f7
                                                      • Instruction ID: 19c8dad1ae945c52cf00985d9f9c5ca92f61fca66a11f58615c14e53e089d38f
                                                      • Opcode Fuzzy Hash: 48cd4ce9dd3c3a9c8f2d37773703f26335cc45b27659d5aeb0d35d79e37b44f7
                                                      • Instruction Fuzzy Hash: B711487190414AEFCB05DF59E94099A7BF4FF49310F104059F808AB352DA30EA11CBA5
                                                      APIs
                                                      • GetForegroundWindow.USER32(00000000,?,?,?,008414B5,?), ref: 00842A01
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ForegroundWindow
                                                      • String ID:
                                                      • API String ID: 2020703349-0
                                                      • Opcode ID: 197c6ac877f379f4469aad7fbb9f9998bcca2c92f44cbaf9d17cc01aa4356c15
                                                      • Instruction ID: 4baf832ab76b574415e9c4253fb31989b335eda15a79f9c739858e3fdf2947e3
                                                      • Opcode Fuzzy Hash: 197c6ac877f379f4469aad7fbb9f9998bcca2c92f44cbaf9d17cc01aa4356c15
                                                      • Instruction Fuzzy Hash: 0301B136308A669FD324CA2CC454F223B92FF85318FA98469E447CB251DB32EC42C7A0
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: d6c69ec2a70ac845cc05b5f137181c3f07394ab8b33ef369e8c7ef627d5c9574
                                                      • Instruction ID: ea18de7b83e1c395e7701adc6edcabc862f7046c42db6bf5be5b3a23b2ee40f7
                                                      • Opcode Fuzzy Hash: d6c69ec2a70ac845cc05b5f137181c3f07394ab8b33ef369e8c7ef627d5c9574
                                                      • Instruction Fuzzy Hash: 35F02D32511A14D6C7323A668C0DB5A33BC9F52334F10071BF525973D2DB7CE80285A6
                                                      APIs
                                                      • RtlAllocateHeap.NTDLL(00000000,?,00881444,?,007CFDF5,?,?,007BA976,00000010,00881440,007B13FC,?,007B13C6,?,007B1129), ref: 007E3852
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: AllocateHeap
                                                      • String ID:
                                                      • API String ID: 1279760036-0
                                                      • Opcode ID: 9cdb24ab57ee2d66a88d578fc3cb559b09a81f302ffec679f242f051037c038a
                                                      • Instruction ID: 9fac118bfbabbf2e9f875c06f57fba4abcd4b713562dcc3be7837c1025fb3c69
                                                      • Opcode Fuzzy Hash: 9cdb24ab57ee2d66a88d578fc3cb559b09a81f302ffec679f242f051037c038a
                                                      • Instruction Fuzzy Hash: 26E065321032A4ABE63126A79D0DB9A3759AB867B0F190123BC1597691DB2DDD0182F1
                                                      APIs
                                                      • FreeLibrary.KERNEL32(?,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4F6D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FreeLibrary
                                                      • String ID:
                                                      • API String ID: 3664257935-0
                                                      • Opcode ID: 39da7279b185725aab6ba2d80a57a8d5b1770773a7b243db8621b95d806bdb3d
                                                      • Instruction ID: db4ad80747efecfdadd3329c095c3d8defde3b3c0a65fe3ae13450e5a87b7cef
                                                      • Opcode Fuzzy Hash: 39da7279b185725aab6ba2d80a57a8d5b1770773a7b243db8621b95d806bdb3d
                                                      • Instruction Fuzzy Hash: D4F03971505752CFDB349F64D494AA2BBF4FF14329328897EE1EA83622C7399844DF10
                                                      APIs
                                                      • IsWindow.USER32(00000000), ref: 00842A66
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window
                                                      • String ID:
                                                      • API String ID: 2353593579-0
                                                      • Opcode ID: bc16820ddcb84ba01555ec3130c46b2af1c2690d292e770a64fcdfacf2741547
                                                      • Instruction ID: c4f0fd63e50531927838350c05c88da9c8d21f7c9227c472f61e0e0ade09186d
                                                      • Opcode Fuzzy Hash: bc16820ddcb84ba01555ec3130c46b2af1c2690d292e770a64fcdfacf2741547
                                                      • Instruction Fuzzy Hash: BCE04F7635412EAAC754EA34EC849FAB75CFF61399750453ABC16C3140DB309A9686A0
                                                      APIs
                                                      • Shell_NotifyIconW.SHELL32(00000002,?), ref: 007B314E
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: IconNotifyShell_
                                                      • String ID:
                                                      • API String ID: 1144537725-0
                                                      • Opcode ID: 62e9eec14f0dde55a2f273c9b18f82b81c6839c8a2e3b72a52ec1084ff2faaa9
                                                      • Instruction ID: d3a3a4d931ad5432b3029dbc190efe177d839bb227aeda24295183e75ee7da3d
                                                      • Opcode Fuzzy Hash: 62e9eec14f0dde55a2f273c9b18f82b81c6839c8a2e3b72a52ec1084ff2faaa9
                                                      • Instruction Fuzzy Hash: 99F037709143189FEB529B28DC4A7D57BBCB701708F0000E5A54896292DB785789CF51
                                                      APIs
                                                      • GetLongPathNameW.KERNELBASE(?,?,00007FFF), ref: 007B2DC4
                                                        • Part of subcall function 007B6B57: _wcslen.LIBCMT ref: 007B6B6A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: LongNamePath_wcslen
                                                      • String ID:
                                                      • API String ID: 541455249-0
                                                      • Opcode ID: 6cf9934e50a66d46a1edf6523045a476b49e83081b569989b97c762570c74d9f
                                                      • Instruction ID: b3f7c9bbff3f365484ad9ca56525ff18cf532009276b01c8933a953149444733
                                                      • Opcode Fuzzy Hash: 6cf9934e50a66d46a1edf6523045a476b49e83081b569989b97c762570c74d9f
                                                      • Instruction Fuzzy Hash: 29E0CD766011249BC71092589C09FEA77EDDFC8790F040071FE09D7248DAA4AD80C550
                                                      APIs
                                                        • Part of subcall function 007B3837: Shell_NotifyIconW.SHELL32(00000000,?), ref: 007B3908
                                                        • Part of subcall function 007BD730: GetInputState.USER32 ref: 007BD807
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 007B2B6B
                                                        • Part of subcall function 007B30F2: Shell_NotifyIconW.SHELL32(00000002,?), ref: 007B314E
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: IconNotifyShell_$CurrentDirectoryInputState
                                                      • String ID:
                                                      • API String ID: 3667716007-0
                                                      • Opcode ID: 239cf67fbfeae930ab4691ac15a90aec66e9909731f19716ef892bece4d87d15
                                                      • Instruction ID: b560895cf7c5647bce0ec895f962b894b6cb2d3b75af866a4e33fb29ee46d7d2
                                                      • Opcode Fuzzy Hash: 239cf67fbfeae930ab4691ac15a90aec66e9909731f19716ef892bece4d87d15
                                                      • Instruction Fuzzy Hash: 27E0863130424486CA04BBB4985E7EDA75EABD1751F40153EF24283163DE2D498A8352
                                                      APIs
                                                      • CreateFileW.KERNELBASE(00000000,00000000,?,007F0704,?,?,00000000,?,007F0704,00000000,0000000C), ref: 007F03B7
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CreateFile
                                                      • String ID:
                                                      • API String ID: 823142352-0
                                                      • Opcode ID: 863bca47567c81481c8770c676942e9efd103e18faa43f2b984bc456a4368d84
                                                      • Instruction ID: 754634fb71f6034882e362a0cc5cb08bfc37607b2adb99d32f34c98cb0075d29
                                                      • Opcode Fuzzy Hash: 863bca47567c81481c8770c676942e9efd103e18faa43f2b984bc456a4368d84
                                                      • Instruction Fuzzy Hash: FDD06C3204010DBBDF028F84DD06EDA3BAAFB48714F014000BE1856020C732E821EB90
                                                      APIs
                                                      • SystemParametersInfoW.USER32(00002001,00000000,00000002), ref: 007B1CBC
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: InfoParametersSystem
                                                      • String ID:
                                                      • API String ID: 3098949447-0
                                                      • Opcode ID: be112453b1a50494ff87e7b10596b1d32751c5e35702e2d38d76967e7903fee9
                                                      • Instruction ID: 0d648e9656b78ef6b0d63044c8c3925663222103df78edc5e0dfa631605da1d8
                                                      • Opcode Fuzzy Hash: be112453b1a50494ff87e7b10596b1d32751c5e35702e2d38d76967e7903fee9
                                                      • Instruction Fuzzy Hash: 02C0923A2C0304AFF6548B88FC4EF547768B348B00F048001F709A96E3C7A22820EB50
                                                      APIs
                                                        • Part of subcall function 007C9BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 007C9BB2
                                                      • DefDlgProcW.USER32(?,0000004E,?,?,?,?,?,?), ref: 0084961A
                                                      • SendMessageW.USER32(?,0000130B,00000000,00000000), ref: 0084965B
                                                      • GetWindowLongW.USER32(FFFFFDD9,000000F0), ref: 0084969F
                                                      • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 008496C9
                                                      • SendMessageW.USER32 ref: 008496F2
                                                      • GetKeyState.USER32(00000011), ref: 0084978B
                                                      • GetKeyState.USER32(00000009), ref: 00849798
                                                      • SendMessageW.USER32(?,0000130B,00000000,00000000), ref: 008497AE
                                                      • GetKeyState.USER32(00000010), ref: 008497B8
                                                      • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 008497E9
                                                      • SendMessageW.USER32 ref: 00849810
                                                      • SendMessageW.USER32(?,00001030,?,00847E95), ref: 00849918
                                                      • ImageList_SetDragCursorImage.COMCTL32(00000000,00000000,00000000,?,?,?), ref: 0084992E
                                                      • ImageList_BeginDrag.COMCTL32(00000000,000000F8,000000F0), ref: 00849941
                                                      • SetCapture.USER32(?), ref: 0084994A
                                                      • ClientToScreen.USER32(?,?), ref: 008499AF
                                                      • ImageList_DragEnter.COMCTL32(00000000,?,?), ref: 008499BC
                                                      • InvalidateRect.USER32(?,00000000,00000001,?,?,?), ref: 008499D6
                                                      • ReleaseCapture.USER32 ref: 008499E1
                                                      • GetCursorPos.USER32(?), ref: 00849A19
                                                      • ScreenToClient.USER32(?,?), ref: 00849A26
                                                      • SendMessageW.USER32(?,00001012,00000000,?), ref: 00849A80
                                                      • SendMessageW.USER32 ref: 00849AAE
                                                      • SendMessageW.USER32(?,00001111,00000000,?), ref: 00849AEB
                                                      • SendMessageW.USER32 ref: 00849B1A
                                                      • SendMessageW.USER32(?,0000110B,00000009,00000000), ref: 00849B3B
                                                      • SendMessageW.USER32(?,0000110B,00000009,?), ref: 00849B4A
                                                      • GetCursorPos.USER32(?), ref: 00849B68
                                                      • ScreenToClient.USER32(?,?), ref: 00849B75
                                                      • GetParent.USER32(?), ref: 00849B93
                                                      • SendMessageW.USER32(?,00001012,00000000,?), ref: 00849BFA
                                                      • SendMessageW.USER32 ref: 00849C2B
                                                      • ClientToScreen.USER32(?,?), ref: 00849C84
                                                      • TrackPopupMenuEx.USER32(?,00000000,?,?,?,00000000), ref: 00849CB4
                                                      • SendMessageW.USER32(?,00001111,00000000,?), ref: 00849CDE
                                                      • SendMessageW.USER32 ref: 00849D01
                                                      • ClientToScreen.USER32(?,?), ref: 00849D4E
                                                      • TrackPopupMenuEx.USER32(?,00000080,?,?,?,00000000), ref: 00849D82
                                                        • Part of subcall function 007C9944: GetWindowLongW.USER32(?,000000EB), ref: 007C9952
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00849E05
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$ClientScreen$ImageLongWindow$CursorDragList_State$CaptureMenuPopupTrack$BeginEnterInvalidateParentProcRectRelease
                                                      • String ID: @GUI_DRAGID$F
                                                      • API String ID: 3429851547-4164748364
                                                      • Opcode ID: 1e8a45da8b3bab601a96c25d6e683745d0a36805c0cca96be036a90e457de754
                                                      • Instruction ID: a2b2a6dc32ec33dfe7574b9e76dc95a8f42d96c71219bd29a2cc688098abe6ca
                                                      • Opcode Fuzzy Hash: 1e8a45da8b3bab601a96c25d6e683745d0a36805c0cca96be036a90e457de754
                                                      • Instruction Fuzzy Hash: 0E427834204209AFDB60CF68CC88EABBBE9FF59314F114619F699C72A1E731A850CF51
                                                      APIs
                                                      • SendMessageW.USER32(00000000,00000408,00000000,00000000), ref: 008448F3
                                                      • SendMessageW.USER32(00000000,00000188,00000000,00000000), ref: 00844908
                                                      • SendMessageW.USER32(00000000,0000018A,00000000,00000000), ref: 00844927
                                                      • SendMessageW.USER32(?,00000148,00000000,00000000), ref: 0084494B
                                                      • SendMessageW.USER32(00000000,00000147,00000000,00000000), ref: 0084495C
                                                      • SendMessageW.USER32(00000000,00000149,00000000,00000000), ref: 0084497B
                                                      • SendMessageW.USER32(00000000,0000130B,00000000,00000000), ref: 008449AE
                                                      • SendMessageW.USER32(00000000,0000133C,00000000,?), ref: 008449D4
                                                      • SendMessageW.USER32(00000000,0000110A,00000009,00000000), ref: 00844A0F
                                                      • SendMessageW.USER32(00000000,0000113E,00000000,00000004), ref: 00844A56
                                                      • SendMessageW.USER32(00000000,0000113E,00000000,00000004), ref: 00844A7E
                                                      • IsMenu.USER32(?), ref: 00844A97
                                                      • GetMenuItemInfoW.USER32(?,?,00000000,?), ref: 00844AF2
                                                      • GetMenuItemInfoW.USER32(?,?,00000000,?), ref: 00844B20
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00844B94
                                                      • SendMessageW.USER32(?,0000113E,00000000,00000008), ref: 00844BE3
                                                      • SendMessageW.USER32(00000000,00001001,00000000,?), ref: 00844C82
                                                      • wsprintfW.USER32 ref: 00844CAE
                                                      • SendMessageW.USER32(00000000,0000000E,00000000,00000000), ref: 00844CC9
                                                      • GetWindowTextW.USER32(?,00000000,00000001), ref: 00844CF1
                                                      • SendMessageW.USER32(00000000,000000F0,00000000,00000000), ref: 00844D13
                                                      • SendMessageW.USER32(00000000,0000000E,00000000,00000000), ref: 00844D33
                                                      • GetWindowTextW.USER32(?,00000000,00000001), ref: 00844D5A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$MenuWindow$InfoItemText$Longwsprintf
                                                      • String ID: %d/%02d/%02d
                                                      • API String ID: 4054740463-328681919
                                                      • Opcode ID: c7001fa924dbed8776ac438ab7a34a32543d59433d6359c4e68698e4f511d6c6
                                                      • Instruction ID: 2d76dbcbfb1c467eaede8a8a6eebf3288cd8e3f7bdd12fba6de3ce3e65db71d8
                                                      • Opcode Fuzzy Hash: c7001fa924dbed8776ac438ab7a34a32543d59433d6359c4e68698e4f511d6c6
                                                      • Instruction Fuzzy Hash: 4B12ED71A00618ABEB249F28CC49FAE7BF8FF45714F105129F916EB2E1DB789941CB50
                                                      APIs
                                                      • GetForegroundWindow.USER32(00000000,00000000,00000000), ref: 007CF998
                                                      • FindWindowW.USER32(Shell_TrayWnd,00000000), ref: 0080F474
                                                      • IsIconic.USER32(00000000), ref: 0080F47D
                                                      • ShowWindow.USER32(00000000,00000009), ref: 0080F48A
                                                      • SetForegroundWindow.USER32(00000000), ref: 0080F494
                                                      • GetWindowThreadProcessId.USER32(00000000,00000000), ref: 0080F4AA
                                                      • GetCurrentThreadId.KERNEL32 ref: 0080F4B1
                                                      • GetWindowThreadProcessId.USER32(00000000,00000000), ref: 0080F4BD
                                                      • AttachThreadInput.USER32(?,00000000,00000001), ref: 0080F4CE
                                                      • AttachThreadInput.USER32(?,00000000,00000001), ref: 0080F4D6
                                                      • AttachThreadInput.USER32(00000000,000000FF,00000001), ref: 0080F4DE
                                                      • SetForegroundWindow.USER32(00000000), ref: 0080F4E1
                                                      • MapVirtualKeyW.USER32(00000012,00000000), ref: 0080F4F6
                                                      • keybd_event.USER32(00000012,00000000), ref: 0080F501
                                                      • MapVirtualKeyW.USER32(00000012,00000000), ref: 0080F50B
                                                      • keybd_event.USER32(00000012,00000000), ref: 0080F510
                                                      • MapVirtualKeyW.USER32(00000012,00000000), ref: 0080F519
                                                      • keybd_event.USER32(00000012,00000000), ref: 0080F51E
                                                      • MapVirtualKeyW.USER32(00000012,00000000), ref: 0080F528
                                                      • keybd_event.USER32(00000012,00000000), ref: 0080F52D
                                                      • SetForegroundWindow.USER32(00000000), ref: 0080F530
                                                      • AttachThreadInput.USER32(?,000000FF,00000000), ref: 0080F557
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Thread$AttachForegroundInputVirtualkeybd_event$Process$CurrentFindIconicShow
                                                      • String ID: Shell_TrayWnd
                                                      • API String ID: 4125248594-2988720461
                                                      • Opcode ID: 41aaca6f352644f508968b125e64c89777d2f0a14f8677a0544ec519bbcc793c
                                                      • Instruction ID: 8f1286e31ad4cc59d2319fa426ea0de351e031c5736c12bdc7ecc7a262a87d08
                                                      • Opcode Fuzzy Hash: 41aaca6f352644f508968b125e64c89777d2f0a14f8677a0544ec519bbcc793c
                                                      • Instruction Fuzzy Hash: BC315E75A41218BBEB706BB55C4AFBF7E6CFB45B50F114029FA05E61D2C6B06D00EAA0
                                                      APIs
                                                        • Part of subcall function 008116C3: LookupPrivilegeValueW.ADVAPI32(00000000,00000000,00000004), ref: 0081170D
                                                        • Part of subcall function 008116C3: AdjustTokenPrivileges.ADVAPI32(?,00000000,00000000,?,00000000,?), ref: 0081173A
                                                        • Part of subcall function 008116C3: GetLastError.KERNEL32 ref: 0081174A
                                                      • LogonUserW.ADVAPI32(?,?,?,00000000,00000000,?), ref: 00811286
                                                      • DuplicateTokenEx.ADVAPI32(?,00000000,00000000,00000002,00000001,?), ref: 008112A8
                                                      • CloseHandle.KERNEL32(?), ref: 008112B9
                                                      • OpenWindowStationW.USER32(winsta0,00000000,00060000), ref: 008112D1
                                                      • GetProcessWindowStation.USER32 ref: 008112EA
                                                      • SetProcessWindowStation.USER32(00000000), ref: 008112F4
                                                      • OpenDesktopW.USER32(default,00000000,00000000,00060081), ref: 00811310
                                                        • Part of subcall function 008110BF: AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000,?,008111FC), ref: 008110D4
                                                        • Part of subcall function 008110BF: CloseHandle.KERNEL32(?,?,008111FC), ref: 008110E9
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: StationTokenWindow$AdjustCloseHandleOpenPrivilegesProcess$DesktopDuplicateErrorLastLogonLookupPrivilegeUserValue
                                                      • String ID: $default$winsta0
                                                      • API String ID: 22674027-1027155976
                                                      • Opcode ID: c801a8b4b328a57a589f3a9a78510020c1a86f2eff867fc82439f94e02073dca
                                                      • Instruction ID: c7241843eba24ea5ca14d90ddefd302ada9300f71624874dfec6e8beff8b884e
                                                      • Opcode Fuzzy Hash: c801a8b4b328a57a589f3a9a78510020c1a86f2eff867fc82439f94e02073dca
                                                      • Instruction Fuzzy Hash: 9F818D71900209ABDF109FA8DC4DBEE7BBEFF05B04F144129FA10E62A0D7758984CB25
                                                      APIs
                                                        • Part of subcall function 008110F9: GetUserObjectSecurity.USER32(?,00000004,?,00000000,?), ref: 00811114
                                                        • Part of subcall function 008110F9: GetLastError.KERNEL32(?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 00811120
                                                        • Part of subcall function 008110F9: GetProcessHeap.KERNEL32(00000008,?,?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 0081112F
                                                        • Part of subcall function 008110F9: HeapAlloc.KERNEL32(00000000,?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 00811136
                                                        • Part of subcall function 008110F9: GetUserObjectSecurity.USER32(?,00000004,00000000,?,?), ref: 0081114D
                                                      • GetSecurityDescriptorDacl.ADVAPI32(?,?,?,?), ref: 00810BCC
                                                      • GetAclInformation.ADVAPI32(?,?,0000000C,00000002), ref: 00810C00
                                                      • GetLengthSid.ADVAPI32(?), ref: 00810C17
                                                      • GetAce.ADVAPI32(?,00000000,?), ref: 00810C51
                                                      • AddAce.ADVAPI32(?,00000002,000000FF,?,?), ref: 00810C6D
                                                      • GetLengthSid.ADVAPI32(?), ref: 00810C84
                                                      • GetProcessHeap.KERNEL32(00000008,00000008), ref: 00810C8C
                                                      • HeapAlloc.KERNEL32(00000000), ref: 00810C93
                                                      • GetLengthSid.ADVAPI32(?,00000008,?), ref: 00810CB4
                                                      • CopySid.ADVAPI32(00000000), ref: 00810CBB
                                                      • AddAce.ADVAPI32(?,00000002,000000FF,00000000,?), ref: 00810CEA
                                                      • SetSecurityDescriptorDacl.ADVAPI32(?,00000001,?,00000000), ref: 00810D0C
                                                      • SetUserObjectSecurity.USER32(?,00000004,?), ref: 00810D1E
                                                      • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00810D45
                                                      • HeapFree.KERNEL32(00000000), ref: 00810D4C
                                                      • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00810D55
                                                      • HeapFree.KERNEL32(00000000), ref: 00810D5C
                                                      • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00810D65
                                                      • HeapFree.KERNEL32(00000000), ref: 00810D6C
                                                      • GetProcessHeap.KERNEL32(00000000,?), ref: 00810D78
                                                      • HeapFree.KERNEL32(00000000), ref: 00810D7F
                                                        • Part of subcall function 00811193: GetProcessHeap.KERNEL32(00000008,00810BB1,?,00000000,?,00810BB1,?), ref: 008111A1
                                                        • Part of subcall function 00811193: HeapAlloc.KERNEL32(00000000,?,00000000,?,00810BB1,?), ref: 008111A8
                                                        • Part of subcall function 00811193: InitializeSecurityDescriptor.ADVAPI32(00000000,00000001,?,00000000,?,00810BB1,?), ref: 008111B7
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Heap$Process$Security$Free$AllocDescriptorLengthObjectUser$Dacl$CopyErrorInformationInitializeLast
                                                      • String ID:
                                                      • API String ID: 4175595110-0
                                                      • Opcode ID: d1799a26887fade3429e3cdb037bee204b548328eb4c2cd62acf4434b849098c
                                                      • Instruction ID: 8b09cbb75c6769ae384a2d5dc96db1eb726c9f5735e92be48380aaf8011057e9
                                                      • Opcode Fuzzy Hash: d1799a26887fade3429e3cdb037bee204b548328eb4c2cd62acf4434b849098c
                                                      • Instruction Fuzzy Hash: A4715CB690120AABDF10DFA4EC48BEEBBBCFF05300F144615E915E6191D7B5A985CFA0
                                                      APIs
                                                      • OpenClipboard.USER32(0084CC08), ref: 0082EB29
                                                      • IsClipboardFormatAvailable.USER32(0000000D), ref: 0082EB37
                                                      • GetClipboardData.USER32(0000000D), ref: 0082EB43
                                                      • CloseClipboard.USER32 ref: 0082EB4F
                                                      • GlobalLock.KERNEL32(00000000), ref: 0082EB87
                                                      • CloseClipboard.USER32 ref: 0082EB91
                                                      • GlobalUnlock.KERNEL32(00000000), ref: 0082EBBC
                                                      • IsClipboardFormatAvailable.USER32(00000001), ref: 0082EBC9
                                                      • GetClipboardData.USER32(00000001), ref: 0082EBD1
                                                      • GlobalLock.KERNEL32(00000000), ref: 0082EBE2
                                                      • GlobalUnlock.KERNEL32(00000000), ref: 0082EC22
                                                      • IsClipboardFormatAvailable.USER32(0000000F), ref: 0082EC38
                                                      • GetClipboardData.USER32(0000000F), ref: 0082EC44
                                                      • GlobalLock.KERNEL32(00000000), ref: 0082EC55
                                                      • DragQueryFileW.SHELL32(00000000,000000FF,00000000,00000000), ref: 0082EC77
                                                      • DragQueryFileW.SHELL32(00000000,?,?,00000104), ref: 0082EC94
                                                      • DragQueryFileW.SHELL32(00000000,?,?,00000104), ref: 0082ECD2
                                                      • GlobalUnlock.KERNEL32(00000000), ref: 0082ECF3
                                                      • CountClipboardFormats.USER32 ref: 0082ED14
                                                      • CloseClipboard.USER32 ref: 0082ED59
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Clipboard$Global$AvailableCloseDataDragFileFormatLockQueryUnlock$CountFormatsOpen
                                                      • String ID:
                                                      • API String ID: 420908878-0
                                                      • Opcode ID: 1d98e9f0f2eff1943ea2fc5d60627db7539f5ec9868f9768dbc750fd3e35d347
                                                      • Instruction ID: 70d26ad48a605bd91c8d96eeaf04639676e02377722b521ce965b4de1a8722eb
                                                      • Opcode Fuzzy Hash: 1d98e9f0f2eff1943ea2fc5d60627db7539f5ec9868f9768dbc750fd3e35d347
                                                      • Instruction Fuzzy Hash: 3C61EE38204301AFD300EF24E888F6ABBA8FF85714F14441DF956D72A2CB75E985CB66
                                                      APIs
                                                      • FindFirstFileW.KERNEL32(?,?), ref: 008269BE
                                                      • FindClose.KERNEL32(00000000), ref: 00826A12
                                                      • FileTimeToLocalFileTime.KERNEL32(?,?), ref: 00826A4E
                                                      • FileTimeToLocalFileTime.KERNEL32(?,?), ref: 00826A75
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • FileTimeToSystemTime.KERNEL32(?,?), ref: 00826AB2
                                                      • FileTimeToSystemTime.KERNEL32(?,?), ref: 00826ADF
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Time$File$FindLocalSystem$CloseFirst_wcslen
                                                      • String ID: %02d$%03d$%4d$%4d%02d%02d%02d%02d%02d$%4d%02d%02d%02d%02d%02d%03d
                                                      • API String ID: 3830820486-3289030164
                                                      • Opcode ID: daa5dd59ef565ac3564eae9c7c897fad44d51b0add3f2f8fc8d83dd560099b59
                                                      • Instruction ID: ed90acc4aeb2a21a10b72b3fc399f026b19da73d77c2113dcdb23d7b4317ce26
                                                      • Opcode Fuzzy Hash: daa5dd59ef565ac3564eae9c7c897fad44d51b0add3f2f8fc8d83dd560099b59
                                                      • Instruction Fuzzy Hash: FCD15172508350EFC314EBA4D885EABB7ECBF88704F04491DF699D6191EB78DA44CB62
                                                      APIs
                                                      • FindFirstFileW.KERNEL32(?,?,74DE8FB0,?,00000000), ref: 00829663
                                                      • GetFileAttributesW.KERNEL32(?), ref: 008296A1
                                                      • SetFileAttributesW.KERNEL32(?,?), ref: 008296BB
                                                      • FindNextFileW.KERNEL32(00000000,?), ref: 008296D3
                                                      • FindClose.KERNEL32(00000000), ref: 008296DE
                                                      • FindFirstFileW.KERNEL32(*.*,?), ref: 008296FA
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 0082974A
                                                      • SetCurrentDirectoryW.KERNEL32(00876B7C), ref: 00829768
                                                      • FindNextFileW.KERNEL32(00000000,00000010), ref: 00829772
                                                      • FindClose.KERNEL32(00000000), ref: 0082977F
                                                      • FindClose.KERNEL32(00000000), ref: 0082978F
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Find$File$Close$AttributesCurrentDirectoryFirstNext
                                                      • String ID: *.*
                                                      • API String ID: 1409584000-438819550
                                                      • Opcode ID: dd0f80fcafb6b06a82d5abcade86095e01ae9253bfbadce2d238f0f4904a830e
                                                      • Instruction ID: a4eabb6f3b957525a1e0d0f1fca76b82c4190295822f59410e6870ee7d641fc0
                                                      • Opcode Fuzzy Hash: dd0f80fcafb6b06a82d5abcade86095e01ae9253bfbadce2d238f0f4904a830e
                                                      • Instruction Fuzzy Hash: 4A31D3365016296FDB10AFB4EC48ADE77BCFF0A320F144156F955E2190EB74DD84CA14
                                                      APIs
                                                      • FindFirstFileW.KERNEL32(?,?,74DE8FB0,?,00000000), ref: 008297BE
                                                      • FindNextFileW.KERNEL32(00000000,?), ref: 00829819
                                                      • FindClose.KERNEL32(00000000), ref: 00829824
                                                      • FindFirstFileW.KERNEL32(*.*,?), ref: 00829840
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 00829890
                                                      • SetCurrentDirectoryW.KERNEL32(00876B7C), ref: 008298AE
                                                      • FindNextFileW.KERNEL32(00000000,00000010), ref: 008298B8
                                                      • FindClose.KERNEL32(00000000), ref: 008298C5
                                                      • FindClose.KERNEL32(00000000), ref: 008298D5
                                                        • Part of subcall function 0081DAE5: CreateFileW.KERNEL32(?,40000000,00000001,00000000,00000003,02000080,00000000), ref: 0081DB00
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Find$File$Close$CurrentDirectoryFirstNext$Create
                                                      • String ID: *.*
                                                      • API String ID: 2640511053-438819550
                                                      • Opcode ID: a748d0f29ed6b0314ecff41715ab36c61ab2c75d1eaf524cbb939a85339f79de
                                                      • Instruction ID: 7e0e3106991e1674fe1058e4c1251df1acec521ed94aa7b3b2f577fc8bdef7eb
                                                      • Opcode Fuzzy Hash: a748d0f29ed6b0314ecff41715ab36c61ab2c75d1eaf524cbb939a85339f79de
                                                      • Instruction Fuzzy Hash: B531C3315016296FDB14EFB4EC48ADE77BCFF06330F184166E994E2290EB75D984CA24
                                                      APIs
                                                        • Part of subcall function 0083C998: CharUpperBuffW.USER32(?,?,?,?,?,?,?,0083B6AE,?,?), ref: 0083C9B5
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083C9F1
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083CA68
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083CA9E
                                                      • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 0083BF3E
                                                      • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?,?,?), ref: 0083BFA9
                                                      • RegCloseKey.ADVAPI32(00000000), ref: 0083BFCD
                                                      • RegQueryValueExW.ADVAPI32(?,?,00000000,?,00000000,?), ref: 0083C02C
                                                      • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,00000008), ref: 0083C0E7
                                                      • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,?,?,00000000), ref: 0083C154
                                                      • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,?,?,00000000), ref: 0083C1E9
                                                      • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,00000000,?,?,?,00000000), ref: 0083C23A
                                                      • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,?,?,00000000), ref: 0083C2E3
                                                      • RegCloseKey.ADVAPI32(?,?,00000000), ref: 0083C382
                                                      • RegCloseKey.ADVAPI32(00000000), ref: 0083C38F
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: QueryValue$Close_wcslen$BuffCharConnectOpenRegistryUpper
                                                      • String ID:
                                                      • API String ID: 3102970594-0
                                                      • Opcode ID: 7d057924f4e77c972c78a88643201eb1dc8f7aa9f8623130f98910d5efd8cfad
                                                      • Instruction ID: 5e2dfdf008dbd6dfe70dcdf02a6c6d47944671222260474cea57d0a48a30e435
                                                      • Opcode Fuzzy Hash: 7d057924f4e77c972c78a88643201eb1dc8f7aa9f8623130f98910d5efd8cfad
                                                      • Instruction Fuzzy Hash: A8020B716042009FD714DF28C895E2ABBE5FF89318F18849DF84ADB2A2DB35ED45CB91
                                                      APIs
                                                      • GetLocalTime.KERNEL32(?), ref: 00828257
                                                      • SystemTimeToFileTime.KERNEL32(?,?), ref: 00828267
                                                      • LocalFileTimeToFileTime.KERNEL32(?,?), ref: 00828273
                                                      • GetCurrentDirectoryW.KERNEL32(00007FFF,?), ref: 00828310
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 00828324
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 00828356
                                                      • SetCurrentDirectoryW.KERNEL32(?,?,?,?,?), ref: 0082838C
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 00828395
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CurrentDirectoryTime$File$Local$System
                                                      • String ID: *.*
                                                      • API String ID: 1464919966-438819550
                                                      • Opcode ID: f367a6cad3911eea264db868a3cc08a5596261d8784aac0b1990c7e6ae2c03b7
                                                      • Instruction ID: dea6c7f11a398fcb72b7037e5e2bc77df8fc9faa8ef28f06cf2e392f1f438c6f
                                                      • Opcode Fuzzy Hash: f367a6cad3911eea264db868a3cc08a5596261d8784aac0b1990c7e6ae2c03b7
                                                      • Instruction Fuzzy Hash: 99614972504315DFCB10EF64D848AAEB3E8FF89314F04891AF999C7251EB35E985CB92
                                                      APIs
                                                        • Part of subcall function 007B3AA2: GetFullPathNameW.KERNEL32(?,00007FFF,?,00000000,?,?,007B3A97,?,?,007B2E7F,?,?,?,00000000), ref: 007B3AC2
                                                        • Part of subcall function 0081E199: GetFileAttributesW.KERNEL32(?,0081CF95), ref: 0081E19A
                                                      • FindFirstFileW.KERNEL32(?,?), ref: 0081D122
                                                      • DeleteFileW.KERNEL32(?,?,?,?,?,00000000,?,?,?), ref: 0081D1DD
                                                      • MoveFileW.KERNEL32(?,?), ref: 0081D1F0
                                                      • DeleteFileW.KERNEL32(?,?,?,?), ref: 0081D20D
                                                      • FindNextFileW.KERNEL32(00000000,00000010), ref: 0081D237
                                                        • Part of subcall function 0081D29C: CopyFileExW.KERNEL32(?,?,00000000,00000000,00000000,00000008,?,?,0081D21C,?,?), ref: 0081D2B2
                                                      • FindClose.KERNEL32(00000000,?,?,?), ref: 0081D253
                                                      • FindClose.KERNEL32(00000000), ref: 0081D264
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: File$Find$CloseDelete$AttributesCopyFirstFullMoveNameNextPath
                                                      • String ID: \*.*
                                                      • API String ID: 1946585618-1173974218
                                                      • Opcode ID: 161cfc07d4372b4f91d790e984c96cab9b67171a26ec4324f677fbaa3a429048
                                                      • Instruction ID: e49f302a25271c7ac3816de4f1782a724c02ec216c230a78ba32f49f66f75e14
                                                      • Opcode Fuzzy Hash: 161cfc07d4372b4f91d790e984c96cab9b67171a26ec4324f677fbaa3a429048
                                                      • Instruction Fuzzy Hash: 4A617B3180120DABCF05EBE4D996AEDB7B9FF15300F204165E512B7191EB34AF89CB61
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Clipboard$AllocCloseEmptyGlobalOpen
                                                      • String ID:
                                                      • API String ID: 1737998785-0
                                                      • Opcode ID: 3bcd0783a50432ccf3d0753468cd39f40426e13fffae51f504e4fffc7c0f9ee6
                                                      • Instruction ID: 3ff1f48c32f14d47a0e6de395c9607a1fd91ef17d9bb7008202ec32c13f61d73
                                                      • Opcode Fuzzy Hash: 3bcd0783a50432ccf3d0753468cd39f40426e13fffae51f504e4fffc7c0f9ee6
                                                      • Instruction Fuzzy Hash: FC419D39205621AFD720DF19E888B29BBE5FF45318F15C099E419CB762C779EC81CB94
                                                      APIs
                                                        • Part of subcall function 008116C3: LookupPrivilegeValueW.ADVAPI32(00000000,00000000,00000004), ref: 0081170D
                                                        • Part of subcall function 008116C3: AdjustTokenPrivileges.ADVAPI32(?,00000000,00000000,?,00000000,?), ref: 0081173A
                                                        • Part of subcall function 008116C3: GetLastError.KERNEL32 ref: 0081174A
                                                      • ExitWindowsEx.USER32(?,00000000), ref: 0081E932
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: AdjustErrorExitLastLookupPrivilegePrivilegesTokenValueWindows
                                                      • String ID: $ $@$SeShutdownPrivilege
                                                      • API String ID: 2234035333-3163812486
                                                      • Opcode ID: cb0c26ebf1a2fffccbd555dfa1ff09c2477707705d2a957453906c707ef07568
                                                      • Instruction ID: f05e902cbe1d76b5fab7efaa79a9f1252d2d62bb1f6d34d90c7d2a4b6a704466
                                                      • Opcode Fuzzy Hash: cb0c26ebf1a2fffccbd555dfa1ff09c2477707705d2a957453906c707ef07568
                                                      • Instruction Fuzzy Hash: 2A014932A10315ABEB5426B8AC8AFFF765CFF18744F150422FD13E21D1D6A55CC085A0
                                                      APIs
                                                      • socket.WSOCK32(00000002,00000001,00000006), ref: 00831276
                                                      • WSAGetLastError.WSOCK32 ref: 00831283
                                                      • bind.WSOCK32(00000000,?,00000010), ref: 008312BA
                                                      • WSAGetLastError.WSOCK32 ref: 008312C5
                                                      • closesocket.WSOCK32(00000000), ref: 008312F4
                                                      • listen.WSOCK32(00000000,00000005), ref: 00831303
                                                      • WSAGetLastError.WSOCK32 ref: 0083130D
                                                      • closesocket.WSOCK32(00000000), ref: 0083133C
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorLast$closesocket$bindlistensocket
                                                      • String ID:
                                                      • API String ID: 540024437-0
                                                      • Opcode ID: 29a7206ac2e6b3cc96c30922d75d707f2dd61475ed1625ae6a819706081f3637
                                                      • Instruction ID: 1d610b6c898d3fec574b7a19f6f0ba50f2cf742c680a281f7d56ebe111381221
                                                      • Opcode Fuzzy Hash: 29a7206ac2e6b3cc96c30922d75d707f2dd61475ed1625ae6a819706081f3637
                                                      • Instruction Fuzzy Hash: 02417F356001009FDB10DF64C488B6ABBE5FF86718F188198E856DF296C775ED81CBE1
                                                      APIs
                                                        • Part of subcall function 007B3AA2: GetFullPathNameW.KERNEL32(?,00007FFF,?,00000000,?,?,007B3A97,?,?,007B2E7F,?,?,?,00000000), ref: 007B3AC2
                                                        • Part of subcall function 0081E199: GetFileAttributesW.KERNEL32(?,0081CF95), ref: 0081E19A
                                                      • FindFirstFileW.KERNEL32(?,?), ref: 0081D420
                                                      • DeleteFileW.KERNEL32(?,?,?,?), ref: 0081D470
                                                      • FindNextFileW.KERNEL32(00000000,00000010), ref: 0081D481
                                                      • FindClose.KERNEL32(00000000), ref: 0081D498
                                                      • FindClose.KERNEL32(00000000), ref: 0081D4A1
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FileFind$Close$AttributesDeleteFirstFullNameNextPath
                                                      • String ID: \*.*
                                                      • API String ID: 2649000838-1173974218
                                                      • Opcode ID: 668c281f38bdd11c30c64302713d9bd508da6a8178a1e134c198521e0c9b8287
                                                      • Instruction ID: 46a68ffa8539213f2c77d5263a435ddde62a08f5216d3627c91567542c066943
                                                      • Opcode Fuzzy Hash: 668c281f38bdd11c30c64302713d9bd508da6a8178a1e134c198521e0c9b8287
                                                      • Instruction Fuzzy Hash: 3A319C71009355ABC300EF64C899AEFB7ECBE92304F444A1DF5E593191EB34AA49CB67
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: __floor_pentium4
                                                      • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                                      • API String ID: 4168288129-2761157908
                                                      • Opcode ID: bc57be55b44c0240b66c3747f25bed99f292ed244f8c71cab34a3e7298901e05
                                                      • Instruction ID: ff0a9df85205f84eb1eb104872bac5011a686f8a6c19bdb6e1503f1d18d1af3d
                                                      • Opcode Fuzzy Hash: bc57be55b44c0240b66c3747f25bed99f292ed244f8c71cab34a3e7298901e05
                                                      • Instruction Fuzzy Hash: B0C27B72E066688FDB25CF29CD407EAB7B5EB48305F1445EAD84DE7241E778AE818F40
                                                      APIs
                                                      • _wcslen.LIBCMT ref: 008264DC
                                                      • CoInitialize.OLE32(00000000), ref: 00826639
                                                      • CoCreateInstance.OLE32(0084FCF8,00000000,00000001,0084FB68,?), ref: 00826650
                                                      • CoUninitialize.OLE32 ref: 008268D4
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CreateInitializeInstanceUninitialize_wcslen
                                                      • String ID: .lnk
                                                      • API String ID: 886957087-24824748
                                                      • Opcode ID: f893096d4e7322b891f1f0eef19796161fb3015edb03fc595b929e2a869b9737
                                                      • Instruction ID: 4677cc5c1f57fbde6181ca4938c1c62aecb4db10334f93fadb96429c1f53431a
                                                      • Opcode Fuzzy Hash: f893096d4e7322b891f1f0eef19796161fb3015edb03fc595b929e2a869b9737
                                                      • Instruction Fuzzy Hash: C8D15871508211AFC304EF24C885AABB7E8FF98704F14496DF595CB2A1EB34ED45CBA2
                                                      APIs
                                                      • GetForegroundWindow.USER32(?,?,00000000), ref: 008322E8
                                                        • Part of subcall function 0082E4EC: GetWindowRect.USER32(?,?), ref: 0082E504
                                                      • GetDesktopWindow.USER32 ref: 00832312
                                                      • GetWindowRect.USER32(00000000), ref: 00832319
                                                      • mouse_event.USER32(00008001,?,?,00000002,00000002), ref: 00832355
                                                      • GetCursorPos.USER32(?), ref: 00832381
                                                      • mouse_event.USER32(00008001,?,?,00000000,00000000), ref: 008323DF
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Rectmouse_event$CursorDesktopForeground
                                                      • String ID:
                                                      • API String ID: 2387181109-0
                                                      • Opcode ID: f06ed5bdcac63c6205850c3c8191deb3677bd4343c5f01638555030887f8093e
                                                      • Instruction ID: 946e2557c38b3416bf38cb2bbc364231dc1a472b907eadae8f6ae49a9e72cdea
                                                      • Opcode Fuzzy Hash: f06ed5bdcac63c6205850c3c8191deb3677bd4343c5f01638555030887f8093e
                                                      • Instruction Fuzzy Hash: 6C31EB72505315ABD720DF18C848A9BBBADFFC9314F000A19F985D7291DB34EA08CBD2
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • FindFirstFileW.KERNEL32(00000001,?,*.*,?,?,00000000,00000000), ref: 00829B78
                                                      • FindClose.KERNEL32(00000000,?,00000000,00000000), ref: 00829C8B
                                                        • Part of subcall function 00823874: GetInputState.USER32 ref: 008238CB
                                                        • Part of subcall function 00823874: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00823966
                                                      • Sleep.KERNEL32(0000000A,?,00000000,00000000), ref: 00829BA8
                                                      • FindNextFileW.KERNEL32(?,?,?,00000000,00000000), ref: 00829C75
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Find$File$CloseFirstInputMessageNextPeekSleepState_wcslen
                                                      • String ID: *.*
                                                      • API String ID: 1972594611-438819550
                                                      • Opcode ID: 8d6dd3521b0e469653de16e939843667445395c3c7d063fb045469a66e6013e0
                                                      • Instruction ID: 4a4664865148f167111ad4607857d5179e4b70d8b033192ae8a2877702140989
                                                      • Opcode Fuzzy Hash: 8d6dd3521b0e469653de16e939843667445395c3c7d063fb045469a66e6013e0
                                                      • Instruction Fuzzy Hash: 3F418E7190021AAFDF55DF64D889AEEBBB8FF05310F24405AE855E2291EB349E84CF60
                                                      APIs
                                                        • Part of subcall function 007C9BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 007C9BB2
                                                      • DefDlgProcW.USER32(?,?,?,?,?), ref: 007C9A4E
                                                      • GetSysColor.USER32(0000000F), ref: 007C9B23
                                                      • SetBkColor.GDI32(?,00000000), ref: 007C9B36
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Color$LongProcWindow
                                                      • String ID:
                                                      • API String ID: 3131106179-0
                                                      • Opcode ID: 25d334b42d0d155e1977b6d2f3a241c4b62233b5837774586cd6a0791387cd1b
                                                      • Instruction ID: 250f5027b649dc180fd2d61af20620e28a309c606707483054bb19aef8032d35
                                                      • Opcode Fuzzy Hash: 25d334b42d0d155e1977b6d2f3a241c4b62233b5837774586cd6a0791387cd1b
                                                      • Instruction Fuzzy Hash: 27A127B1609444BEE7B5AA2C8C4DF7F2B9DFB42340B15811DF212D66D1CA29AD01D376
                                                      APIs
                                                        • Part of subcall function 0083304E: inet_addr.WSOCK32(?), ref: 0083307A
                                                        • Part of subcall function 0083304E: _wcslen.LIBCMT ref: 0083309B
                                                      • socket.WSOCK32(00000002,00000002,00000011), ref: 0083185D
                                                      • WSAGetLastError.WSOCK32 ref: 00831884
                                                      • bind.WSOCK32(00000000,?,00000010), ref: 008318DB
                                                      • WSAGetLastError.WSOCK32 ref: 008318E6
                                                      • closesocket.WSOCK32(00000000), ref: 00831915
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorLast$_wcslenbindclosesocketinet_addrsocket
                                                      • String ID:
                                                      • API String ID: 1601658205-0
                                                      • Opcode ID: d643066a3f3dfbbcfcfef5ab8d7823a607e92763bd3d5455d51584a6bad5b97c
                                                      • Instruction ID: 908772a10ccc822ab6519cbdc44b03cba4dc68ec11ef0de54987b4f9a4fd0b4f
                                                      • Opcode Fuzzy Hash: d643066a3f3dfbbcfcfef5ab8d7823a607e92763bd3d5455d51584a6bad5b97c
                                                      • Instruction Fuzzy Hash: BC519175A00200AFDB10AF24C88AF6A77E5EB85718F08849CF9069F393C775AD41CBE1
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$EnabledForegroundIconicVisibleZoomed
                                                      • String ID:
                                                      • API String ID: 292994002-0
                                                      • Opcode ID: ecd43e7d4e7dbb4b37fb103c6017dc3d56f94fbd475ec9ee2296612c1daf15b4
                                                      • Instruction ID: b6cf2a1207dfd86d62ba0327f0e5ecbda89ab54a4ea887ae4226030dd16777e2
                                                      • Opcode Fuzzy Hash: ecd43e7d4e7dbb4b37fb103c6017dc3d56f94fbd475ec9ee2296612c1daf15b4
                                                      • Instruction Fuzzy Hash: 5C21D3317412159FDB208F1ADC88B6A7BE9FF95315B198058E84ACB351C775DC82CB90
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: ERCP$VUUU$VUUU$VUUU$VUUU
                                                      • API String ID: 0-1546025612
                                                      • Opcode ID: 4e26d3e98fa97253bf5ee3e623b83e6f72ca883769504f5c79c6217fe26746d2
                                                      • Instruction ID: a935b0329c206711c9a0025703c797e44efb9536168389ab3c51ab5513a98be9
                                                      • Opcode Fuzzy Hash: 4e26d3e98fa97253bf5ee3e623b83e6f72ca883769504f5c79c6217fe26746d2
                                                      • Instruction Fuzzy Hash: 8CA24A70A0021ECBDF64CF58C8407FDB7B5BB54314F2481AAEA15AB385EB789D81DB91
                                                      APIs
                                                      • GetKeyboardState.USER32(?,00000001,00000040,00000000), ref: 0081AAAC
                                                      • SetKeyboardState.USER32(00000080), ref: 0081AAC8
                                                      • PostMessageW.USER32(?,00000102,00000001,00000001), ref: 0081AB36
                                                      • SendInput.USER32(00000001,?,0000001C,00000001,00000040,00000000), ref: 0081AB88
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: KeyboardState$InputMessagePostSend
                                                      • String ID:
                                                      • API String ID: 432972143-0
                                                      • Opcode ID: 595f3f1a9d7b8a444da205aa039bcf3af491694b3e74a3d8ac1a3cd6b893f401
                                                      • Instruction ID: c888791674a9e236ec8f1967d991f9ed7eb46355b3642917957b297c6a71b242
                                                      • Opcode Fuzzy Hash: 595f3f1a9d7b8a444da205aa039bcf3af491694b3e74a3d8ac1a3cd6b893f401
                                                      • Instruction Fuzzy Hash: 66312570A46288AEEB38CA68CC05BFA7BAEFF55330F04421AF081D21D1D37589C1C762
                                                      APIs
                                                      • _free.LIBCMT ref: 007EBB7F
                                                        • Part of subcall function 007E29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000), ref: 007E29DE
                                                        • Part of subcall function 007E29C8: GetLastError.KERNEL32(00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000,00000000), ref: 007E29F0
                                                      • GetTimeZoneInformation.KERNEL32 ref: 007EBB91
                                                      • WideCharToMultiByte.KERNEL32(00000000,?,0088121C,000000FF,?,0000003F,?,?), ref: 007EBC09
                                                      • WideCharToMultiByte.KERNEL32(00000000,?,00881270,000000FF,?,0000003F,?,?,?,0088121C,000000FF,?,0000003F,?,?), ref: 007EBC36
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharMultiWide$ErrorFreeHeapInformationLastTimeZone_free
                                                      • String ID:
                                                      • API String ID: 806657224-0
                                                      • Opcode ID: c6865c5d94ada38534294776684d01a3b469161e2e2a9aff7a3b85d23a3539b8
                                                      • Instruction ID: 5fe1aabd7d025a8043cc766793f5e1ddcd020e1f17c44333d3771d6bf617c662
                                                      • Opcode Fuzzy Hash: c6865c5d94ada38534294776684d01a3b469161e2e2a9aff7a3b85d23a3539b8
                                                      • Instruction Fuzzy Hash: 2031B270909285DFCB11DF6ADC8586ABFBCFF49750B24426AE060D72B1DB349D02CB60
                                                      APIs
                                                      • InternetReadFile.WININET(?,?,00000400,?), ref: 0082CE89
                                                      • GetLastError.KERNEL32(?,00000000), ref: 0082CEEA
                                                      • SetEvent.KERNEL32(?,?,00000000), ref: 0082CEFE
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorEventFileInternetLastRead
                                                      • String ID:
                                                      • API String ID: 234945975-0
                                                      • Opcode ID: 178b6b28b62f1882852aed5dcf1e4e69b92e8834a4f05b4c9d982a0236625ccb
                                                      • Instruction ID: 6f6587535dbbc486be53583dfd6afe318078846b70efbf08eff17e4576e6b68f
                                                      • Opcode Fuzzy Hash: 178b6b28b62f1882852aed5dcf1e4e69b92e8834a4f05b4c9d982a0236625ccb
                                                      • Instruction Fuzzy Hash: 9221BDB5500715EBDB20DFA5E948BAABBFCFB10358F10441EE546D2251EBB4EE84CB60
                                                      APIs
                                                      • lstrlenW.KERNEL32(?,?,?,00000000), ref: 008182AA
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: lstrlen
                                                      • String ID: ($|
                                                      • API String ID: 1659193697-1631851259
                                                      • Opcode ID: d6ae90395ee45484e27afbd9b5a1d75dd5731fabd0038ce3bcbf77aa9f396867
                                                      • Instruction ID: 5eaab2fcd789cc79e39935a399d08f09eba5375629fe6b5693ed5cfe750dcbfb
                                                      • Opcode Fuzzy Hash: d6ae90395ee45484e27afbd9b5a1d75dd5731fabd0038ce3bcbf77aa9f396867
                                                      • Instruction Fuzzy Hash: F2323674A00605DFC728CF59C481AAAB7F4FF48710B15C56EE59ADB3A1EB70E981CB40
                                                      APIs
                                                      • FindFirstFileW.KERNEL32(?,?), ref: 00825CC1
                                                      • FindNextFileW.KERNEL32(00000000,?), ref: 00825D17
                                                      • FindClose.KERNEL32(?), ref: 00825D5F
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Find$File$CloseFirstNext
                                                      • String ID:
                                                      • API String ID: 3541575487-0
                                                      • Opcode ID: 5feb721cd0d2887cc0e539f5560e984ec56bd50ed11870745d78fa531f533505
                                                      • Instruction ID: 6df17040c9e66a1c8680cb9c55f272c90e0555d0cbd79a566c0745b7dcbe5cce
                                                      • Opcode Fuzzy Hash: 5feb721cd0d2887cc0e539f5560e984ec56bd50ed11870745d78fa531f533505
                                                      • Instruction Fuzzy Hash: B751A835600A019FC314CF28D498A9AB7E4FF09324F14856EE95ACB3A2DB30ED44CB91
                                                      APIs
                                                      • IsDebuggerPresent.KERNEL32 ref: 007E271A
                                                      • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 007E2724
                                                      • UnhandledExceptionFilter.KERNEL32(?), ref: 007E2731
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                                      • String ID:
                                                      • API String ID: 3906539128-0
                                                      • Opcode ID: f68e90561578566727a515d9ac1b0daa53820a25b9be3f7011eae8c659cc66e2
                                                      • Instruction ID: 5d86e878b77766ebb493418cda938315fa509f17597ee868deb348b428ef05e6
                                                      • Opcode Fuzzy Hash: f68e90561578566727a515d9ac1b0daa53820a25b9be3f7011eae8c659cc66e2
                                                      • Instruction Fuzzy Hash: E731B5749112189BCB21DF65DC8979DB7B8BF08310F5051EAE41CA7261E7749F818F45
                                                      APIs
                                                      • SetErrorMode.KERNEL32(00000001), ref: 008251DA
                                                      • GetDiskFreeSpaceExW.KERNEL32(?,?,?,?), ref: 00825238
                                                      • SetErrorMode.KERNEL32(00000000), ref: 008252A1
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorMode$DiskFreeSpace
                                                      • String ID:
                                                      • API String ID: 1682464887-0
                                                      • Opcode ID: 2b0692dae3f1f9ce0686b25e9d852877d35d938df9b19c9199f5fa9b128b322b
                                                      • Instruction ID: c4de5d7ea6e1350daeb794baad217fa1f8004e41ff578703a452271caeb71127
                                                      • Opcode Fuzzy Hash: 2b0692dae3f1f9ce0686b25e9d852877d35d938df9b19c9199f5fa9b128b322b
                                                      • Instruction Fuzzy Hash: 59314C75A00618DFDB00DF54D888FADBBB4FF49314F188099E805AB3A2DB35E855CBA0
                                                      APIs
                                                        • Part of subcall function 007CFDDB: __CxxThrowException@8.LIBVCRUNTIME ref: 007D0668
                                                        • Part of subcall function 007CFDDB: __CxxThrowException@8.LIBVCRUNTIME ref: 007D0685
                                                      • LookupPrivilegeValueW.ADVAPI32(00000000,00000000,00000004), ref: 0081170D
                                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,00000000,?,00000000,?), ref: 0081173A
                                                      • GetLastError.KERNEL32 ref: 0081174A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Exception@8Throw$AdjustErrorLastLookupPrivilegePrivilegesTokenValue
                                                      • String ID:
                                                      • API String ID: 577356006-0
                                                      • Opcode ID: 0bfc823786314b777ad8f0ea81c1ae94f34fa848e9eab74611b62b67b861bd68
                                                      • Instruction ID: f7cd3a7242af2bcf2d2a55666ae5422cc402c3e67f6dbe3de8abae2f4addbac2
                                                      • Opcode Fuzzy Hash: 0bfc823786314b777ad8f0ea81c1ae94f34fa848e9eab74611b62b67b861bd68
                                                      • Instruction Fuzzy Hash: 551191B2514309AFD7189F54DC8AEAAB7FDFF44714B20852EE05697291EB70BC81CA60
                                                      APIs
                                                      • CreateFileW.KERNEL32(?,00000080,00000003,00000000,00000003,00000080,00000000), ref: 0081D608
                                                      • DeviceIoControl.KERNEL32(00000000,002D1400,?,0000000C,?,00000028,?,00000000), ref: 0081D645
                                                      • CloseHandle.KERNEL32(?,?,00000080,00000003,00000000,00000003,00000080,00000000), ref: 0081D650
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CloseControlCreateDeviceFileHandle
                                                      • String ID:
                                                      • API String ID: 33631002-0
                                                      • Opcode ID: 319d748bb5250c71a25b3e58894f324e38fe24736270b03d370dfbf4277e347b
                                                      • Instruction ID: f3f2bb63242efa200f1e517f08d0b503c876247f0c0a7397c7dc75484ce963fd
                                                      • Opcode Fuzzy Hash: 319d748bb5250c71a25b3e58894f324e38fe24736270b03d370dfbf4277e347b
                                                      • Instruction Fuzzy Hash: 6D113C75E05228BBDB208F95AC45FAFBBBCFB45B50F108115F904E7290D6B05A058BA1
                                                      APIs
                                                      • AllocateAndInitializeSid.ADVAPI32(?,00000002,00000020,00000220,00000000,00000000,00000000,00000000,00000000,00000000,?,?), ref: 0081168C
                                                      • CheckTokenMembership.ADVAPI32(00000000,?,?), ref: 008116A1
                                                      • FreeSid.ADVAPI32(?), ref: 008116B1
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: AllocateCheckFreeInitializeMembershipToken
                                                      • String ID:
                                                      • API String ID: 3429775523-0
                                                      • Opcode ID: 94dff07213445ce5295e3b454c0b67d7a673cc707522e444821643eb7e9a5e2f
                                                      • Instruction ID: 08d28467e565838e88e6f329e6d717e97354cf708979bf115c6e85bb70eed289
                                                      • Opcode Fuzzy Hash: 94dff07213445ce5295e3b454c0b67d7a673cc707522e444821643eb7e9a5e2f
                                                      • Instruction Fuzzy Hash: 03F0F475A51309FBDF00DFE49C89AAEBBBCFB08605F504965E501E2181E774AA448A54
                                                      APIs
                                                      • GetUserNameW.ADVAPI32(?,?), ref: 0080D28C
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: NameUser
                                                      • String ID: X64
                                                      • API String ID: 2645101109-893830106
                                                      • Opcode ID: 8998da5bf2991af5f2767e73466c3d83431398e75e884cddccf48fd72909cc2b
                                                      • Instruction ID: cc6a150767ee1976015c787b84510d26dad30c984967cd4fba8fc478e37ba1a9
                                                      • Opcode Fuzzy Hash: 8998da5bf2991af5f2767e73466c3d83431398e75e884cddccf48fd72909cc2b
                                                      • Instruction Fuzzy Hash: 6DD0C9B480211DEBCB90CB90DC88DD9B37CBB14305F100155F106E2040D77495488F10
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 2fbdbeface8d474e65e3d830227d731b015bc4fe83c76ff0107a9da6199ccf29
                                                      • Instruction ID: 887e2f7fe43384356b54a913814697f260e245b0739f1c841e5ba9d30cee4775
                                                      • Opcode Fuzzy Hash: 2fbdbeface8d474e65e3d830227d731b015bc4fe83c76ff0107a9da6199ccf29
                                                      • Instruction Fuzzy Hash: 01022E72E0011A9FDF15CFA9C9806ADFBF1EF48314F25826AD919E7384D735A941CB90
                                                      APIs
                                                      • FindFirstFileW.KERNEL32(?,?), ref: 00826918
                                                      • FindClose.KERNEL32(00000000), ref: 00826961
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Find$CloseFileFirst
                                                      • String ID:
                                                      • API String ID: 2295610775-0
                                                      • Opcode ID: d4008379dc71207df22c81a74ea5ca8931991878c9caed257a498b8bf5e93bb0
                                                      • Instruction ID: 8d9f7b6728609dea5a29e02c43d6058468cee4ae1b73bef59749d778be6a30b3
                                                      • Opcode Fuzzy Hash: d4008379dc71207df22c81a74ea5ca8931991878c9caed257a498b8bf5e93bb0
                                                      • Instruction Fuzzy Hash: 6E11D0356042109FC710CF29D488A26BBE4FF85328F04C699F4698F2A2DB74EC85CB90
                                                      APIs
                                                      • GetLastError.KERNEL32(00000000,?,00000FFF,00000000,?,?,?,00834891,?,?,00000035,?), ref: 008237E4
                                                      • FormatMessageW.KERNEL32(00001000,00000000,?,00000000,?,00000FFF,00000000,?,?,?,00834891,?,?,00000035,?), ref: 008237F4
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorFormatLastMessage
                                                      • String ID:
                                                      • API String ID: 3479602957-0
                                                      • Opcode ID: bf92905cec17bc47c5f5f396646061b3c8abd7085f8e20571bffa2964c115564
                                                      • Instruction ID: 0240b8c5be96d6e16e1d173495479ba12d2fcb4ac3bf872b37bc19bf9cff9491
                                                      • Opcode Fuzzy Hash: bf92905cec17bc47c5f5f396646061b3c8abd7085f8e20571bffa2964c115564
                                                      • Instruction Fuzzy Hash: 8CF0E5B46052286BEB6017B69C4DFEB3AAEFFC5761F000275F609D2291D9A09944C6B0
                                                      APIs
                                                      • SendInput.USER32(00000001,?,0000001C,?,?,00000002), ref: 0081B25D
                                                      • keybd_event.USER32(?,75C0C0D0,?,00000000), ref: 0081B270
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: InputSendkeybd_event
                                                      • String ID:
                                                      • API String ID: 3536248340-0
                                                      • Opcode ID: 5db047f0597291159f2de79dea8ca5d0c18c9bf2f3ff2f60f4c04fb9cef8336a
                                                      • Instruction ID: 7c6ee300b6d925419e4cad1608e8953ad65c99901dd41ff6ae06468f9a391c97
                                                      • Opcode Fuzzy Hash: 5db047f0597291159f2de79dea8ca5d0c18c9bf2f3ff2f60f4c04fb9cef8336a
                                                      • Instruction Fuzzy Hash: 44F01D7590424DABDB159FA4C805BEE7BB4FF05309F008009F955E6191C3798655DF94
                                                      APIs
                                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000,?,008111FC), ref: 008110D4
                                                      • CloseHandle.KERNEL32(?,?,008111FC), ref: 008110E9
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: AdjustCloseHandlePrivilegesToken
                                                      • String ID:
                                                      • API String ID: 81990902-0
                                                      • Opcode ID: 8acd8b9fe8228e3fbe09e7bb375cd6c6e21ee067118e2a098458220658e6f66a
                                                      • Instruction ID: da4ea6254f5ed1069c50aabcededfb4646f32e9f73926cff854c1498d39e5e1c
                                                      • Opcode Fuzzy Hash: 8acd8b9fe8228e3fbe09e7bb375cd6c6e21ee067118e2a098458220658e6f66a
                                                      • Instruction Fuzzy Hash: E1E0BF76115A10EEE7652F51FC09F7777ADFF05310B14882EF5A6804B1DB626C90DB50
                                                      Strings
                                                      • Variable is not of type 'Object'., xrefs: 00800C40
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Variable is not of type 'Object'.
                                                      • API String ID: 0-1840281001
                                                      • Opcode ID: 0737545edb8471297625bae86863010f95fe8268c84d6ab0aac056d78fd80f44
                                                      • Instruction ID: 24e2820227c6b8a1d3c4fdf88ff481ce9e6762616b0c1629da2b38e240bfb3cc
                                                      • Opcode Fuzzy Hash: 0737545edb8471297625bae86863010f95fe8268c84d6ab0aac056d78fd80f44
                                                      • Instruction Fuzzy Hash: 3C329C74A00218DFDF15DF94C895BEDBBB5FF05304F248069E806AB292DB79AE45CB60
                                                      APIs
                                                      • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,007E6766,?,?,00000008,?,?,007EFEFE,00000000), ref: 007E6998
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ExceptionRaise
                                                      • String ID:
                                                      • API String ID: 3997070919-0
                                                      • Opcode ID: 5ca036b4220c24f7424240c83599b118ca6fc22fbe4620ebff5dfae822c63a24
                                                      • Instruction ID: 3afdcb59fc3100b23658443fa656ca690f740d629dd42764941fd857d91f3ac1
                                                      • Opcode Fuzzy Hash: 5ca036b4220c24f7424240c83599b118ca6fc22fbe4620ebff5dfae822c63a24
                                                      • Instruction Fuzzy Hash: B5B169716116488FD719CF29C48AB647BE0FF193A4F25C65CE899CF2A2C339E981CB40
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: a78dbb6819c49db2e9e7052a271377b9271305f6dbbce470e46382db87fa63f1
                                                      • Instruction ID: 66cdfa7cca44f0f9bc7b66500fdac595c8993bcf01a90416ba66c63356266075
                                                      • Opcode Fuzzy Hash: a78dbb6819c49db2e9e7052a271377b9271305f6dbbce470e46382db87fa63f1
                                                      • Instruction Fuzzy Hash: F9123E71900229DFDB54CF58C881BEEB7B5FF48710F15819AE849EB295EB349A81CF90
                                                      APIs
                                                      • BlockInput.USER32(00000001), ref: 0082EABD
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: BlockInput
                                                      • String ID:
                                                      • API String ID: 3456056419-0
                                                      • Opcode ID: aa56408e5682c4cb4dbeaf8db820746673cd235f66a32d49cedb923d0559c82f
                                                      • Instruction ID: 1dda23cd55a898d8b9141e4f57ee34f6e77e6bc6c0041d0528a3ea8aa1b0bc32
                                                      • Opcode Fuzzy Hash: aa56408e5682c4cb4dbeaf8db820746673cd235f66a32d49cedb923d0559c82f
                                                      • Instruction Fuzzy Hash: 2EE012752002149FC710DF59D404E9AB7EDFF69760F00841AFC4AC7251D674A8408B91
                                                      APIs
                                                      • SetUnhandledExceptionFilter.KERNEL32(Function_000209E1,007D03EE), ref: 007D09DA
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ExceptionFilterUnhandled
                                                      • String ID:
                                                      • API String ID: 3192549508-0
                                                      • Opcode ID: eddd58dab075fd5e131effaa5bc80b888fcc747710d51c99b6f562efa945445e
                                                      • Instruction ID: 0ed1eb06eb66f68bd871d8577a5c3774b430488172c0f00202e36d148d87abaf
                                                      • Opcode Fuzzy Hash: eddd58dab075fd5e131effaa5bc80b888fcc747710d51c99b6f562efa945445e
                                                      • Instruction Fuzzy Hash:
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: 0
                                                      • API String ID: 0-4108050209
                                                      • Opcode ID: 9084b4e029052128895840c3c28e948f6724b1d83b91d22a18243ac96ad56844
                                                      • Instruction ID: 524fc1e03a5d6f68f95409f4f15ad6012ac6d82fca642812d005cce6c09e7a18
                                                      • Opcode Fuzzy Hash: 9084b4e029052128895840c3c28e948f6724b1d83b91d22a18243ac96ad56844
                                                      • Instruction Fuzzy Hash: E451677260C7459BDB3C856888AE7BE67B99B52300F18050BD886DB382F61DEE41E356
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: cf789f8af10a6d13a9d3ec2a9702d2ad4439d26ada26f9f74d990df3287c30cc
                                                      • Instruction ID: ba2920f483475723c66805b7642280a74f2461043f9b3179ad6762511c073cda
                                                      • Opcode Fuzzy Hash: cf789f8af10a6d13a9d3ec2a9702d2ad4439d26ada26f9f74d990df3287c30cc
                                                      • Instruction Fuzzy Hash: 05322322D2AF814DD7279635D8223356259BFBB3C6F14D737E81AB59A6EF2DC4838100
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 3fb6ebf565cb25174ace8702e73a4b02b6677d437b689461c7150179e2648bd8
                                                      • Instruction ID: fd448adea62279b9153319ff48474851b6d5eaa88ec86510d29cbf7b4d251a43
                                                      • Opcode Fuzzy Hash: 3fb6ebf565cb25174ace8702e73a4b02b6677d437b689461c7150179e2648bd8
                                                      • Instruction Fuzzy Hash: 51320232A041198BDF79CF29C894B7D7BA1FB45314F28826ED89ACB2D1D234DD81DB51
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 521293262bbeafdb4d815ac79e479a4abd26691d79e3c04132e44ab9c30885a2
                                                      • Instruction ID: da360f733b950ba6777d4032e7b28461b65de1e4ef6be1d49fea559222a024f3
                                                      • Opcode Fuzzy Hash: 521293262bbeafdb4d815ac79e479a4abd26691d79e3c04132e44ab9c30885a2
                                                      • Instruction Fuzzy Hash: 8A228EB0A04609DFDF14DF68D885BEEB7B6FF44300F204529E916AB391EB39A951CB50
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 33de26385668d8461dce66500748765c2dd9077ae83f088181d613008c4f1d72
                                                      • Instruction ID: 477fbd10c624b78aaea92dedf39f93e414dec230005efe4a9c4e0056ba7d6ba4
                                                      • Opcode Fuzzy Hash: 33de26385668d8461dce66500748765c2dd9077ae83f088181d613008c4f1d72
                                                      • Instruction Fuzzy Hash: 1E02A7B1E00209EBDB14DF64D885BBDB7B5FF44300F108169EA169B3A1EB39DA50DB91
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: fcf81f42ef7b0397818b8064c40af0fdcf99f19b227230f2396317225a808119
                                                      • Instruction ID: 9369cbbd8c18c3eef5974c26225465263018a679ea9a2286a9b3b2376b0af720
                                                      • Opcode Fuzzy Hash: fcf81f42ef7b0397818b8064c40af0fdcf99f19b227230f2396317225a808119
                                                      • Instruction Fuzzy Hash: 31B1F020D2AF414DC62396399831336B75CBFBB6D6F91D31BFC2674E22EB2686834140
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 93657a121f16255c59120ad0d08fdbba6372c273009ad596b4ecdf6e8f3c6909
                                                      • Instruction ID: ad58c1e606bf26f58a887eac6606d20549147af21a86469759dc06de5e240761
                                                      • Opcode Fuzzy Hash: 93657a121f16255c59120ad0d08fdbba6372c273009ad596b4ecdf6e8f3c6909
                                                      • Instruction Fuzzy Hash: B79176722090E35ADB29463E857403EFFF15A923A235A079FD4F2CA3C5FE28D954D620
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 05e0b846b00456d0f1e87463b9d189974beed2fe63262d4392584e128a114ea2
                                                      • Instruction ID: 8f2028f9bc27fce677bd02f5cf124f41e5b8e23481cceb1df10d1fc05fd0e4d0
                                                      • Opcode Fuzzy Hash: 05e0b846b00456d0f1e87463b9d189974beed2fe63262d4392584e128a114ea2
                                                      • Instruction Fuzzy Hash: 0E9169722090E349DB6D4339857403DFFF15AA23A131A479FE4F2CB2C6EE29D556D620
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 40101273f58913c3cb3bc7eb54df01d47b4121c3e67d19f11ec2cb23d33ea445
                                                      • Instruction ID: ab9bc2a21a5880f6d25682787912b68eecbb869972b73ae910fe2b26a87cdbd3
                                                      • Opcode Fuzzy Hash: 40101273f58913c3cb3bc7eb54df01d47b4121c3e67d19f11ec2cb23d33ea445
                                                      • Instruction Fuzzy Hash: B89154722090E35ADB2D427A857403EFFF15A923A239A479FD4F2CA2C5FE28D554D620
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: f7254075197c6e3f3e73751c42fe2aa758b471049a743cdbfcae28d361e71a25
                                                      • Instruction ID: 62142cea7ef744e1fbfd2ac3c34bec2f5e6f6d0a64d72cc962736b87afec309a
                                                      • Opcode Fuzzy Hash: f7254075197c6e3f3e73751c42fe2aa758b471049a743cdbfcae28d361e71a25
                                                      • Instruction Fuzzy Hash: 44614BB120874996DA3C5A2C8D96BBE23B8DF81700F14491FE846DB381F61DDE42C366
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: dce13b0d871eef399c94097beece11b31ebd49e1a40d3b04c283d1cab66b3997
                                                      • Instruction ID: 7b32e13d9d46272207342d8e12e924cb833b0b7b50492969595cfd25d5115b8d
                                                      • Opcode Fuzzy Hash: dce13b0d871eef399c94097beece11b31ebd49e1a40d3b04c283d1cab66b3997
                                                      • Instruction Fuzzy Hash: 39616A7170870996DE3C4A288896BBF63B6DF42704F14095BE983DB381FA1EED42C256
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 70da388f96bbbf26b230a155b4728740b34f0d100ea60ab2bbadb9d7d0befbf0
                                                      • Instruction ID: 893de2ce9f4573d324b55c64d80b79c86ea1fd9f15ab7398311d744167746b4a
                                                      • Opcode Fuzzy Hash: 70da388f96bbbf26b230a155b4728740b34f0d100ea60ab2bbadb9d7d0befbf0
                                                      • Instruction Fuzzy Hash: F78163726090E319EB6D827A853443EFFF15A923B135A079FD4F2CA2D1EE289554E620
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 06113e9d275bb668a73157ddaa1f1c24ed544c7273796778d8a9c7839bba3a06
                                                      • Instruction ID: 3f57fcf30c17d3eedcbaa1ce4a44b30b1f8cd67a3bdae20d0beae84e3e6f6985
                                                      • Opcode Fuzzy Hash: 06113e9d275bb668a73157ddaa1f1c24ed544c7273796778d8a9c7839bba3a06
                                                      • Instruction Fuzzy Hash: D621A8326206218BD728CE79C81267A73E5FB64310F15862EE4A7C77D0DE35A944CB40
                                                      APIs
                                                      • DeleteObject.GDI32(00000000), ref: 00832B30
                                                      • DeleteObject.GDI32(00000000), ref: 00832B43
                                                      • DestroyWindow.USER32 ref: 00832B52
                                                      • GetDesktopWindow.USER32 ref: 00832B6D
                                                      • GetWindowRect.USER32(00000000), ref: 00832B74
                                                      • SetRect.USER32(?,00000000,00000000,00000007,00000002), ref: 00832CA3
                                                      • AdjustWindowRectEx.USER32(?,88C00000,00000000,?), ref: 00832CB1
                                                      • CreateWindowExW.USER32(?,AutoIt v3,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00832CF8
                                                      • GetClientRect.USER32(00000000,?), ref: 00832D04
                                                      • CreateWindowExW.USER32(00000000,static,00000000,5000000E,00000000,00000000,?,?,00000000,00000000,00000000), ref: 00832D40
                                                      • CreateFileW.KERNEL32(?,80000000,00000000,00000000,00000003,00000000,00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00832D62
                                                      • GetFileSize.KERNEL32(00000000,00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00832D75
                                                      • GlobalAlloc.KERNEL32(00000002,00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00832D80
                                                      • GlobalLock.KERNEL32(00000000), ref: 00832D89
                                                      • ReadFile.KERNEL32(00000000,00000000,00000000,?,00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00832D98
                                                      • GlobalUnlock.KERNEL32(00000000), ref: 00832DA1
                                                      • CloseHandle.KERNEL32(00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00832DA8
                                                      • GlobalFree.KERNEL32(00000000), ref: 00832DB3
                                                      • CreateStreamOnHGlobal.OLE32(00000000,00000001,?,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00832DC5
                                                      • OleLoadPicture.OLEAUT32(?,00000000,00000000,0084FC38,00000000), ref: 00832DDB
                                                      • GlobalFree.KERNEL32(00000000), ref: 00832DEB
                                                      • CopyImage.USER32(00000007,00000000,00000000,00000000,00002000), ref: 00832E11
                                                      • SendMessageW.USER32(00000000,00000172,00000000,00000007), ref: 00832E30
                                                      • SetWindowPos.USER32(00000000,00000000,00000000,00000000,?,?,00000020,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00832E52
                                                      • ShowWindow.USER32(00000004,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 0083303F
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Global$CreateRect$File$DeleteFreeObject$AdjustAllocClientCloseCopyDesktopDestroyHandleImageLoadLockMessagePictureReadSendShowSizeStreamUnlock
                                                      • String ID: $AutoIt v3$DISPLAY$static
                                                      • API String ID: 2211948467-2373415609
                                                      • Opcode ID: 2a1f81974851d170d5cb5ae9df6e1c74a47469bf538cd2e2d4c790d7e437515e
                                                      • Instruction ID: de225b8e1bb19c54a2fe0a37a6454395ce4765346d593baaa9a1e32bbebf032e
                                                      • Opcode Fuzzy Hash: 2a1f81974851d170d5cb5ae9df6e1c74a47469bf538cd2e2d4c790d7e437515e
                                                      • Instruction Fuzzy Hash: 64024975500218EFDB24DF68CC89EAE7BB9FF49710F048558F915EB2A1DB74A901CBA0
                                                      APIs
                                                      • SetTextColor.GDI32(?,00000000), ref: 0084712F
                                                      • GetSysColorBrush.USER32(0000000F), ref: 00847160
                                                      • GetSysColor.USER32(0000000F), ref: 0084716C
                                                      • SetBkColor.GDI32(?,000000FF), ref: 00847186
                                                      • SelectObject.GDI32(?,?), ref: 00847195
                                                      • InflateRect.USER32(?,000000FF,000000FF), ref: 008471C0
                                                      • GetSysColor.USER32(00000010), ref: 008471C8
                                                      • CreateSolidBrush.GDI32(00000000), ref: 008471CF
                                                      • FrameRect.USER32(?,?,00000000), ref: 008471DE
                                                      • DeleteObject.GDI32(00000000), ref: 008471E5
                                                      • InflateRect.USER32(?,000000FE,000000FE), ref: 00847230
                                                      • FillRect.USER32(?,?,?), ref: 00847262
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00847284
                                                        • Part of subcall function 008473E8: GetSysColor.USER32(00000012), ref: 00847421
                                                        • Part of subcall function 008473E8: SetTextColor.GDI32(?,?), ref: 00847425
                                                        • Part of subcall function 008473E8: GetSysColorBrush.USER32(0000000F), ref: 0084743B
                                                        • Part of subcall function 008473E8: GetSysColor.USER32(0000000F), ref: 00847446
                                                        • Part of subcall function 008473E8: GetSysColor.USER32(00000011), ref: 00847463
                                                        • Part of subcall function 008473E8: CreatePen.GDI32(00000000,00000001,00743C00), ref: 00847471
                                                        • Part of subcall function 008473E8: SelectObject.GDI32(?,00000000), ref: 00847482
                                                        • Part of subcall function 008473E8: SetBkColor.GDI32(?,00000000), ref: 0084748B
                                                        • Part of subcall function 008473E8: SelectObject.GDI32(?,?), ref: 00847498
                                                        • Part of subcall function 008473E8: InflateRect.USER32(?,000000FF,000000FF), ref: 008474B7
                                                        • Part of subcall function 008473E8: RoundRect.GDI32(?,?,?,?,?,00000005,00000005), ref: 008474CE
                                                        • Part of subcall function 008473E8: GetWindowLongW.USER32(00000000,000000F0), ref: 008474DB
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Color$Rect$Object$BrushInflateSelect$CreateLongTextWindow$DeleteFillFrameRoundSolid
                                                      • String ID:
                                                      • API String ID: 4124339563-0
                                                      • Opcode ID: 10ee9c17faaabc063ab7e1356e31aab080272d9ebd1674a953e482da728a5e3d
                                                      • Instruction ID: 765c7c820242e0881352ec17fa747d780afdc7684f34830b6d3cf1ea659bc5ac
                                                      • Opcode Fuzzy Hash: 10ee9c17faaabc063ab7e1356e31aab080272d9ebd1674a953e482da728a5e3d
                                                      • Instruction Fuzzy Hash: 23A1AF76009315AFDB509F64DC48E6BBBA9FF8A320F100A19F962E61E1D770E944CB91
                                                      APIs
                                                      • DestroyWindow.USER32(?,?), ref: 007C8E14
                                                      • SendMessageW.USER32(?,00001308,?,00000000), ref: 00806AC5
                                                      • ImageList_Remove.COMCTL32(?,000000FF,?), ref: 00806AFE
                                                      • MoveWindow.USER32(?,?,?,?,?,00000000), ref: 00806F43
                                                        • Part of subcall function 007C8F62: InvalidateRect.USER32(?,00000000,00000001,?,?,?,007C8BE8,?,00000000,?,?,?,?,007C8BBA,00000000,?), ref: 007C8FC5
                                                      • SendMessageW.USER32(?,00001053), ref: 00806F7F
                                                      • SendMessageW.USER32(?,00001008,000000FF,00000000), ref: 00806F96
                                                      • ImageList_Destroy.COMCTL32(00000000,?), ref: 00806FAC
                                                      • ImageList_Destroy.COMCTL32(00000000,?), ref: 00806FB7
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: DestroyImageList_MessageSend$Window$InvalidateMoveRectRemove
                                                      • String ID: 0
                                                      • API String ID: 2760611726-4108050209
                                                      • Opcode ID: d719e92253906da0e560665713dace305ba87b8fcdd02875513b461ea5d46841
                                                      • Instruction ID: 7f3433964298a26378854a6256eb689d9390172b6443fa529c02fe2b8930344c
                                                      • Opcode Fuzzy Hash: d719e92253906da0e560665713dace305ba87b8fcdd02875513b461ea5d46841
                                                      • Instruction Fuzzy Hash: 9912AC34201211DFDBA5CF28CC58BA9BBE5FF45310F54446DE495CB2A2DB35E862CB92
                                                      APIs
                                                      • DestroyWindow.USER32(00000000), ref: 0083273E
                                                      • SystemParametersInfoW.USER32(00000030,00000000,?,00000000), ref: 0083286A
                                                      • SetRect.USER32(?,00000000,00000000,0000012C,?), ref: 008328A9
                                                      • AdjustWindowRectEx.USER32(?,88C00000,00000000,00000008), ref: 008328B9
                                                      • CreateWindowExW.USER32(00000008,AutoIt v3,?,88C00000,000000FF,?,?,?,00000000,00000000,00000000), ref: 00832900
                                                      • GetClientRect.USER32(00000000,?), ref: 0083290C
                                                      • CreateWindowExW.USER32(00000000,static,?,50000000,?,00000004,00000500,-00000017,00000000,00000000,00000000), ref: 00832955
                                                      • CreateDCW.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00832964
                                                      • GetStockObject.GDI32(00000011), ref: 00832974
                                                      • SelectObject.GDI32(00000000,00000000), ref: 00832978
                                                      • GetTextFaceW.GDI32(00000000,00000040,?,?,50000000,?,00000004,00000500,-00000017,00000000,00000000,00000000,?,88C00000,000000FF,?), ref: 00832988
                                                      • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00832991
                                                      • DeleteDC.GDI32(00000000), ref: 0083299A
                                                      • CreateFontW.GDI32(00000000,00000000,00000000,00000000,00000258,00000000,00000000,00000000,00000001,00000004,00000000,00000002,00000000,?), ref: 008329C6
                                                      • SendMessageW.USER32(00000030,00000000,00000001), ref: 008329DD
                                                      • CreateWindowExW.USER32(00000200,msctls_progress32,00000000,50000001,?,-0000001D,00000104,00000014,00000000,00000000,00000000), ref: 00832A1D
                                                      • SendMessageW.USER32(00000000,00000401,00000000,00640000), ref: 00832A31
                                                      • SendMessageW.USER32(00000404,00000001,00000000), ref: 00832A42
                                                      • CreateWindowExW.USER32(00000000,static,?,50000000,?,00000041,00000500,-00000027,00000000,00000000,00000000), ref: 00832A77
                                                      • GetStockObject.GDI32(00000011), ref: 00832A82
                                                      • SendMessageW.USER32(00000030,00000000,?,50000000), ref: 00832A8D
                                                      • ShowWindow.USER32(00000004,?,50000000,?,00000004,00000500,-00000017,00000000,00000000,00000000,?,88C00000,000000FF,?,?,?), ref: 00832A97
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Create$MessageSend$ObjectRect$Stock$AdjustCapsClientDeleteDestroyDeviceFaceFontInfoParametersSelectShowSystemText
                                                      • String ID: AutoIt v3$DISPLAY$msctls_progress32$static
                                                      • API String ID: 2910397461-517079104
                                                      • Opcode ID: 42f6ab8db8f57951d15bfa8142149586d7703f832eb4af3d780732a282b74bc1
                                                      • Instruction ID: e3b379803e14e7dd318039e1bb2d1dc92b6d133347857f5bce554b731aef1237
                                                      • Opcode Fuzzy Hash: 42f6ab8db8f57951d15bfa8142149586d7703f832eb4af3d780732a282b74bc1
                                                      • Instruction Fuzzy Hash: F3B16C75A00219AFEB14DFA8CC4AFAE7BA9FB48714F008514F915E7290DB74ED40CBA0
                                                      APIs
                                                      • SetErrorMode.KERNEL32(00000001), ref: 00824AED
                                                      • GetDriveTypeW.KERNEL32(?,0084CB68,?,\\.\,0084CC08), ref: 00824BCA
                                                      • SetErrorMode.KERNEL32(00000000,0084CB68,?,\\.\,0084CC08), ref: 00824D36
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorMode$DriveType
                                                      • String ID: 1394$ATA$ATAPI$CDROM$Fibre$FileBackedVirtual$Fixed$MMC$Network$PhysicalDrive$RAID$RAMDisk$Removable$SAS$SATA$SCSI$SSA$SSD$USB$Unknown$Virtual$\\.\$iSCSI
                                                      • API String ID: 2907320926-4222207086
                                                      • Opcode ID: 57628564f60d5b832ac0b273d8f380e5ed4549c85789049cedcb031ef6817ec2
                                                      • Instruction ID: 71ac7bcd1eace9da5b23383f833b7ba123e9ec81be9bf7a821a97e2da5ada5ee
                                                      • Opcode Fuzzy Hash: 57628564f60d5b832ac0b273d8f380e5ed4549c85789049cedcb031ef6817ec2
                                                      • Instruction Fuzzy Hash: CE610630601619DBCB14DF68DA85DAC7BA0FF44304B249016F81AEB396EB3ADDD1DB61
                                                      APIs
                                                      • GetSysColor.USER32(00000012), ref: 00847421
                                                      • SetTextColor.GDI32(?,?), ref: 00847425
                                                      • GetSysColorBrush.USER32(0000000F), ref: 0084743B
                                                      • GetSysColor.USER32(0000000F), ref: 00847446
                                                      • CreateSolidBrush.GDI32(?), ref: 0084744B
                                                      • GetSysColor.USER32(00000011), ref: 00847463
                                                      • CreatePen.GDI32(00000000,00000001,00743C00), ref: 00847471
                                                      • SelectObject.GDI32(?,00000000), ref: 00847482
                                                      • SetBkColor.GDI32(?,00000000), ref: 0084748B
                                                      • SelectObject.GDI32(?,?), ref: 00847498
                                                      • InflateRect.USER32(?,000000FF,000000FF), ref: 008474B7
                                                      • RoundRect.GDI32(?,?,?,?,?,00000005,00000005), ref: 008474CE
                                                      • GetWindowLongW.USER32(00000000,000000F0), ref: 008474DB
                                                      • SendMessageW.USER32(00000000,0000000E,00000000,00000000), ref: 0084752A
                                                      • GetWindowTextW.USER32(00000000,00000000,00000001), ref: 00847554
                                                      • InflateRect.USER32(?,000000FD,000000FD), ref: 00847572
                                                      • DrawFocusRect.USER32(?,?), ref: 0084757D
                                                      • GetSysColor.USER32(00000011), ref: 0084758E
                                                      • SetTextColor.GDI32(?,00000000), ref: 00847596
                                                      • DrawTextW.USER32(?,008470F5,000000FF,?,00000000), ref: 008475A8
                                                      • SelectObject.GDI32(?,?), ref: 008475BF
                                                      • DeleteObject.GDI32(?), ref: 008475CA
                                                      • SelectObject.GDI32(?,?), ref: 008475D0
                                                      • DeleteObject.GDI32(?), ref: 008475D5
                                                      • SetTextColor.GDI32(?,?), ref: 008475DB
                                                      • SetBkColor.GDI32(?,?), ref: 008475E5
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Color$Object$Text$RectSelect$BrushCreateDeleteDrawInflateWindow$FocusLongMessageRoundSendSolid
                                                      • String ID:
                                                      • API String ID: 1996641542-0
                                                      • Opcode ID: d3cf065a283503f6623c3425484309ed5ff45f5d45476a826bfaa7abf5e2b2d0
                                                      • Instruction ID: d6224014a002ad7f0ff79dc7d5a2697c23b377326337c4872d921a66a2239604
                                                      • Opcode Fuzzy Hash: d3cf065a283503f6623c3425484309ed5ff45f5d45476a826bfaa7abf5e2b2d0
                                                      • Instruction Fuzzy Hash: 35616A76901218AFDF119FA4DC49EAEBFB9FB09320F118115F915BB2A1D7749940CF90
                                                      APIs
                                                      • GetCursorPos.USER32(?), ref: 00841128
                                                      • GetDesktopWindow.USER32 ref: 0084113D
                                                      • GetWindowRect.USER32(00000000), ref: 00841144
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00841199
                                                      • DestroyWindow.USER32(?), ref: 008411B9
                                                      • CreateWindowExW.USER32(00000008,tooltips_class32,00000000,7FFFFFFD,80000000,80000000,80000000,80000000,00000000,00000000,00000000,00000000), ref: 008411ED
                                                      • SendMessageW.USER32(00000000,00000432,00000000,00000030), ref: 0084120B
                                                      • SendMessageW.USER32(00000000,00000418,00000000,?), ref: 0084121D
                                                      • SendMessageW.USER32(00000000,00000421,?,?), ref: 00841232
                                                      • SendMessageW.USER32(00000000,0000041D,00000000,00000000), ref: 00841245
                                                      • IsWindowVisible.USER32(00000000), ref: 008412A1
                                                      • SendMessageW.USER32(00000000,00000412,00000000,D8F0D8F0), ref: 008412BC
                                                      • SendMessageW.USER32(00000000,00000411,00000001,00000030), ref: 008412D0
                                                      • GetWindowRect.USER32(00000000,?), ref: 008412E8
                                                      • MonitorFromPoint.USER32(?,?,00000002), ref: 0084130E
                                                      • GetMonitorInfoW.USER32(00000000,?), ref: 00841328
                                                      • CopyRect.USER32(?,?), ref: 0084133F
                                                      • SendMessageW.USER32(00000000,00000412,00000000), ref: 008413AA
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSendWindow$Rect$Monitor$CopyCreateCursorDesktopDestroyFromInfoLongPointVisible
                                                      • String ID: ($0$tooltips_class32
                                                      • API String ID: 698492251-4156429822
                                                      • Opcode ID: e8857675b455bb798727b58c8232ad6253c871286ebdd2fc2f01579275611c4e
                                                      • Instruction ID: e02ff8c16b9035c6c8926b66873e34a28ab9ef6b6d0ff0dfadcbe4f19a749648
                                                      • Opcode Fuzzy Hash: e8857675b455bb798727b58c8232ad6253c871286ebdd2fc2f01579275611c4e
                                                      • Instruction Fuzzy Hash: 2AB17D71604345AFDB54DF64C888BAABBE4FF89354F00891CF999DB261C771E844CB92
                                                      APIs
                                                      • SystemParametersInfoW.USER32(00000030,00000000,000000FF,00000000), ref: 007C8968
                                                      • GetSystemMetrics.USER32(00000007), ref: 007C8970
                                                      • SystemParametersInfoW.USER32(00000030,00000000,000000FF,00000000), ref: 007C899B
                                                      • GetSystemMetrics.USER32(00000008), ref: 007C89A3
                                                      • GetSystemMetrics.USER32(00000004), ref: 007C89C8
                                                      • SetRect.USER32(000000FF,00000000,00000000,000000FF,000000FF), ref: 007C89E5
                                                      • AdjustWindowRectEx.USER32(000000FF,?,00000000,?), ref: 007C89F5
                                                      • CreateWindowExW.USER32(?,AutoIt v3 GUI,?,?,?,000000FF,000000FF,000000FF,?,00000000,00000000), ref: 007C8A28
                                                      • SetWindowLongW.USER32(00000000,000000EB,00000000), ref: 007C8A3C
                                                      • GetClientRect.USER32(00000000,000000FF), ref: 007C8A5A
                                                      • GetStockObject.GDI32(00000011), ref: 007C8A76
                                                      • SendMessageW.USER32(00000000,00000030,00000000), ref: 007C8A81
                                                        • Part of subcall function 007C912D: GetCursorPos.USER32(?), ref: 007C9141
                                                        • Part of subcall function 007C912D: ScreenToClient.USER32(00000000,?), ref: 007C915E
                                                        • Part of subcall function 007C912D: GetAsyncKeyState.USER32(00000001), ref: 007C9183
                                                        • Part of subcall function 007C912D: GetAsyncKeyState.USER32(00000002), ref: 007C919D
                                                      • SetTimer.USER32(00000000,00000000,00000028,007C90FC), ref: 007C8AA8
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: System$MetricsRectWindow$AsyncClientInfoParametersState$AdjustCreateCursorLongMessageObjectScreenSendStockTimer
                                                      • String ID: AutoIt v3 GUI
                                                      • API String ID: 1458621304-248962490
                                                      • Opcode ID: 21bad5887a6951e8a429dd5ee04059b893e63cdd167a6a8df35df2c513903126
                                                      • Instruction ID: 8293708309932ccce6a3c8c1b09fbdbb734a17a459b3c0ef6f2d911d929b5645
                                                      • Opcode Fuzzy Hash: 21bad5887a6951e8a429dd5ee04059b893e63cdd167a6a8df35df2c513903126
                                                      • Instruction Fuzzy Hash: 8FB18A75A0020AAFDF54DFA8CC49BAE7BB9FB48314F11422DFA15E7290DB34A851CB51
                                                      APIs
                                                        • Part of subcall function 008110F9: GetUserObjectSecurity.USER32(?,00000004,?,00000000,?), ref: 00811114
                                                        • Part of subcall function 008110F9: GetLastError.KERNEL32(?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 00811120
                                                        • Part of subcall function 008110F9: GetProcessHeap.KERNEL32(00000008,?,?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 0081112F
                                                        • Part of subcall function 008110F9: HeapAlloc.KERNEL32(00000000,?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 00811136
                                                        • Part of subcall function 008110F9: GetUserObjectSecurity.USER32(?,00000004,00000000,?,?), ref: 0081114D
                                                      • GetSecurityDescriptorDacl.ADVAPI32(?,?,?,?), ref: 00810DF5
                                                      • GetAclInformation.ADVAPI32(?,?,0000000C,00000002), ref: 00810E29
                                                      • GetLengthSid.ADVAPI32(?), ref: 00810E40
                                                      • GetAce.ADVAPI32(?,00000000,?), ref: 00810E7A
                                                      • AddAce.ADVAPI32(?,00000002,000000FF,?,?), ref: 00810E96
                                                      • GetLengthSid.ADVAPI32(?), ref: 00810EAD
                                                      • GetProcessHeap.KERNEL32(00000008,00000008), ref: 00810EB5
                                                      • HeapAlloc.KERNEL32(00000000), ref: 00810EBC
                                                      • GetLengthSid.ADVAPI32(?,00000008,?), ref: 00810EDD
                                                      • CopySid.ADVAPI32(00000000), ref: 00810EE4
                                                      • AddAce.ADVAPI32(?,00000002,000000FF,00000000,?), ref: 00810F13
                                                      • SetSecurityDescriptorDacl.ADVAPI32(?,00000001,?,00000000), ref: 00810F35
                                                      • SetUserObjectSecurity.USER32(?,00000004,?), ref: 00810F47
                                                      • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00810F6E
                                                      • HeapFree.KERNEL32(00000000), ref: 00810F75
                                                      • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00810F7E
                                                      • HeapFree.KERNEL32(00000000), ref: 00810F85
                                                      • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00810F8E
                                                      • HeapFree.KERNEL32(00000000), ref: 00810F95
                                                      • GetProcessHeap.KERNEL32(00000000,?), ref: 00810FA1
                                                      • HeapFree.KERNEL32(00000000), ref: 00810FA8
                                                        • Part of subcall function 00811193: GetProcessHeap.KERNEL32(00000008,00810BB1,?,00000000,?,00810BB1,?), ref: 008111A1
                                                        • Part of subcall function 00811193: HeapAlloc.KERNEL32(00000000,?,00000000,?,00810BB1,?), ref: 008111A8
                                                        • Part of subcall function 00811193: InitializeSecurityDescriptor.ADVAPI32(00000000,00000001,?,00000000,?,00810BB1,?), ref: 008111B7
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Heap$Process$Security$Free$AllocDescriptorLengthObjectUser$Dacl$CopyErrorInformationInitializeLast
                                                      • String ID:
                                                      • API String ID: 4175595110-0
                                                      • Opcode ID: 337e1eb813370e709417c086be5436925f92dabeff2125b56a97aef522fb7571
                                                      • Instruction ID: 30cb46ac7d96d2665850688efda8f31fb9d5c29f5f0e013e73940b53b491ce77
                                                      • Opcode Fuzzy Hash: 337e1eb813370e709417c086be5436925f92dabeff2125b56a97aef522fb7571
                                                      • Instruction Fuzzy Hash: 9171487690120AABDB209FA5DC49BEEBBBCFF05300F044115E959E6191DB719A86CF60
                                                      APIs
                                                      • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 0083C4BD
                                                      • RegCreateKeyExW.ADVAPI32(?,?,00000000,0084CC08,00000000,?,00000000,?,?), ref: 0083C544
                                                      • RegCloseKey.ADVAPI32(00000000,00000000,00000000), ref: 0083C5A4
                                                      • _wcslen.LIBCMT ref: 0083C5F4
                                                      • _wcslen.LIBCMT ref: 0083C66F
                                                      • RegSetValueExW.ADVAPI32(00000001,?,00000000,00000001,?,?), ref: 0083C6B2
                                                      • RegSetValueExW.ADVAPI32(00000001,?,00000000,00000007,?,?), ref: 0083C7C1
                                                      • RegSetValueExW.ADVAPI32(00000001,?,00000000,0000000B,?,00000008), ref: 0083C84D
                                                      • RegCloseKey.ADVAPI32(?), ref: 0083C881
                                                      • RegCloseKey.ADVAPI32(00000000), ref: 0083C88E
                                                      • RegSetValueExW.ADVAPI32(00000001,?,00000000,00000003,00000000,00000000), ref: 0083C960
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Value$Close$_wcslen$ConnectCreateRegistry
                                                      • String ID: REG_BINARY$REG_DWORD$REG_EXPAND_SZ$REG_MULTI_SZ$REG_QWORD$REG_SZ
                                                      • API String ID: 9721498-966354055
                                                      • Opcode ID: 9189e7f91001ef01aaaef177b6a18dd99e9e437b94bc11346e59622040e2aaaf
                                                      • Instruction ID: 19cc5cd4c630f8493a62c4cc936dd02d9bf427eabe57c65402344910b4ec52a5
                                                      • Opcode Fuzzy Hash: 9189e7f91001ef01aaaef177b6a18dd99e9e437b94bc11346e59622040e2aaaf
                                                      • Instruction Fuzzy Hash: 5B123435604201DFCB14DF14C885B6AB7E5FF88714F14889DF89AAB2A2DB35ED41CB91
                                                      APIs
                                                      • CharUpperBuffW.USER32(?,?), ref: 008409C6
                                                      • _wcslen.LIBCMT ref: 00840A01
                                                      • SendMessageW.USER32(?,00001105,00000000,00000000), ref: 00840A54
                                                      • _wcslen.LIBCMT ref: 00840A8A
                                                      • _wcslen.LIBCMT ref: 00840B06
                                                      • _wcslen.LIBCMT ref: 00840B81
                                                        • Part of subcall function 007CF9F2: _wcslen.LIBCMT ref: 007CF9FD
                                                        • Part of subcall function 00812BE8: SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00812BFA
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$MessageSend$BuffCharUpper
                                                      • String ID: CHECK$COLLAPSE$EXISTS$EXPAND$GETITEMCOUNT$GETSELECTED$GETTEXT$GETTOTALCOUNT$ISCHECKED$SELECT$UNCHECK
                                                      • API String ID: 1103490817-4258414348
                                                      • Opcode ID: 11f5358184063a390b88f9988477ef12a53897d931eaff3219dbe8da420ec9e1
                                                      • Instruction ID: 55e4d8eb6a3f4d9bfca4a3d644c7bafdb43ed57f86d5de9b5f2341458b66eb6f
                                                      • Opcode Fuzzy Hash: 11f5358184063a390b88f9988477ef12a53897d931eaff3219dbe8da420ec9e1
                                                      • Instruction Fuzzy Hash: 10E17831608305DFC714DF24C491A6AB7E2FF98318B14895DF99A9B3A2D734ED49CB82
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$BuffCharUpper
                                                      • String ID: HKCC$HKCR$HKCU$HKEY_CLASSES_ROOT$HKEY_CURRENT_CONFIG$HKEY_CURRENT_USER$HKEY_LOCAL_MACHINE$HKEY_USERS$HKLM$HKU
                                                      • API String ID: 1256254125-909552448
                                                      • Opcode ID: 92ce81ddef22ef537d01200543781dbcbe4baa0aa70c0791b8ac7876f10f9fe2
                                                      • Instruction ID: 9ca86d202b339990f141ed305aa969b5fbfacdef98adffa7c22e863867014045
                                                      • Opcode Fuzzy Hash: 92ce81ddef22ef537d01200543781dbcbe4baa0aa70c0791b8ac7876f10f9fe2
                                                      • Instruction Fuzzy Hash: 7271D37260012A8BCB20DE7CCD516BA73A5FBE0764F254529F866F7284EA35DD45C3E0
                                                      APIs
                                                      • _wcslen.LIBCMT ref: 0084835A
                                                      • _wcslen.LIBCMT ref: 0084836E
                                                      • _wcslen.LIBCMT ref: 00848391
                                                      • _wcslen.LIBCMT ref: 008483B4
                                                      • LoadImageW.USER32(00000000,?,00000001,?,?,00002010), ref: 008483F2
                                                      • LoadLibraryExW.KERNEL32(?,00000000,00000032,?,?,00000001,?,?,?,0084361A,?), ref: 0084844E
                                                      • LoadImageW.USER32(?,?,00000001,?,?,00000000), ref: 00848487
                                                      • LoadImageW.USER32(00000000,?,00000001,?,?,00000000), ref: 008484CA
                                                      • LoadImageW.USER32(?,?,00000001,?,?,00000000), ref: 00848501
                                                      • FreeLibrary.KERNEL32(?), ref: 0084850D
                                                      • ExtractIconExW.SHELL32(?,00000000,00000000,00000000,00000001), ref: 0084851D
                                                      • DestroyIcon.USER32(?), ref: 0084852C
                                                      • SendMessageW.USER32(?,00000170,00000000,00000000), ref: 00848549
                                                      • SendMessageW.USER32(?,00000064,00000172,00000001), ref: 00848555
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Load$Image_wcslen$IconLibraryMessageSend$DestroyExtractFree
                                                      • String ID: .dll$.exe$.icl
                                                      • API String ID: 799131459-1154884017
                                                      • Opcode ID: 15f317537bd7df392fba25ab743e63f6cfd9526fcd82a442900d44ee0b921287
                                                      • Instruction ID: 0755e91b7ab20ab911b55309e3dc2967c8d10a9aec67aeb3ad187cb982899be9
                                                      • Opcode Fuzzy Hash: 15f317537bd7df392fba25ab743e63f6cfd9526fcd82a442900d44ee0b921287
                                                      • Instruction Fuzzy Hash: B961AF71900219FBEB14DF64CC85BBE77ACFB04B11F10454AF915E61D1DB74AA90CBA0
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: "$#OnAutoItStartRegister$#ce$#comments-end$#comments-start$#cs$#include$#include-once$#notrayicon$#pragma compile$#requireadmin$'$Bad directive syntax error$Cannot parse #include$Unterminated group of comments
                                                      • API String ID: 0-1645009161
                                                      • Opcode ID: 64599cebc13cd0d12b7f1bf469ecb68ccc8f82fb96059e56254695749a34808e
                                                      • Instruction ID: e9ae8844307ff727b0ea56be9e59a88c66f851b101d7ba9b43d039a3d3b105c7
                                                      • Opcode Fuzzy Hash: 64599cebc13cd0d12b7f1bf469ecb68ccc8f82fb96059e56254695749a34808e
                                                      • Instruction Fuzzy Hash: BB81C371A04609FBDB24AF60CC46FFE37A9FF55300F044025FA15AA296EB7CD911D6A1
                                                      APIs
                                                      • CharLowerBuffW.USER32(?,?), ref: 00823EF8
                                                      • _wcslen.LIBCMT ref: 00823F03
                                                      • _wcslen.LIBCMT ref: 00823F5A
                                                      • _wcslen.LIBCMT ref: 00823F98
                                                      • GetDriveTypeW.KERNEL32(?), ref: 00823FD6
                                                      • mciSendStringW.WINMM(?,00000000,00000000,00000000), ref: 0082401E
                                                      • mciSendStringW.WINMM(?,00000000,00000000,00000000), ref: 00824059
                                                      • mciSendStringW.WINMM(?,00000000,00000000,00000000), ref: 00824087
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: SendString_wcslen$BuffCharDriveLowerType
                                                      • String ID: type cdaudio alias cd wait$ wait$close$close cd wait$closed$open$open $set cd door
                                                      • API String ID: 1839972693-4113822522
                                                      • Opcode ID: 7a8d00cfb8414bf816bfec0c31da590350dd89975edab9292cd904dbeb019244
                                                      • Instruction ID: e5fc2d533d9e1a16cf615f241f11eb5dadedea36d0b3f5ddcfd437aafe71a33b
                                                      • Opcode Fuzzy Hash: 7a8d00cfb8414bf816bfec0c31da590350dd89975edab9292cd904dbeb019244
                                                      • Instruction Fuzzy Hash: 267101326046119FC310EF24D8909AAB7F4FF94758F10892DF9A5D7251EB38ED89CB51
                                                      APIs
                                                      • LoadIconW.USER32(00000063), ref: 00815A2E
                                                      • SendMessageW.USER32(?,00000080,00000000,00000000), ref: 00815A40
                                                      • SetWindowTextW.USER32(?,?), ref: 00815A57
                                                      • GetDlgItem.USER32(?,000003EA), ref: 00815A6C
                                                      • SetWindowTextW.USER32(00000000,?), ref: 00815A72
                                                      • GetDlgItem.USER32(?,000003E9), ref: 00815A82
                                                      • SetWindowTextW.USER32(00000000,?), ref: 00815A88
                                                      • SendDlgItemMessageW.USER32(?,000003E9,000000CC,?,00000000), ref: 00815AA9
                                                      • SendDlgItemMessageW.USER32(?,000003E9,000000C5,00000000,00000000), ref: 00815AC3
                                                      • GetWindowRect.USER32(?,?), ref: 00815ACC
                                                      • _wcslen.LIBCMT ref: 00815B33
                                                      • SetWindowTextW.USER32(?,?), ref: 00815B6F
                                                      • GetDesktopWindow.USER32 ref: 00815B75
                                                      • GetWindowRect.USER32(00000000), ref: 00815B7C
                                                      • MoveWindow.USER32(?,?,00000080,00000000,?,00000000), ref: 00815BD3
                                                      • GetClientRect.USER32(?,?), ref: 00815BE0
                                                      • PostMessageW.USER32(?,00000005,00000000,?), ref: 00815C05
                                                      • SetTimer.USER32(?,0000040A,00000000,00000000), ref: 00815C2F
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$ItemMessageText$RectSend$ClientDesktopIconLoadMovePostTimer_wcslen
                                                      • String ID:
                                                      • API String ID: 895679908-0
                                                      • Opcode ID: 1a4674c344b2de4132d1e20a0fb70f2298fdfeca4356c1a6e65832bbdb7ad9df
                                                      • Instruction ID: 18d71799e6ad14f13930a64823c0960bdc378615cc513ea4a99d52609d6a2055
                                                      • Opcode Fuzzy Hash: 1a4674c344b2de4132d1e20a0fb70f2298fdfeca4356c1a6e65832bbdb7ad9df
                                                      • Instruction Fuzzy Hash: F2716F31900B09EFDB20DFA9CE85AAEBBF9FF88714F104519E542E25A0D775E984CB50
                                                      APIs
                                                      • LoadCursorW.USER32(00000000,00007F89), ref: 0082FE27
                                                      • LoadCursorW.USER32(00000000,00007F8A), ref: 0082FE32
                                                      • LoadCursorW.USER32(00000000,00007F00), ref: 0082FE3D
                                                      • LoadCursorW.USER32(00000000,00007F03), ref: 0082FE48
                                                      • LoadCursorW.USER32(00000000,00007F8B), ref: 0082FE53
                                                      • LoadCursorW.USER32(00000000,00007F01), ref: 0082FE5E
                                                      • LoadCursorW.USER32(00000000,00007F81), ref: 0082FE69
                                                      • LoadCursorW.USER32(00000000,00007F88), ref: 0082FE74
                                                      • LoadCursorW.USER32(00000000,00007F80), ref: 0082FE7F
                                                      • LoadCursorW.USER32(00000000,00007F86), ref: 0082FE8A
                                                      • LoadCursorW.USER32(00000000,00007F83), ref: 0082FE95
                                                      • LoadCursorW.USER32(00000000,00007F85), ref: 0082FEA0
                                                      • LoadCursorW.USER32(00000000,00007F82), ref: 0082FEAB
                                                      • LoadCursorW.USER32(00000000,00007F84), ref: 0082FEB6
                                                      • LoadCursorW.USER32(00000000,00007F04), ref: 0082FEC1
                                                      • LoadCursorW.USER32(00000000,00007F02), ref: 0082FECC
                                                      • GetCursorInfo.USER32(?), ref: 0082FEDC
                                                      • GetLastError.KERNEL32 ref: 0082FF1E
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Cursor$Load$ErrorInfoLast
                                                      • String ID:
                                                      • API String ID: 3215588206-0
                                                      • Opcode ID: 2b9e669b75deb0085c38591913aa42ca1d423837d60f74dd56c4adf797f351cc
                                                      • Instruction ID: 043c68343e12d85225fac4952fd7b9c99572e6c9bdcfe6e916b6ec6e18499a0f
                                                      • Opcode Fuzzy Hash: 2b9e669b75deb0085c38591913aa42ca1d423837d60f74dd56c4adf797f351cc
                                                      • Instruction Fuzzy Hash: 314160B0D04319AADB109FBA9C8985EBFF8FF04354B50853AF119E7281DB78A941CE90
                                                      APIs
                                                      • __scrt_initialize_thread_safe_statics_platform_specific.LIBCMT ref: 007D00C6
                                                        • Part of subcall function 007D00ED: InitializeCriticalSectionAndSpinCount.KERNEL32(0088070C,00000FA0,7C8A83F1,?,?,?,?,007F23B3,000000FF), ref: 007D011C
                                                        • Part of subcall function 007D00ED: GetModuleHandleW.KERNEL32(api-ms-win-core-synch-l1-2-0.dll,?,?,?,?,007F23B3,000000FF), ref: 007D0127
                                                        • Part of subcall function 007D00ED: GetModuleHandleW.KERNEL32(kernel32.dll,?,?,?,?,007F23B3,000000FF), ref: 007D0138
                                                        • Part of subcall function 007D00ED: GetProcAddress.KERNEL32(00000000,InitializeConditionVariable), ref: 007D014E
                                                        • Part of subcall function 007D00ED: GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 007D015C
                                                        • Part of subcall function 007D00ED: GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 007D016A
                                                        • Part of subcall function 007D00ED: __crt_fast_encode_pointer.LIBVCRUNTIME ref: 007D0195
                                                        • Part of subcall function 007D00ED: __crt_fast_encode_pointer.LIBVCRUNTIME ref: 007D01A0
                                                      • ___scrt_fastfail.LIBCMT ref: 007D00E7
                                                        • Part of subcall function 007D00A3: __onexit.LIBCMT ref: 007D00A9
                                                      Strings
                                                      • WakeAllConditionVariable, xrefs: 007D0162
                                                      • InitializeConditionVariable, xrefs: 007D0148
                                                      • api-ms-win-core-synch-l1-2-0.dll, xrefs: 007D0122
                                                      • SleepConditionVariableCS, xrefs: 007D0154
                                                      • kernel32.dll, xrefs: 007D0133
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: AddressProc$HandleModule__crt_fast_encode_pointer$CountCriticalInitializeSectionSpin___scrt_fastfail__onexit__scrt_initialize_thread_safe_statics_platform_specific
                                                      • String ID: InitializeConditionVariable$SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
                                                      • API String ID: 66158676-1714406822
                                                      • Opcode ID: fb5fc22f96e3cff6248dc2f0653c1cb4342d459d20ec6aaee3f4f9b64ae1e7d8
                                                      • Instruction ID: 5c245c9f306993479fbfc1a9d13b205c66e4fc8408f9863c02985868cfb002ab
                                                      • Opcode Fuzzy Hash: fb5fc22f96e3cff6248dc2f0653c1cb4342d459d20ec6aaee3f4f9b64ae1e7d8
                                                      • Instruction Fuzzy Hash: 0D21C636A45719ABE7506BA4AC09B6E77E8FB05B51F10013FF911E3392DB7E98008AD0
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen
                                                      • String ID: CLASS$CLASSNN$INSTANCE$NAME$REGEXPCLASS$TEXT
                                                      • API String ID: 176396367-1603158881
                                                      • Opcode ID: a8137b3f5c9445f4494a8947a0c393c5cd25e3b5b73f82fe5e319595d5c56ef2
                                                      • Instruction ID: 0fedceb0302cbd488bfd94d1c42bd4f4bd7e2ba3d28bf9bbc2925dd844819846
                                                      • Opcode Fuzzy Hash: a8137b3f5c9445f4494a8947a0c393c5cd25e3b5b73f82fe5e319595d5c56ef2
                                                      • Instruction Fuzzy Hash: 63E1E432A00516EBCB189FA8C455BEDFBB9FF54710F54812AE566F7240DB30AEC98790
                                                      APIs
                                                      • CharLowerBuffW.USER32(00000000,00000000,0084CC08), ref: 00824527
                                                      • _wcslen.LIBCMT ref: 0082453B
                                                      • _wcslen.LIBCMT ref: 00824599
                                                      • _wcslen.LIBCMT ref: 008245F4
                                                      • _wcslen.LIBCMT ref: 0082463F
                                                      • _wcslen.LIBCMT ref: 008246A7
                                                        • Part of subcall function 007CF9F2: _wcslen.LIBCMT ref: 007CF9FD
                                                      • GetDriveTypeW.KERNEL32(?,00876BF0,00000061), ref: 00824743
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$BuffCharDriveLowerType
                                                      • String ID: all$cdrom$fixed$network$ramdisk$removable$unknown
                                                      • API String ID: 2055661098-1000479233
                                                      • Opcode ID: 0ce5cbb06bdf287ad6008cb94fe77b48c7af531ac44dd64504502d91b3904ddb
                                                      • Instruction ID: a922b0521a8c074d8b507d955d448b3b9ffd4edd28cf4bebd4f6f4dab113efae
                                                      • Opcode Fuzzy Hash: 0ce5cbb06bdf287ad6008cb94fe77b48c7af531ac44dd64504502d91b3904ddb
                                                      • Instruction Fuzzy Hash: A1B112316083229FC710DF28E890A6EB7E5FFA5724F50591DF5AAC7291E734D884CB62
                                                      APIs
                                                      • LoadLibraryA.KERNEL32(kernel32.dll,?,0084CC08), ref: 008340BB
                                                      • GetProcAddress.KERNEL32(00000000,GetModuleHandleExW), ref: 008340CD
                                                      • GetModuleFileNameW.KERNEL32(?,?,00000104,?,?,?,0084CC08), ref: 008340F2
                                                      • FreeLibrary.KERNEL32(00000000,?,0084CC08), ref: 0083413E
                                                      • StringFromGUID2.OLE32(?,?,00000028,?,0084CC08), ref: 008341A8
                                                      • SysFreeString.OLEAUT32(00000009), ref: 00834262
                                                      • QueryPathOfRegTypeLib.OLEAUT32(?,?,?,?,?), ref: 008342C8
                                                      • SysFreeString.OLEAUT32(?), ref: 008342F2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FreeString$Library$AddressFileFromLoadModuleNamePathProcQueryType
                                                      • String ID: GetModuleHandleExW$kernel32.dll
                                                      • API String ID: 354098117-199464113
                                                      • Opcode ID: 4ed91841bbe92b514f4a2b006addf9b61e4f5ddff4ae81c5fd90b4b6d43f5d87
                                                      • Instruction ID: 2e4ae6a385866f397824fe749e10ef71288891ceeec14c517b0fd55e8b81d250
                                                      • Opcode Fuzzy Hash: 4ed91841bbe92b514f4a2b006addf9b61e4f5ddff4ae81c5fd90b4b6d43f5d87
                                                      • Instruction Fuzzy Hash: 99122D75A00119EFDB14CF94C884EAEBBB9FF85318F248098E905EB251D731ED46CBA0
                                                      APIs
                                                      • GetMenuItemCount.USER32(00881990), ref: 007F2F8D
                                                      • GetMenuItemCount.USER32(00881990), ref: 007F303D
                                                      • GetCursorPos.USER32(?), ref: 007F3081
                                                      • SetForegroundWindow.USER32(00000000), ref: 007F308A
                                                      • TrackPopupMenuEx.USER32(00881990,00000000,?,00000000,00000000,00000000), ref: 007F309D
                                                      • PostMessageW.USER32(00000000,00000000,00000000,00000000), ref: 007F30A9
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Menu$CountItem$CursorForegroundMessagePopupPostTrackWindow
                                                      • String ID: 0
                                                      • API String ID: 36266755-4108050209
                                                      • Opcode ID: a1d8b536b3ab54fa66dde813e5c94c6697b7b97fd18966722f5b4b625007b585
                                                      • Instruction ID: ce8344698765f5ab8dfbc8e13e75fc09c1031beeb5a925525f7bfb7b9b137017
                                                      • Opcode Fuzzy Hash: a1d8b536b3ab54fa66dde813e5c94c6697b7b97fd18966722f5b4b625007b585
                                                      • Instruction Fuzzy Hash: B5712D70644209BEEB218F64CC49FEABF69FF05324F204216F615A62D1C7B9AD50DB51
                                                      APIs
                                                      • DestroyWindow.USER32(00000000,?), ref: 00846DEB
                                                        • Part of subcall function 007B6B57: _wcslen.LIBCMT ref: 007B6B6A
                                                      • CreateWindowExW.USER32(00000008,tooltips_class32,00000000,?,80000000,80000000,80000000,80000000,?,00000000,00000000,?), ref: 00846E5F
                                                      • SendMessageW.USER32(00000000,00000433,00000000,00000030), ref: 00846E81
                                                      • SendMessageW.USER32(00000000,00000432,00000000,00000030), ref: 00846E94
                                                      • DestroyWindow.USER32(?), ref: 00846EB5
                                                      • CreateWindowExW.USER32(00000008,tooltips_class32,00000000,?,80000000,80000000,80000000,80000000,?,00000000,007B0000,00000000), ref: 00846EE4
                                                      • SendMessageW.USER32(00000000,00000432,00000000,00000030), ref: 00846EFD
                                                      • GetDesktopWindow.USER32 ref: 00846F16
                                                      • GetWindowRect.USER32(00000000), ref: 00846F1D
                                                      • SendMessageW.USER32(00000000,00000418,00000000,?), ref: 00846F35
                                                      • SendMessageW.USER32(00000000,00000421,?,00000000), ref: 00846F4D
                                                        • Part of subcall function 007C9944: GetWindowLongW.USER32(?,000000EB), ref: 007C9952
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$MessageSend$CreateDestroy$DesktopLongRect_wcslen
                                                      • String ID: 0$tooltips_class32
                                                      • API String ID: 2429346358-3619404913
                                                      • Opcode ID: 7324067461c5b0abb4bd5c1edd98fc0aea3392cecda6757137138d198a0764fa
                                                      • Instruction ID: 59fbb75dd60c66bc5a3a352b1f24904d8d8c8462b208c094b4b13a2d77133f45
                                                      • Opcode Fuzzy Hash: 7324067461c5b0abb4bd5c1edd98fc0aea3392cecda6757137138d198a0764fa
                                                      • Instruction Fuzzy Hash: 9A714674104348AFDB61CF18DC48BAABBE9FB8A304F54441DF999C7261DB74A91ACB12
                                                      APIs
                                                        • Part of subcall function 007C9BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 007C9BB2
                                                      • DragQueryPoint.SHELL32(?,?), ref: 00849147
                                                        • Part of subcall function 00847674: ClientToScreen.USER32(?,?), ref: 0084769A
                                                        • Part of subcall function 00847674: GetWindowRect.USER32(?,?), ref: 00847710
                                                        • Part of subcall function 00847674: PtInRect.USER32(?,?,00848B89), ref: 00847720
                                                      • SendMessageW.USER32(?,000000B0,?,?), ref: 008491B0
                                                      • DragQueryFileW.SHELL32(?,000000FF,00000000,00000000), ref: 008491BB
                                                      • DragQueryFileW.SHELL32(?,00000000,?,00000104), ref: 008491DE
                                                      • SendMessageW.USER32(?,000000C2,00000001,?), ref: 00849225
                                                      • SendMessageW.USER32(?,000000B0,?,?), ref: 0084923E
                                                      • SendMessageW.USER32(?,000000B1,?,?), ref: 00849255
                                                      • SendMessageW.USER32(?,000000B1,?,?), ref: 00849277
                                                      • DragFinish.SHELL32(?), ref: 0084927E
                                                      • DefDlgProcW.USER32(?,00000233,?,00000000,?,?,?), ref: 00849371
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$Drag$Query$FileRectWindow$ClientFinishLongPointProcScreen
                                                      • String ID: @GUI_DRAGFILE$@GUI_DRAGID$@GUI_DROPID
                                                      • API String ID: 221274066-3440237614
                                                      • Opcode ID: 73234da629cbd78eb70dcfc152f34a4d3252928702f820598f720f00c8b5ca71
                                                      • Instruction ID: bdbbfa59c9f06e861bfc0e85633b40ae4c7a2a46a3a1954221d2fa731e0e9048
                                                      • Opcode Fuzzy Hash: 73234da629cbd78eb70dcfc152f34a4d3252928702f820598f720f00c8b5ca71
                                                      • Instruction Fuzzy Hash: 07617C71108305AFD701EF64DC89EAFBBE8FF89350F40491DF6A5922A1DB709A49CB52
                                                      APIs
                                                      • InternetConnectW.WININET(?,?,?,?,?,?,00000000,00000000), ref: 0082C4B0
                                                      • GetLastError.KERNEL32(?,00000003,?,?,?,?,?,?), ref: 0082C4C3
                                                      • SetEvent.KERNEL32(?,?,00000003,?,?,?,?,?,?), ref: 0082C4D7
                                                      • HttpOpenRequestW.WININET(00000000,00000000,?,00000000,00000000,00000000,?,00000000), ref: 0082C4F0
                                                      • InternetQueryOptionW.WININET(00000000,0000001F,?,?), ref: 0082C533
                                                      • InternetSetOptionW.WININET(00000000,0000001F,00000100,00000004), ref: 0082C549
                                                      • HttpSendRequestW.WININET(00000000,00000000,00000000,00000000,00000000), ref: 0082C554
                                                      • HttpQueryInfoW.WININET(00000000,00000005,?,?,?), ref: 0082C584
                                                      • GetLastError.KERNEL32(?,00000003,?,?,?,?,?,?), ref: 0082C5DC
                                                      • SetEvent.KERNEL32(?,?,00000003,?,?,?,?,?,?), ref: 0082C5F0
                                                      • InternetCloseHandle.WININET(00000000), ref: 0082C5FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Internet$Http$ErrorEventLastOptionQueryRequest$CloseConnectHandleInfoOpenSend
                                                      • String ID:
                                                      • API String ID: 3800310941-3916222277
                                                      • Opcode ID: f298dea88832a5e65c1a29458ebb40c6e3ff002fd90ea0b71bd33c0f4f6d804e
                                                      • Instruction ID: c652945e43e4d41af07cab9cdc426af269a9cc61754e98b66f1b20f1297b3179
                                                      • Opcode Fuzzy Hash: f298dea88832a5e65c1a29458ebb40c6e3ff002fd90ea0b71bd33c0f4f6d804e
                                                      • Instruction Fuzzy Hash: 4D5158B4500618AFEB219F64DA88ABB7BFCFF09344F00441AF945D6250DB74E984DB60
                                                      APIs
                                                      • CreateFileW.KERNEL32(?,80000000,00000000,00000000,00000003,00000000,00000000,?,00000000,?), ref: 00848592
                                                      • GetFileSize.KERNEL32(00000000,00000000), ref: 008485A2
                                                      • GlobalAlloc.KERNEL32(00000002,00000000), ref: 008485AD
                                                      • CloseHandle.KERNEL32(00000000), ref: 008485BA
                                                      • GlobalLock.KERNEL32(00000000), ref: 008485C8
                                                      • ReadFile.KERNEL32(00000000,00000000,00000000,?,00000000), ref: 008485D7
                                                      • GlobalUnlock.KERNEL32(00000000), ref: 008485E0
                                                      • CloseHandle.KERNEL32(00000000), ref: 008485E7
                                                      • CreateStreamOnHGlobal.OLE32(00000000,00000001,?), ref: 008485F8
                                                      • OleLoadPicture.OLEAUT32(?,00000000,00000000,0084FC38,?), ref: 00848611
                                                      • GlobalFree.KERNEL32(00000000), ref: 00848621
                                                      • GetObjectW.GDI32(?,00000018,000000FF), ref: 00848641
                                                      • CopyImage.USER32(?,00000000,00000000,?,00002000), ref: 00848671
                                                      • DeleteObject.GDI32(00000000), ref: 00848699
                                                      • SendMessageW.USER32(?,00000172,00000000,00000000), ref: 008486AF
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Global$File$CloseCreateHandleObject$AllocCopyDeleteFreeImageLoadLockMessagePictureReadSendSizeStreamUnlock
                                                      • String ID:
                                                      • API String ID: 3840717409-0
                                                      • Opcode ID: 6e08ea6f6a589543d07bbed1e3c1eb075cffe3d2ea23c9687765bea4b09db686
                                                      • Instruction ID: 7da7ef7db1ef7a90081bfab9c8421dccd1309b2c1413ec2e677ef774535f6a14
                                                      • Opcode Fuzzy Hash: 6e08ea6f6a589543d07bbed1e3c1eb075cffe3d2ea23c9687765bea4b09db686
                                                      • Instruction Fuzzy Hash: D8412979601208EFDB519FA5CC48EAE7BBCFF9A715F118058F909E7260DB749901DB20
                                                      APIs
                                                      • VariantInit.OLEAUT32(00000000), ref: 00821502
                                                      • VariantCopy.OLEAUT32(?,?), ref: 0082150B
                                                      • VariantClear.OLEAUT32(?), ref: 00821517
                                                      • VariantTimeToSystemTime.OLEAUT32(?,?,?), ref: 008215FB
                                                      • VarR8FromDec.OLEAUT32(?,?), ref: 00821657
                                                      • VariantInit.OLEAUT32(?), ref: 00821708
                                                      • SysFreeString.OLEAUT32(?), ref: 0082178C
                                                      • VariantClear.OLEAUT32(?), ref: 008217D8
                                                      • VariantClear.OLEAUT32(?), ref: 008217E7
                                                      • VariantInit.OLEAUT32(00000000), ref: 00821823
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Variant$ClearInit$Time$CopyFreeFromStringSystem
                                                      • String ID: %4d%02d%02d%02d%02d%02d$Default
                                                      • API String ID: 1234038744-3931177956
                                                      • Opcode ID: d27d66d1397570efa1b24bb300897270d60de9aee44f815f873a66d03a141748
                                                      • Instruction ID: 15a55445df01e1e8f38bac0e7d42cfb47e89e0e35077e7c34c292fe008193826
                                                      • Opcode Fuzzy Hash: d27d66d1397570efa1b24bb300897270d60de9aee44f815f873a66d03a141748
                                                      • Instruction Fuzzy Hash: 4CD1CF71A00229EBDF109F65E98DBB9B7B5FF55704F24809AE406EB180DB34EC81DB61
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 0083C998: CharUpperBuffW.USER32(?,?,?,?,?,?,?,0083B6AE,?,?), ref: 0083C9B5
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083C9F1
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083CA68
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083CA9E
                                                      • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 0083B6F4
                                                      • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 0083B772
                                                      • RegDeleteValueW.ADVAPI32(?,?), ref: 0083B80A
                                                      • RegCloseKey.ADVAPI32(?), ref: 0083B87E
                                                      • RegCloseKey.ADVAPI32(?), ref: 0083B89C
                                                      • LoadLibraryA.KERNEL32(advapi32.dll), ref: 0083B8F2
                                                      • GetProcAddress.KERNEL32(00000000,RegDeleteKeyExW), ref: 0083B904
                                                      • RegDeleteKeyW.ADVAPI32(?,?), ref: 0083B922
                                                      • FreeLibrary.KERNEL32(00000000), ref: 0083B983
                                                      • RegCloseKey.ADVAPI32(00000000), ref: 0083B994
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$Close$DeleteLibrary$AddressBuffCharConnectFreeLoadOpenProcRegistryUpperValue
                                                      • String ID: RegDeleteKeyExW$advapi32.dll
                                                      • API String ID: 146587525-4033151799
                                                      • Opcode ID: a54c3aa904fc45b99503c02276fc718fba4217feda7901b5a0ce10c95142ad81
                                                      • Instruction ID: 30513ba37bd3a0391948f638cf2344f51ef3e724e4cb0e6172822ab24584d91f
                                                      • Opcode Fuzzy Hash: a54c3aa904fc45b99503c02276fc718fba4217feda7901b5a0ce10c95142ad81
                                                      • Instruction Fuzzy Hash: 03C17A75208201EFD710DF14C499B6ABBE5FF84318F18849CF69A8B2A2DB35ED45CB91
                                                      APIs
                                                      • GetDC.USER32(00000000), ref: 008325D8
                                                      • CreateCompatibleBitmap.GDI32(00000000,?,?), ref: 008325E8
                                                      • CreateCompatibleDC.GDI32(?), ref: 008325F4
                                                      • SelectObject.GDI32(00000000,?), ref: 00832601
                                                      • StretchBlt.GDI32(?,00000000,00000000,?,?,?,00000006,?,?,?,00CC0020), ref: 0083266D
                                                      • GetDIBits.GDI32(?,?,00000000,00000000,00000000,00000028,00000000), ref: 008326AC
                                                      • GetDIBits.GDI32(?,?,00000000,?,00000000,00000028,00000000), ref: 008326D0
                                                      • SelectObject.GDI32(?,?), ref: 008326D8
                                                      • DeleteObject.GDI32(?), ref: 008326E1
                                                      • DeleteDC.GDI32(?), ref: 008326E8
                                                      • ReleaseDC.USER32(00000000,?), ref: 008326F3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Object$BitsCompatibleCreateDeleteSelect$BitmapReleaseStretch
                                                      • String ID: (
                                                      • API String ID: 2598888154-3887548279
                                                      • Opcode ID: aad4aa2bc5f34126b20d361abbf775c0e74afc29abdbbb3e232eb1320852a9a9
                                                      • Instruction ID: e8186a6d8b64aa710d723f887d49b43914c7514245dced594197877913144902
                                                      • Opcode Fuzzy Hash: aad4aa2bc5f34126b20d361abbf775c0e74afc29abdbbb3e232eb1320852a9a9
                                                      • Instruction Fuzzy Hash: CB61E275D01219EFCF14CFA8D885AAEBBBAFF48310F208529E955E7250E770A951CF90
                                                      APIs
                                                      • ___free_lconv_mon.LIBCMT ref: 007EDAA1
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED659
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED66B
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED67D
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED68F
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED6A1
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED6B3
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED6C5
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED6D7
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED6E9
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED6FB
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED70D
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED71F
                                                        • Part of subcall function 007ED63C: _free.LIBCMT ref: 007ED731
                                                      • _free.LIBCMT ref: 007EDA96
                                                        • Part of subcall function 007E29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000), ref: 007E29DE
                                                        • Part of subcall function 007E29C8: GetLastError.KERNEL32(00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000,00000000), ref: 007E29F0
                                                      • _free.LIBCMT ref: 007EDAB8
                                                      • _free.LIBCMT ref: 007EDACD
                                                      • _free.LIBCMT ref: 007EDAD8
                                                      • _free.LIBCMT ref: 007EDAFA
                                                      • _free.LIBCMT ref: 007EDB0D
                                                      • _free.LIBCMT ref: 007EDB1B
                                                      • _free.LIBCMT ref: 007EDB26
                                                      • _free.LIBCMT ref: 007EDB5E
                                                      • _free.LIBCMT ref: 007EDB65
                                                      • _free.LIBCMT ref: 007EDB82
                                                      • _free.LIBCMT ref: 007EDB9A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free$ErrorFreeHeapLast___free_lconv_mon
                                                      • String ID:
                                                      • API String ID: 161543041-0
                                                      • Opcode ID: b4d5840bfc30ca9022307aa1ecd3015d85341cc2b50ad69d6863f88f0ff58c12
                                                      • Instruction ID: cadab9b782c309b43f8f849fc2163c742b30370a4ad6403aaf63d0bd409cb1ad
                                                      • Opcode Fuzzy Hash: b4d5840bfc30ca9022307aa1ecd3015d85341cc2b50ad69d6863f88f0ff58c12
                                                      • Instruction Fuzzy Hash: 62315F71506288DFDB31AA76D84AB5677E8FF08310F115429E458E71A2EA3DFD418B20
                                                      APIs
                                                      • GetClassNameW.USER32(?,?,00000100), ref: 0081369C
                                                      • _wcslen.LIBCMT ref: 008136A7
                                                      • SendMessageTimeoutW.USER32(?,?,00000101,00000000,00000002,00001388,?), ref: 00813797
                                                      • GetClassNameW.USER32(?,?,00000400), ref: 0081380C
                                                      • GetDlgCtrlID.USER32(?), ref: 0081385D
                                                      • GetWindowRect.USER32(?,?), ref: 00813882
                                                      • GetParent.USER32(?), ref: 008138A0
                                                      • ScreenToClient.USER32(00000000), ref: 008138A7
                                                      • GetClassNameW.USER32(?,?,00000100), ref: 00813921
                                                      • GetWindowTextW.USER32(?,?,00000400), ref: 0081395D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClassName$Window$ClientCtrlMessageParentRectScreenSendTextTimeout_wcslen
                                                      • String ID: %s%u
                                                      • API String ID: 4010501982-679674701
                                                      • Opcode ID: a84072a21a3d19320f277c12d6fda2d5eee65f28471c589ccf53badaa9a65334
                                                      • Instruction ID: b8174ff7018e758bc9656e04ec2446cebe36a206382cb83e366266fa773738bf
                                                      • Opcode Fuzzy Hash: a84072a21a3d19320f277c12d6fda2d5eee65f28471c589ccf53badaa9a65334
                                                      • Instruction Fuzzy Hash: C291AF71204606AFD719DF24C885FEAFBACFF45350F008629F999D2190DB34EA95CBA1
                                                      APIs
                                                      • GetClassNameW.USER32(?,?,00000400), ref: 00814994
                                                      • GetWindowTextW.USER32(?,?,00000400), ref: 008149DA
                                                      • _wcslen.LIBCMT ref: 008149EB
                                                      • CharUpperBuffW.USER32(?,00000000), ref: 008149F7
                                                      • _wcsstr.LIBVCRUNTIME ref: 00814A2C
                                                      • GetClassNameW.USER32(00000018,?,00000400), ref: 00814A64
                                                      • GetWindowTextW.USER32(?,?,00000400), ref: 00814A9D
                                                      • GetClassNameW.USER32(00000018,?,00000400), ref: 00814AE6
                                                      • GetClassNameW.USER32(?,?,00000400), ref: 00814B20
                                                      • GetWindowRect.USER32(?,?), ref: 00814B8B
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClassName$Window$Text$BuffCharRectUpper_wcslen_wcsstr
                                                      • String ID: ThumbnailClass
                                                      • API String ID: 1311036022-1241985126
                                                      • Opcode ID: 4c35fe6e6f5a247bdd25830eca6ca770d27be02f05abf4b5ef2031bc679643ed
                                                      • Instruction ID: d39455dc301cfbb0c8bd6abfc5b9519509f65586d4c80559f349caab81242975
                                                      • Opcode Fuzzy Hash: 4c35fe6e6f5a247bdd25830eca6ca770d27be02f05abf4b5ef2031bc679643ed
                                                      • Instruction Fuzzy Hash: D4919C710082059BDB04CF54C985BEA7BECFF84354F04946AFD8ADA196EB34ED85CBA1
                                                      APIs
                                                      • GetMenuItemInfoW.USER32(00881990,000000FF,00000000,00000030), ref: 0081BFAC
                                                      • SetMenuItemInfoW.USER32(00881990,00000004,00000000,00000030), ref: 0081BFE1
                                                      • Sleep.KERNEL32(000001F4), ref: 0081BFF3
                                                      • GetMenuItemCount.USER32(?), ref: 0081C039
                                                      • GetMenuItemID.USER32(?,00000000), ref: 0081C056
                                                      • GetMenuItemID.USER32(?,-00000001), ref: 0081C082
                                                      • GetMenuItemID.USER32(?,?), ref: 0081C0C9
                                                      • CheckMenuRadioItem.USER32(?,00000000,?,00000000,00000400), ref: 0081C10F
                                                      • GetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 0081C124
                                                      • SetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 0081C145
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ItemMenu$Info$CheckCountRadioSleep
                                                      • String ID: 0
                                                      • API String ID: 1460738036-4108050209
                                                      • Opcode ID: 262cde61f2206fdcb93278877392d95e5379a2b20d64e962c00b82d99f00ca33
                                                      • Instruction ID: 367f7f1afec4795ccb081c6da047aa1aa522907223a79dbc9b0dd2b170bc19de
                                                      • Opcode Fuzzy Hash: 262cde61f2206fdcb93278877392d95e5379a2b20d64e962c00b82d99f00ca33
                                                      • Instruction Fuzzy Hash: 51615AB498024AABDF11CF68DC88AEEBBADFF06344F104155E811E3291CB35AD85CB61
                                                      APIs
                                                      • RegEnumKeyExW.ADVAPI32(?,00000000,?,000000FF,00000000,00000000,00000000,?,?,?,00000000), ref: 0083CC64
                                                      • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?,?,?,00000000), ref: 0083CC8D
                                                      • FreeLibrary.KERNEL32(00000000,?,?,00000000), ref: 0083CD48
                                                        • Part of subcall function 0083CC34: RegCloseKey.ADVAPI32(?,?,?,00000000), ref: 0083CCAA
                                                        • Part of subcall function 0083CC34: LoadLibraryA.KERNEL32(advapi32.dll,?,?,00000000), ref: 0083CCBD
                                                        • Part of subcall function 0083CC34: GetProcAddress.KERNEL32(00000000,RegDeleteKeyExW), ref: 0083CCCF
                                                        • Part of subcall function 0083CC34: FreeLibrary.KERNEL32(00000000,?,?,00000000), ref: 0083CD05
                                                        • Part of subcall function 0083CC34: RegEnumKeyExW.ADVAPI32(?,00000000,?,000000FF,00000000,00000000,00000000,?,?,?,00000000), ref: 0083CD28
                                                      • RegDeleteKeyW.ADVAPI32(?,?), ref: 0083CCF3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Library$EnumFree$AddressCloseDeleteLoadOpenProc
                                                      • String ID: RegDeleteKeyExW$advapi32.dll
                                                      • API String ID: 2734957052-4033151799
                                                      • Opcode ID: 236d771883ecb8f5718df8a4d68d6aeb2cc41e63fef33f405f5dd9dfdb5d0d5c
                                                      • Instruction ID: 22b0f1c9fc82eb60db71aec6aa43807974f58b74acdc6b38951f65299314fbbe
                                                      • Opcode Fuzzy Hash: 236d771883ecb8f5718df8a4d68d6aeb2cc41e63fef33f405f5dd9dfdb5d0d5c
                                                      • Instruction Fuzzy Hash: E9316C75902129BBDB609B65DC88EFFBB7CFF86754F000165B906E2240DA349A45DBE0
                                                      APIs
                                                      • GetFullPathNameW.KERNEL32(?,00007FFF,?,?), ref: 00823D40
                                                      • _wcslen.LIBCMT ref: 00823D6D
                                                      • CreateDirectoryW.KERNEL32(?,00000000), ref: 00823D9D
                                                      • CreateFileW.KERNEL32(?,40000000,00000000,00000000,00000003,02200000,00000000), ref: 00823DBE
                                                      • RemoveDirectoryW.KERNEL32(?), ref: 00823DCE
                                                      • DeviceIoControl.KERNEL32(00000000,000900A4,?,?,00000000,00000000,?,00000000), ref: 00823E55
                                                      • CloseHandle.KERNEL32(00000000), ref: 00823E60
                                                      • CloseHandle.KERNEL32(00000000), ref: 00823E6B
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CloseCreateDirectoryHandle$ControlDeviceFileFullNamePathRemove_wcslen
                                                      • String ID: :$\$\??\%s
                                                      • API String ID: 1149970189-3457252023
                                                      • Opcode ID: 5f0a3dcb3bbc06d1f1b19e66dc39d7fcc556453781af9770c3d5d753772d8af2
                                                      • Instruction ID: d7ec37b13efa586e67184ed12d2c18261143e34b1aa1e80b6813f2a05535bd97
                                                      • Opcode Fuzzy Hash: 5f0a3dcb3bbc06d1f1b19e66dc39d7fcc556453781af9770c3d5d753772d8af2
                                                      • Instruction Fuzzy Hash: 1F31A176A00219ABDB209FA0DC49FEB37BCFF89700F1041A6F509D6160E7789784CB24
                                                      APIs
                                                      • timeGetTime.WINMM ref: 0081E6B4
                                                        • Part of subcall function 007CE551: timeGetTime.WINMM(?,?,0081E6D4), ref: 007CE555
                                                      • Sleep.KERNEL32(0000000A), ref: 0081E6E1
                                                      • EnumThreadWindows.USER32(?,Function_0006E665,00000000), ref: 0081E705
                                                      • FindWindowExW.USER32(00000000,00000000,BUTTON,00000000), ref: 0081E727
                                                      • SetActiveWindow.USER32 ref: 0081E746
                                                      • SendMessageW.USER32(00000000,000000F5,00000000,00000000), ref: 0081E754
                                                      • SendMessageW.USER32(00000010,00000000,00000000), ref: 0081E773
                                                      • Sleep.KERNEL32(000000FA), ref: 0081E77E
                                                      • IsWindow.USER32 ref: 0081E78A
                                                      • EndDialog.USER32(00000000), ref: 0081E79B
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$MessageSendSleepTimetime$ActiveDialogEnumFindThreadWindows
                                                      • String ID: BUTTON
                                                      • API String ID: 1194449130-3405671355
                                                      • Opcode ID: 22c13e52455321b8ca7607fcb0225ed33e9f6ebc23cc8a47bcbf6cc2d1258a7e
                                                      • Instruction ID: 3ea98f274d18cb4169a702da365f9b00772bda9d6865b8e2c172d0039125f18f
                                                      • Opcode Fuzzy Hash: 22c13e52455321b8ca7607fcb0225ed33e9f6ebc23cc8a47bcbf6cc2d1258a7e
                                                      • Instruction Fuzzy Hash: 96218174201204AFFB50DF68EC89E653BADFF76748F144424F915C22A1EB75AC80CB25
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • mciSendStringW.WINMM(status PlayMe mode,?,00000100,00000000), ref: 0081EA5D
                                                      • mciSendStringW.WINMM(close PlayMe,00000000,00000000,00000000), ref: 0081EA73
                                                      • mciSendStringW.WINMM(?,00000000,00000000,00000000), ref: 0081EA84
                                                      • mciSendStringW.WINMM(play PlayMe wait,00000000,00000000,00000000), ref: 0081EA96
                                                      • mciSendStringW.WINMM(play PlayMe,00000000,00000000,00000000), ref: 0081EAA7
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: SendString$_wcslen
                                                      • String ID: alias PlayMe$close PlayMe$open $play PlayMe$play PlayMe wait$status PlayMe mode
                                                      • API String ID: 2420728520-1007645807
                                                      • Opcode ID: e6bf2cb8509cf0db647adb5d170499a85c357bb953b725aa0141290a9e7839cb
                                                      • Instruction ID: 466c79ea8bfe02a29b2e9699877d591223304839b2db0a0920f8bc2a81929720
                                                      • Opcode Fuzzy Hash: e6bf2cb8509cf0db647adb5d170499a85c357bb953b725aa0141290a9e7839cb
                                                      • Instruction Fuzzy Hash: 1511BF20A50229B9D720A3A1DC4AEFB6F7CFFD1B40F000429B925E20D5EA744984C5B0
                                                      APIs
                                                      • GetKeyboardState.USER32(?), ref: 0081A012
                                                      • SetKeyboardState.USER32(?), ref: 0081A07D
                                                      • GetAsyncKeyState.USER32(000000A0), ref: 0081A09D
                                                      • GetKeyState.USER32(000000A0), ref: 0081A0B4
                                                      • GetAsyncKeyState.USER32(000000A1), ref: 0081A0E3
                                                      • GetKeyState.USER32(000000A1), ref: 0081A0F4
                                                      • GetAsyncKeyState.USER32(00000011), ref: 0081A120
                                                      • GetKeyState.USER32(00000011), ref: 0081A12E
                                                      • GetAsyncKeyState.USER32(00000012), ref: 0081A157
                                                      • GetKeyState.USER32(00000012), ref: 0081A165
                                                      • GetAsyncKeyState.USER32(0000005B), ref: 0081A18E
                                                      • GetKeyState.USER32(0000005B), ref: 0081A19C
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: State$Async$Keyboard
                                                      • String ID:
                                                      • API String ID: 541375521-0
                                                      • Opcode ID: 497a251811f0993f0798f257375429fc50bc91dec2e6000eb5f95f13b0f4b153
                                                      • Instruction ID: 7bb4f49127d558ea732d146b7d421f176b9fce52cb93254030d5f38b1a29d488
                                                      • Opcode Fuzzy Hash: 497a251811f0993f0798f257375429fc50bc91dec2e6000eb5f95f13b0f4b153
                                                      • Instruction Fuzzy Hash: 4E51B96490578469FB39DB64C4117EABFBCEF12340F084599D5C2D61C2DA649ACCC763
                                                      APIs
                                                      • GetDlgItem.USER32(?,00000001), ref: 00815CE2
                                                      • GetWindowRect.USER32(00000000,?), ref: 00815CFB
                                                      • MoveWindow.USER32(?,0000000A,00000004,?,?,00000004,00000000), ref: 00815D59
                                                      • GetDlgItem.USER32(?,00000002), ref: 00815D69
                                                      • GetWindowRect.USER32(00000000,?), ref: 00815D7B
                                                      • MoveWindow.USER32(?,?,00000004,00000000,?,00000004,00000000), ref: 00815DCF
                                                      • GetDlgItem.USER32(?,000003E9), ref: 00815DDD
                                                      • GetWindowRect.USER32(00000000,?), ref: 00815DEF
                                                      • MoveWindow.USER32(?,0000000A,00000000,?,00000004,00000000), ref: 00815E31
                                                      • GetDlgItem.USER32(?,000003EA), ref: 00815E44
                                                      • MoveWindow.USER32(00000000,0000000A,0000000A,?,-00000005,00000000), ref: 00815E5A
                                                      • InvalidateRect.USER32(?,00000000,00000001), ref: 00815E67
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$ItemMoveRect$Invalidate
                                                      • String ID:
                                                      • API String ID: 3096461208-0
                                                      • Opcode ID: df0719639641416704eabca035255ab84f0f749b18f3771593a4b201515f0403
                                                      • Instruction ID: 0eb812a29dc43a0ca2b843a20ade7daea5dcc3de54e3bfe8f0eacaf70f353b37
                                                      • Opcode Fuzzy Hash: df0719639641416704eabca035255ab84f0f749b18f3771593a4b201515f0403
                                                      • Instruction Fuzzy Hash: BE510E75B01609AFDF18CF68DD89AAEBBB9FF89300F148129F915E6290D7709E40CB50
                                                      APIs
                                                        • Part of subcall function 007C8F62: InvalidateRect.USER32(?,00000000,00000001,?,?,?,007C8BE8,?,00000000,?,?,?,?,007C8BBA,00000000,?), ref: 007C8FC5
                                                      • DestroyWindow.USER32(?), ref: 007C8C81
                                                      • KillTimer.USER32(00000000,?,?,?,?,007C8BBA,00000000,?), ref: 007C8D1B
                                                      • DestroyAcceleratorTable.USER32(00000000), ref: 00806973
                                                      • ImageList_Destroy.COMCTL32(00000000,?,?,?,?,?,?,00000000,?,?,?,?,007C8BBA,00000000,?), ref: 008069A1
                                                      • ImageList_Destroy.COMCTL32(?,?,?,?,?,?,?,00000000,?,?,?,?,007C8BBA,00000000,?), ref: 008069B8
                                                      • ImageList_Destroy.COMCTL32(00000000,?,?,?,?,?,?,?,?,00000000,?,?,?,?,007C8BBA,00000000), ref: 008069D4
                                                      • DeleteObject.GDI32(00000000), ref: 008069E6
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Destroy$ImageList_$AcceleratorDeleteInvalidateKillObjectRectTableTimerWindow
                                                      • String ID:
                                                      • API String ID: 641708696-0
                                                      • Opcode ID: 59f78126dd5f9fda10547256c65b812d82d84c57e13774994908d9309df60b37
                                                      • Instruction ID: bcb263434e6f0378092e68be610bd50ffb88919ec2be2df314bcc872dc5a5daf
                                                      • Opcode Fuzzy Hash: 59f78126dd5f9fda10547256c65b812d82d84c57e13774994908d9309df60b37
                                                      • Instruction Fuzzy Hash: 3561BD31102A10DFCBB59F18DD48B25BBF5FB41312F14456CE0429BAA0CB39ACA1DFA6
                                                      APIs
                                                        • Part of subcall function 007C9944: GetWindowLongW.USER32(?,000000EB), ref: 007C9952
                                                      • GetSysColor.USER32(0000000F), ref: 007C9862
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ColorLongWindow
                                                      • String ID:
                                                      • API String ID: 259745315-0
                                                      • Opcode ID: e0d57f440088004a5f9b58c821e61bbba51619d6b014fa08e57b2500c340d0d0
                                                      • Instruction ID: 5b267e0ef934107272f051fbd7921e2ba9c0aa5ba0533bccb465315cd8ecbcb9
                                                      • Opcode Fuzzy Hash: e0d57f440088004a5f9b58c821e61bbba51619d6b014fa08e57b2500c340d0d0
                                                      • Instruction Fuzzy Hash: 79417D35505640AFDBA05F389C88FB93BA9FB47330F14465DFAA2871E2D735A942DB10
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: .}
                                                      • API String ID: 0-2266125135
                                                      • Opcode ID: f9e43d3984fe416a90cab7291451a35ea3c5704c9c9fbed47d7df97e1be1d1ea
                                                      • Instruction ID: 2be937ed8ee9abca35004e715190fcad8cb3275e3a1b5ce37c4b2fe708a5de9b
                                                      • Opcode Fuzzy Hash: f9e43d3984fe416a90cab7291451a35ea3c5704c9c9fbed47d7df97e1be1d1ea
                                                      • Instruction Fuzzy Hash: 2AC13675905289EFCF51DFAAC844BADBBB0BF0D310F044199E619AB392C7389941CF61
                                                      APIs
                                                      • GetModuleHandleW.KERNEL32(00000000,?,00000FFF,00000001,00000000,?,?,007FF7F8,00000001,0000138C,00000001,?,00000001,00000000,?,?), ref: 00819717
                                                      • LoadStringW.USER32(00000000,?,007FF7F8,00000001), ref: 00819720
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • GetModuleHandleW.KERNEL32(00000000,00000001,?,00000FFF,?,?,007FF7F8,00000001,0000138C,00000001,?,00000001,00000000,?,?,00000000), ref: 00819742
                                                      • LoadStringW.USER32(00000000,?,007FF7F8,00000001), ref: 00819745
                                                      • MessageBoxW.USER32(00000000,00000000,?,00011010), ref: 00819866
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: HandleLoadModuleString$Message_wcslen
                                                      • String ID: Error: $%s (%d) : ==> %s: %s %s$Line %d (File "%s"):$Line %d:$^ ERROR
                                                      • API String ID: 747408836-2268648507
                                                      • Opcode ID: 3cfda51a4965d2061224a6e9395e96e044ee31c20fcd36766a41474d2b0354b4
                                                      • Instruction ID: 3da26277cd922559b3b0e6bc49e58a195898d5cb668853ce9604f15d9db22a2e
                                                      • Opcode Fuzzy Hash: 3cfda51a4965d2061224a6e9395e96e044ee31c20fcd36766a41474d2b0354b4
                                                      • Instruction Fuzzy Hash: AF411371800219AACB04EBE4DD9AEEEB77CFF55340F504465F605B2192EB396F88CB61
                                                      APIs
                                                        • Part of subcall function 007B6B57: _wcslen.LIBCMT ref: 007B6B6A
                                                      • WNetAddConnection2W.MPR(?,?,?,00000000), ref: 008107A2
                                                      • RegConnectRegistryW.ADVAPI32(?,80000002,?), ref: 008107BE
                                                      • RegOpenKeyExW.ADVAPI32(?,?,00000000,00020019,?,?,SOFTWARE\Classes\), ref: 008107DA
                                                      • RegQueryValueExW.ADVAPI32(?,00000000,00000000,00000000,?,?,?,SOFTWARE\Classes\), ref: 00810804
                                                      • CLSIDFromString.OLE32(?,000001FE,?,SOFTWARE\Classes\), ref: 0081082C
                                                      • RegCloseKey.ADVAPI32(?,?,SOFTWARE\Classes\), ref: 00810837
                                                      • RegCloseKey.ADVAPI32(?,?,SOFTWARE\Classes\), ref: 0081083C
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Close$ConnectConnection2FromOpenQueryRegistryStringValue_wcslen
                                                      • String ID: SOFTWARE\Classes\$\CLSID$\IPC$
                                                      • API String ID: 323675364-22481851
                                                      • Opcode ID: 18910849108dce7a890fcdc0a30a1b75a0a00d841621e82f73c55500dd898c4d
                                                      • Instruction ID: c41c86ff60da3f0400585c3dd958b69d18e7d4d9c590baab1d0996459de86142
                                                      • Opcode Fuzzy Hash: 18910849108dce7a890fcdc0a30a1b75a0a00d841621e82f73c55500dd898c4d
                                                      • Instruction Fuzzy Hash: 0B413872C00229EBDF11EBA4DC89DEEB778FF04340B144129E915A31A1EB74AE84CF90
                                                      APIs
                                                      • MoveWindow.USER32(?,?,?,000000FF,000000FF,00000000,?,?,000000FF,000000FF,?,?,static,00000000,00000000,?), ref: 0084403B
                                                      • CreateCompatibleDC.GDI32(00000000), ref: 00844042
                                                      • SendMessageW.USER32(?,00000173,00000000,00000000), ref: 00844055
                                                      • SelectObject.GDI32(00000000,00000000), ref: 0084405D
                                                      • GetPixel.GDI32(00000000,00000000,00000000), ref: 00844068
                                                      • DeleteDC.GDI32(00000000), ref: 00844072
                                                      • GetWindowLongW.USER32(?,000000EC), ref: 0084407C
                                                      • SetLayeredWindowAttributes.USER32(?,?,00000000,00000001,?,00000000,?), ref: 00844092
                                                      • DestroyWindow.USER32(?,?,?,000000FF,000000FF,?,?,static,00000000,00000000,?,?,00000000,00000000,?), ref: 0084409E
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$AttributesCompatibleCreateDeleteDestroyLayeredLongMessageMoveObjectPixelSelectSend
                                                      • String ID: static
                                                      • API String ID: 2559357485-2160076837
                                                      • Opcode ID: 52249f73ed6b33390965c6ef48fac6664ba563ea6c1944eb5cdd2e746fec01af
                                                      • Instruction ID: 4b38fab7eda6b3b3ef4c4f8c1fe1da5bb9d282187d89e48847d2a202fdd98c2e
                                                      • Opcode Fuzzy Hash: 52249f73ed6b33390965c6ef48fac6664ba563ea6c1944eb5cdd2e746fec01af
                                                      • Instruction Fuzzy Hash: 43315A36502219ABDF619FA8DC09FDA3B6CFF0E324F110215FA59E61A0D775D820DB54
                                                      APIs
                                                      • VariantInit.OLEAUT32(?), ref: 00833C5C
                                                      • CoInitialize.OLE32(00000000), ref: 00833C8A
                                                      • CoUninitialize.OLE32 ref: 00833C94
                                                      • _wcslen.LIBCMT ref: 00833D2D
                                                      • GetRunningObjectTable.OLE32(00000000,?), ref: 00833DB1
                                                      • SetErrorMode.KERNEL32(00000001,00000029), ref: 00833ED5
                                                      • CoGetInstanceFromFile.OLE32(00000000,?,00000000,00000015,00000002,?,00000001,?), ref: 00833F0E
                                                      • CoGetObject.OLE32(?,00000000,0084FB98,?), ref: 00833F2D
                                                      • SetErrorMode.KERNEL32(00000000), ref: 00833F40
                                                      • SetErrorMode.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 00833FC4
                                                      • VariantClear.OLEAUT32(?), ref: 00833FD8
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorMode$ObjectVariant$ClearFileFromInitInitializeInstanceRunningTableUninitialize_wcslen
                                                      • String ID:
                                                      • API String ID: 429561992-0
                                                      • Opcode ID: 310b64ab8eba9e7c3be35206d2d3682098833e9b83f6811a07eb76747ff0ddf8
                                                      • Instruction ID: b0c05532ad7d56a888cb74c4010604013c8d576b1888322cbecfbabd622cf773
                                                      • Opcode Fuzzy Hash: 310b64ab8eba9e7c3be35206d2d3682098833e9b83f6811a07eb76747ff0ddf8
                                                      • Instruction Fuzzy Hash: FDC11271608205AFD700DF68C88496BBBE9FF89748F10491DF98ADB211DB71EE45CB92
                                                      APIs
                                                      • CoInitialize.OLE32(00000000), ref: 00827AF3
                                                      • SHGetSpecialFolderLocation.SHELL32(00000000,00000000,?), ref: 00827B8F
                                                      • SHGetDesktopFolder.SHELL32(?), ref: 00827BA3
                                                      • CoCreateInstance.OLE32(0084FD08,00000000,00000001,00876E6C,?), ref: 00827BEF
                                                      • SHCreateShellItem.SHELL32(00000000,00000000,?,00000003), ref: 00827C74
                                                      • CoTaskMemFree.OLE32(?,?), ref: 00827CCC
                                                      • SHBrowseForFolderW.SHELL32(?), ref: 00827D57
                                                      • SHGetPathFromIDListW.SHELL32(00000000,?), ref: 00827D7A
                                                      • CoTaskMemFree.OLE32(00000000), ref: 00827D81
                                                      • CoTaskMemFree.OLE32(00000000), ref: 00827DD6
                                                      • CoUninitialize.OLE32 ref: 00827DDC
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FolderFreeTask$Create$BrowseDesktopFromInitializeInstanceItemListLocationPathShellSpecialUninitialize
                                                      • String ID:
                                                      • API String ID: 2762341140-0
                                                      • Opcode ID: 5ed7ae773a31b71ac91a7124bae52729996454adf448d54e7855004a417f8db4
                                                      • Instruction ID: 3e07028b8b9a9bdecc91e7ec1a2ce444fd55c8370204e76c459b60ea7b55d35e
                                                      • Opcode Fuzzy Hash: 5ed7ae773a31b71ac91a7124bae52729996454adf448d54e7855004a417f8db4
                                                      • Instruction Fuzzy Hash: 2DC14B75A00119EFCB14DFA4D888DAEBBF9FF48304B1484A9E916DB261D730ED81CB90
                                                      APIs
                                                      • SendMessageW.USER32(?,00000158,000000FF,00000158), ref: 00845504
                                                      • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 00845515
                                                      • CharNextW.USER32(00000158), ref: 00845544
                                                      • SendMessageW.USER32(?,0000014B,00000000,00000000), ref: 00845585
                                                      • SendMessageW.USER32(?,00000158,000000FF,0000014E), ref: 0084559B
                                                      • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 008455AC
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$CharNext
                                                      • String ID:
                                                      • API String ID: 1350042424-0
                                                      • Opcode ID: 4cfbe50355e38dd0333251ad56e587f816efc3953ca398ac610f21f2b0026575
                                                      • Instruction ID: 8dfd5ab271c0b9f81d60831491258d3683578e9a2e4c0435a98da25e36755efd
                                                      • Opcode Fuzzy Hash: 4cfbe50355e38dd0333251ad56e587f816efc3953ca398ac610f21f2b0026575
                                                      • Instruction Fuzzy Hash: 21619F7490560CEFDF509F64CC849FE7BB9FB06728F108149F925EA292D7748A81DB60
                                                      APIs
                                                      • SafeArrayAllocDescriptorEx.OLEAUT32(0000000C,?,?), ref: 0080FAAF
                                                      • SafeArrayAllocData.OLEAUT32(?), ref: 0080FB08
                                                      • VariantInit.OLEAUT32(?), ref: 0080FB1A
                                                      • SafeArrayAccessData.OLEAUT32(?,?), ref: 0080FB3A
                                                      • VariantCopy.OLEAUT32(?,?), ref: 0080FB8D
                                                      • SafeArrayUnaccessData.OLEAUT32(?), ref: 0080FBA1
                                                      • VariantClear.OLEAUT32(?), ref: 0080FBB6
                                                      • SafeArrayDestroyData.OLEAUT32(?), ref: 0080FBC3
                                                      • SafeArrayDestroyDescriptor.OLEAUT32(?), ref: 0080FBCC
                                                      • VariantClear.OLEAUT32(?), ref: 0080FBDE
                                                      • SafeArrayDestroyDescriptor.OLEAUT32(?), ref: 0080FBE9
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ArraySafe$DataVariant$DescriptorDestroy$AllocClear$AccessCopyInitUnaccess
                                                      • String ID:
                                                      • API String ID: 2706829360-0
                                                      • Opcode ID: 73454fe1ff715a895f3dcde965c7f42dbf9aa5f6f8979d3327ca3674efa20e18
                                                      • Instruction ID: e1a3dc52d10de2c2d2ec2c207d72e608bbb37b7187ac62d38be907bfa884417d
                                                      • Opcode Fuzzy Hash: 73454fe1ff715a895f3dcde965c7f42dbf9aa5f6f8979d3327ca3674efa20e18
                                                      • Instruction Fuzzy Hash: 63415F35A01219DFCB50DF68CC689AEBBB9FF49354F00C069E945E7262CB34A945CFA4
                                                      APIs
                                                      • GetKeyboardState.USER32(?), ref: 00819CA1
                                                      • GetAsyncKeyState.USER32(000000A0), ref: 00819D22
                                                      • GetKeyState.USER32(000000A0), ref: 00819D3D
                                                      • GetAsyncKeyState.USER32(000000A1), ref: 00819D57
                                                      • GetKeyState.USER32(000000A1), ref: 00819D6C
                                                      • GetAsyncKeyState.USER32(00000011), ref: 00819D84
                                                      • GetKeyState.USER32(00000011), ref: 00819D96
                                                      • GetAsyncKeyState.USER32(00000012), ref: 00819DAE
                                                      • GetKeyState.USER32(00000012), ref: 00819DC0
                                                      • GetAsyncKeyState.USER32(0000005B), ref: 00819DD8
                                                      • GetKeyState.USER32(0000005B), ref: 00819DEA
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: State$Async$Keyboard
                                                      • String ID:
                                                      • API String ID: 541375521-0
                                                      • Opcode ID: d386c8a2160d8b4e9696b6cff84dd06ffe703883b29f3161f89eec673f896949
                                                      • Instruction ID: 4ac756ada051ed6f5c97e8d2a3ef22eafb4b79da475fa8f9ee0feff2d421e4d1
                                                      • Opcode Fuzzy Hash: d386c8a2160d8b4e9696b6cff84dd06ffe703883b29f3161f89eec673f896949
                                                      • Instruction Fuzzy Hash: E241D5346047C96DFF708664D8243F5BEE8FF12344F08805ADAC6965C2EBA499C8C7A2
                                                      APIs
                                                      • WSAStartup.WSOCK32(00000101,?), ref: 008305BC
                                                      • inet_addr.WSOCK32(?), ref: 0083061C
                                                      • gethostbyname.WSOCK32(?), ref: 00830628
                                                      • IcmpCreateFile.IPHLPAPI ref: 00830636
                                                      • IcmpSendEcho.IPHLPAPI(?,?,?,00000005,00000000,?,00000029,00000FA0), ref: 008306C6
                                                      • IcmpSendEcho.IPHLPAPI(00000000,00000000,?,00000005,00000000,?,00000029,00000FA0), ref: 008306E5
                                                      • IcmpCloseHandle.IPHLPAPI(?), ref: 008307B9
                                                      • WSACleanup.WSOCK32 ref: 008307BF
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Icmp$EchoSend$CleanupCloseCreateFileHandleStartupgethostbynameinet_addr
                                                      • String ID: Ping
                                                      • API String ID: 1028309954-2246546115
                                                      • Opcode ID: 9f1c6d2bd0c054155880706f675eafd4543a66b097340ad0e4c8344b4ee3406b
                                                      • Instruction ID: 890a9b139598f197213da5b6c45959010b813cdda79e84996e8a0abf4f09147b
                                                      • Opcode Fuzzy Hash: 9f1c6d2bd0c054155880706f675eafd4543a66b097340ad0e4c8344b4ee3406b
                                                      • Instruction Fuzzy Hash: 4A9167356082019FD320DF19C899B1ABBE4FF88318F1485A9E46ADB6A2C735EC41CFD1
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$BuffCharLower
                                                      • String ID: cdecl$none$stdcall$winapi
                                                      • API String ID: 707087890-567219261
                                                      • Opcode ID: 3e86d6065a0e9a89aea144e1dd64b6321b5c080b7a0bf494f6e246c3cd337bbe
                                                      • Instruction ID: 90a78edcf8663f084168a90b63eb67ea37c53a765f1495acc384709c61ec4946
                                                      • Opcode Fuzzy Hash: 3e86d6065a0e9a89aea144e1dd64b6321b5c080b7a0bf494f6e246c3cd337bbe
                                                      • Instruction Fuzzy Hash: 5D518031A00616DBCF14DF68C9909BEB7A5FFA4724B214229F526E7284EB35DD44C7D0
                                                      APIs
                                                      • CoInitialize.OLE32 ref: 00833774
                                                      • CoUninitialize.OLE32 ref: 0083377F
                                                      • CoCreateInstance.OLE32(?,00000000,00000017,0084FB78,?), ref: 008337D9
                                                      • IIDFromString.OLE32(?,?), ref: 0083384C
                                                      • VariantInit.OLEAUT32(?), ref: 008338E4
                                                      • VariantClear.OLEAUT32(?), ref: 00833936
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Variant$ClearCreateFromInitInitializeInstanceStringUninitialize
                                                      • String ID: Failed to create object$Invalid parameter$NULL Pointer assignment
                                                      • API String ID: 636576611-1287834457
                                                      • Opcode ID: 6b29be6bb1937d9edfe9d6fd0db38bbc51a82e99456c34b2f48f8574a17e85e7
                                                      • Instruction ID: 6cddecab79ad8871549343a6c0d4c90db660dbfc4de05ef1879aa6d1fe3bd628
                                                      • Opcode Fuzzy Hash: 6b29be6bb1937d9edfe9d6fd0db38bbc51a82e99456c34b2f48f8574a17e85e7
                                                      • Instruction Fuzzy Hash: DD6159B4608301AFD310DF54C889B6ABBE8FF89714F104929F995DB291C774EE48CB92
                                                      APIs
                                                      • LoadStringW.USER32(00000066,?,00000FFF,?), ref: 008233CF
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • LoadStringW.USER32(00000072,?,00000FFF,?), ref: 008233F0
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: LoadString$_wcslen
                                                      • String ID: Error: $"%s" (%d) : ==> %s:$"%s" (%d) : ==> %s:%s%s$Incorrect parameters to object property !$Line %d (File "%s"):$^ ERROR
                                                      • API String ID: 4099089115-3080491070
                                                      • Opcode ID: 7142b1ed3cb79f5af9ccfd49f4bf376ca0e2db01c250d55f187c9cc3b900ca74
                                                      • Instruction ID: 4306ef850d39e4e6f7aad73a72c4e0ff3be64cf4962e258a73550ceb2f8df60b
                                                      • Opcode Fuzzy Hash: 7142b1ed3cb79f5af9ccfd49f4bf376ca0e2db01c250d55f187c9cc3b900ca74
                                                      • Instruction Fuzzy Hash: FA51A371800219EADF14EBA0DD5AEEEB7B8FF14340F204065F119B2151EB396F98DB61
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$BuffCharUpper
                                                      • String ID: APPEND$EXISTS$KEYS$REMOVE
                                                      • API String ID: 1256254125-769500911
                                                      • Opcode ID: 61c0155671e3f2669a1662d988e1b2342c69914ace5b6fea8ffac2fa343b47da
                                                      • Instruction ID: cb380ac7da1442273fc2c591bf2d50ce2b3ccfaaaa10d0ee1fe13686e9b32751
                                                      • Opcode Fuzzy Hash: 61c0155671e3f2669a1662d988e1b2342c69914ace5b6fea8ffac2fa343b47da
                                                      • Instruction Fuzzy Hash: 4D41A032A001269BCB206F7988A05FEB7A9FFB17A4F244229E525D7284F735CDC1C690
                                                      APIs
                                                      • SetErrorMode.KERNEL32(00000001), ref: 008253A0
                                                      • GetDiskFreeSpaceW.KERNEL32(?,?,?,?,?,00000002,00000001), ref: 00825416
                                                      • GetLastError.KERNEL32 ref: 00825420
                                                      • SetErrorMode.KERNEL32(00000000,READY), ref: 008254A7
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Error$Mode$DiskFreeLastSpace
                                                      • String ID: INVALID$NOTREADY$READONLY$READY$UNKNOWN
                                                      • API String ID: 4194297153-14809454
                                                      • Opcode ID: c3472e5c528a082446a2894f8633d010d2591f534d079579d86b0b40f5de2b2b
                                                      • Instruction ID: 50c0c3b545787483bf7cbd5eab23f08f67032dfe1d1d9d40023dd666d82a3c06
                                                      • Opcode Fuzzy Hash: c3472e5c528a082446a2894f8633d010d2591f534d079579d86b0b40f5de2b2b
                                                      • Instruction Fuzzy Hash: 6D31D2B5A40614DFD710EF68D488BAABBB4FF05305F148066E505CB292E771DDC6CBA0
                                                      APIs
                                                      • CreateMenu.USER32 ref: 00843C79
                                                      • SetMenu.USER32(?,00000000), ref: 00843C88
                                                      • GetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 00843D10
                                                      • IsMenu.USER32(?), ref: 00843D24
                                                      • CreatePopupMenu.USER32 ref: 00843D2E
                                                      • InsertMenuItemW.USER32(?,?,00000001,00000030), ref: 00843D5B
                                                      • DrawMenuBar.USER32 ref: 00843D63
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Menu$CreateItem$DrawInfoInsertPopup
                                                      • String ID: 0$F
                                                      • API String ID: 161812096-3044882817
                                                      • Opcode ID: 71c8fd9c983dba33de3926d474a02cbfeb2434a30892d7ed57d4c19cce65d648
                                                      • Instruction ID: fd888473996f90fdc6f8c2a8df4fb9a123c2a2671e5dc7477db360518a91c825
                                                      • Opcode Fuzzy Hash: 71c8fd9c983dba33de3926d474a02cbfeb2434a30892d7ed57d4c19cce65d648
                                                      • Instruction Fuzzy Hash: BA412779A02209EFDB14DF64D884BAEBBB9FF49350F140029E956A7360D770AA11CB94
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 00813CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00813CCA
                                                      • SendMessageW.USER32(?,0000018C,000000FF,00020000), ref: 00811F64
                                                      • GetDlgCtrlID.USER32 ref: 00811F6F
                                                      • GetParent.USER32 ref: 00811F8B
                                                      • SendMessageW.USER32(00000000,?,00000111,?), ref: 00811F8E
                                                      • GetDlgCtrlID.USER32(?), ref: 00811F97
                                                      • GetParent.USER32(?), ref: 00811FAB
                                                      • SendMessageW.USER32(00000000,?,00000111,?), ref: 00811FAE
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$CtrlParent$ClassName_wcslen
                                                      • String ID: ComboBox$ListBox
                                                      • API String ID: 711023334-1403004172
                                                      • Opcode ID: baf27075a124c8aeae314851a3b7f90137e49caa0000450ad59482434fb60a6d
                                                      • Instruction ID: 4d3bc2548a1a7201342eff14d7863019603d101ce725feafc6decb823a6afb35
                                                      • Opcode Fuzzy Hash: baf27075a124c8aeae314851a3b7f90137e49caa0000450ad59482434fb60a6d
                                                      • Instruction Fuzzy Hash: F321B374A00118BBCF44AFA0CC89AEEBBB8FF16314F104119BA65A7291DB785949DB60
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 00813CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00813CCA
                                                      • SendMessageW.USER32(?,00000186,00020000,00000000), ref: 00812043
                                                      • GetDlgCtrlID.USER32 ref: 0081204E
                                                      • GetParent.USER32 ref: 0081206A
                                                      • SendMessageW.USER32(00000000,?,00000111,?), ref: 0081206D
                                                      • GetDlgCtrlID.USER32(?), ref: 00812076
                                                      • GetParent.USER32(?), ref: 0081208A
                                                      • SendMessageW.USER32(00000000,?,00000111,?), ref: 0081208D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$CtrlParent$ClassName_wcslen
                                                      • String ID: ComboBox$ListBox
                                                      • API String ID: 711023334-1403004172
                                                      • Opcode ID: f1fd6916b25bbd3dfc6e1c15c44d4a978097a7e7ba87c753da7ef50d33173ae3
                                                      • Instruction ID: 5d8af3269f41b278c269c2139d875599891a2ce7111731a0f9cbd4470951da0b
                                                      • Opcode Fuzzy Hash: f1fd6916b25bbd3dfc6e1c15c44d4a978097a7e7ba87c753da7ef50d33173ae3
                                                      • Instruction Fuzzy Hash: 9121D7B5900218BBCF14AFA0CC89EFEBBBCFF19344F104005BA65A7191D7794554DB60
                                                      APIs
                                                      • SendMessageW.USER32(?,0000101F,00000000,00000000), ref: 00843A9D
                                                      • SendMessageW.USER32(00000000,?,0000101F,00000000), ref: 00843AA0
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00843AC7
                                                      • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00843AEA
                                                      • SendMessageW.USER32(?,0000104D,00000000,00000007), ref: 00843B62
                                                      • SendMessageW.USER32(?,00001074,00000000,00000007), ref: 00843BAC
                                                      • SendMessageW.USER32(?,00001057,00000000,00000000), ref: 00843BC7
                                                      • SendMessageW.USER32(?,0000101D,00001004,00000000), ref: 00843BE2
                                                      • SendMessageW.USER32(?,0000101E,00001004,00000000), ref: 00843BF6
                                                      • SendMessageW.USER32(?,00001008,00000000,00000007), ref: 00843C13
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$LongWindow
                                                      • String ID:
                                                      • API String ID: 312131281-0
                                                      • Opcode ID: b36c6fa13d8c906a34c9adcb2f31529d9fdf4a57c04368defd06e6e247e5a32e
                                                      • Instruction ID: 06b1834d92bbfcd46ba937aa7ff566edff02a09fb7628493f902ccb89660bb0e
                                                      • Opcode Fuzzy Hash: b36c6fa13d8c906a34c9adcb2f31529d9fdf4a57c04368defd06e6e247e5a32e
                                                      • Instruction Fuzzy Hash: FB617775A00208AFDB11DFA8CC85EEEB7B8FB09714F104199FA15E72A1C774AA46DF50
                                                      APIs
                                                      • GetCurrentThreadId.KERNEL32 ref: 0081B151
                                                      • GetForegroundWindow.USER32(00000000,?,?,?,?,?,0081A1E1,?,00000001), ref: 0081B165
                                                      • GetWindowThreadProcessId.USER32(00000000), ref: 0081B16C
                                                      • AttachThreadInput.USER32(00000000,00000000,00000001,?,?,?,?,?,0081A1E1,?,00000001), ref: 0081B17B
                                                      • GetWindowThreadProcessId.USER32(?,00000000), ref: 0081B18D
                                                      • AttachThreadInput.USER32(?,00000000,00000001,?,?,?,?,?,0081A1E1,?,00000001), ref: 0081B1A6
                                                      • AttachThreadInput.USER32(00000000,00000000,00000001,?,?,?,?,?,0081A1E1,?,00000001), ref: 0081B1B8
                                                      • AttachThreadInput.USER32(00000000,00000000,?,?,?,?,?,0081A1E1,?,00000001), ref: 0081B1FD
                                                      • AttachThreadInput.USER32(?,?,00000000,?,?,?,?,?,0081A1E1,?,00000001), ref: 0081B212
                                                      • AttachThreadInput.USER32(00000000,?,00000000,?,?,?,?,?,0081A1E1,?,00000001), ref: 0081B21D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Thread$AttachInput$Window$Process$CurrentForeground
                                                      • String ID:
                                                      • API String ID: 2156557900-0
                                                      • Opcode ID: 2ce2ec533c8e28eec879781e5703d6e6d5a3ea3c9dbf2e818ce61bdc61ed408b
                                                      • Instruction ID: d7dfd91ac48a9c2f86063d4c9b0975a32e418046316e917454caa7fa5a5ea460
                                                      • Opcode Fuzzy Hash: 2ce2ec533c8e28eec879781e5703d6e6d5a3ea3c9dbf2e818ce61bdc61ed408b
                                                      • Instruction Fuzzy Hash: 3D31A9B5601604BFDB10AF68DC58FAD7BADFF62711F218009FA01DA190D7B49A84CF64
                                                      APIs
                                                      • _free.LIBCMT ref: 007E2C94
                                                        • Part of subcall function 007E29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000), ref: 007E29DE
                                                        • Part of subcall function 007E29C8: GetLastError.KERNEL32(00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000,00000000), ref: 007E29F0
                                                      • _free.LIBCMT ref: 007E2CA0
                                                      • _free.LIBCMT ref: 007E2CAB
                                                      • _free.LIBCMT ref: 007E2CB6
                                                      • _free.LIBCMT ref: 007E2CC1
                                                      • _free.LIBCMT ref: 007E2CCC
                                                      • _free.LIBCMT ref: 007E2CD7
                                                      • _free.LIBCMT ref: 007E2CE2
                                                      • _free.LIBCMT ref: 007E2CED
                                                      • _free.LIBCMT ref: 007E2CFB
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free$ErrorFreeHeapLast
                                                      • String ID:
                                                      • API String ID: 776569668-0
                                                      • Opcode ID: 6a5642ee0f4265d412e1b5124f56cbb85029b90440b2839ac6e66c2600181a35
                                                      • Instruction ID: 652d438804ef9c724adc7d609681b5c562699d3d061682c5deed2efa36a3ee23
                                                      • Opcode Fuzzy Hash: 6a5642ee0f4265d412e1b5124f56cbb85029b90440b2839ac6e66c2600181a35
                                                      • Instruction Fuzzy Hash: 9D11B376101148EFCB02EF56D846C9D3BA9BF09350F5254A0FA48AB233D639EA519F90
                                                      APIs
                                                      • GetCurrentDirectoryW.KERNEL32(00007FFF,?), ref: 00827FAD
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 00827FC1
                                                      • GetFileAttributesW.KERNEL32(?), ref: 00827FEB
                                                      • SetFileAttributesW.KERNEL32(?,00000000), ref: 00828005
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 00828017
                                                      • SetCurrentDirectoryW.KERNEL32(?), ref: 00828060
                                                      • SetCurrentDirectoryW.KERNEL32(?,?,?,?,?), ref: 008280B0
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CurrentDirectory$AttributesFile
                                                      • String ID: *.*
                                                      • API String ID: 769691225-438819550
                                                      • Opcode ID: 15159bcc5d01456358efb080b8c0ba9bf1e9d4648a77b2db2fdfa16cbe39be94
                                                      • Instruction ID: 04672a6c4cc442ebd48c1820beb9078b5bb82227de0c67f45853a57616257c1e
                                                      • Opcode Fuzzy Hash: 15159bcc5d01456358efb080b8c0ba9bf1e9d4648a77b2db2fdfa16cbe39be94
                                                      • Instruction Fuzzy Hash: 0281C076508255DBCB20EF15D844AAAB3E8FF88714F55486EF885C7250EB34ED84CBA2
                                                      APIs
                                                      • SetWindowLongW.USER32(?,000000EB), ref: 007B5C7A
                                                        • Part of subcall function 007B5D0A: GetClientRect.USER32(?,?), ref: 007B5D30
                                                        • Part of subcall function 007B5D0A: GetWindowRect.USER32(?,?), ref: 007B5D71
                                                        • Part of subcall function 007B5D0A: ScreenToClient.USER32(?,?), ref: 007B5D99
                                                      • GetDC.USER32 ref: 007F46F5
                                                      • SendMessageW.USER32(?,00000031,00000000,00000000), ref: 007F4708
                                                      • SelectObject.GDI32(00000000,00000000), ref: 007F4716
                                                      • SelectObject.GDI32(00000000,00000000), ref: 007F472B
                                                      • ReleaseDC.USER32(?,00000000), ref: 007F4733
                                                      • MoveWindow.USER32(?,?,?,?,?,?,?,00000031,00000000,00000000), ref: 007F47C4
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$ClientObjectRectSelect$LongMessageMoveReleaseScreenSend
                                                      • String ID: U
                                                      • API String ID: 4009187628-3372436214
                                                      • Opcode ID: 51bfc8d57aa8a0e34585e1a044a973e03e8b4678cecb6ab39cbe38197646279b
                                                      • Instruction ID: 02f2abdcbaf424dbf86495f22651afc7e668d08a574b6fb4baaeab3f8151260d
                                                      • Opcode Fuzzy Hash: 51bfc8d57aa8a0e34585e1a044a973e03e8b4678cecb6ab39cbe38197646279b
                                                      • Instruction Fuzzy Hash: CF71E135500209DFCF219F68C984BFB7BB6FF4A360F144269EE559A266C7398841DF60
                                                      APIs
                                                      • LoadStringW.USER32(00000066,?,00000FFF,00000000), ref: 008235E4
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • LoadStringW.USER32(00882390,?,00000FFF,?), ref: 0082360A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: LoadString$_wcslen
                                                      • String ID: Error: $"%s" (%d) : ==> %s:$"%s" (%d) : ==> %s:%s%s$Line %d (File "%s"):$^ ERROR
                                                      • API String ID: 4099089115-2391861430
                                                      • Opcode ID: 77649d3f5a9ae6c421c0708659f2871c0036acc6fc8808a0481f2c536b6c3605
                                                      • Instruction ID: a48a8a34419c28ff3563222028f5279c371d02c04acc1052cbd9fadf4c8e0768
                                                      • Opcode Fuzzy Hash: 77649d3f5a9ae6c421c0708659f2871c0036acc6fc8808a0481f2c536b6c3605
                                                      • Instruction Fuzzy Hash: FE513B71800219FACF14EBA4DC9AEEEBB78FF14300F144125F215A21A1EB395AD9DF61
                                                      APIs
                                                      • InternetOpenUrlW.WININET(?,?,00000000,00000000,?,00000000), ref: 0082C272
                                                      • HttpSendRequestW.WININET(00000000,00000000,00000000,00000000,00000000), ref: 0082C29A
                                                      • HttpQueryInfoW.WININET(00000000,00000005,?,?,?), ref: 0082C2CA
                                                      • GetLastError.KERNEL32 ref: 0082C322
                                                      • SetEvent.KERNEL32(?), ref: 0082C336
                                                      • InternetCloseHandle.WININET(00000000), ref: 0082C341
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: HttpInternet$CloseErrorEventHandleInfoLastOpenQueryRequestSend
                                                      • String ID:
                                                      • API String ID: 3113390036-3916222277
                                                      • Opcode ID: 8034bf4c8262d34c9def46e377874ab1b2221defc5f4d5c38e9963dbdc3cabf2
                                                      • Instruction ID: 3a89b5d80945110745e383bff48d8acbcafa968d149f7bdf3c7c825cde2d7352
                                                      • Opcode Fuzzy Hash: 8034bf4c8262d34c9def46e377874ab1b2221defc5f4d5c38e9963dbdc3cabf2
                                                      • Instruction Fuzzy Hash: 8F317CB5500618AFD721DFA8A888ABF7AFCFB49744B10891EA446D2200DB74DD848B61
                                                      APIs
                                                      • GetModuleHandleW.KERNEL32(00000000,?,?,00000FFF,00000000,?,007F3AAF,?,?,Bad directive syntax error,0084CC08,00000000,00000010,?,?,>>>AUTOIT SCRIPT<<<), ref: 008198BC
                                                      • LoadStringW.USER32(00000000,?,007F3AAF,?), ref: 008198C3
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • MessageBoxW.USER32(00000000,00000001,00000001,00011010), ref: 00819987
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: HandleLoadMessageModuleString_wcslen
                                                      • String ID: Error: $%s (%d) : ==> %s.: %s %s$.$Line %d (File "%s"):$Line %d:
                                                      • API String ID: 858772685-4153970271
                                                      • Opcode ID: fd1863f1c27539792cbbf70b8af028657b1bb30e9cc320a01425770b1479bf00
                                                      • Instruction ID: e1bbf06c5e3e51803466a8de2ed01a127228210785854a541e8f189fb746ae31
                                                      • Opcode Fuzzy Hash: fd1863f1c27539792cbbf70b8af028657b1bb30e9cc320a01425770b1479bf00
                                                      • Instruction Fuzzy Hash: 8B21713180021DFBCF15AF90CC1AEEE7B79FF14304F044459F629A61A2EB3996A8CB10
                                                      APIs
                                                      • GetParent.USER32 ref: 008120AB
                                                      • GetClassNameW.USER32(00000000,?,00000100), ref: 008120C0
                                                      • SendMessageW.USER32(00000000,00000111,0000702B,00000000), ref: 0081214D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClassMessageNameParentSend
                                                      • String ID: SHELLDLL_DefView$details$largeicons$list$smallicons
                                                      • API String ID: 1290815626-3381328864
                                                      • Opcode ID: 6892a3a97441899cfb81af8dcdf1fe6a99f3574a5f61602b55ff6310859656e3
                                                      • Instruction ID: cab16a55a736dad167132639c66e664090987a771a4beaa6e93f9de000dcc777
                                                      • Opcode Fuzzy Hash: 6892a3a97441899cfb81af8dcdf1fe6a99f3574a5f61602b55ff6310859656e3
                                                      • Instruction Fuzzy Hash: A7113A7A684706FAF705A220DC0ACFA33ACFF15324B20801AFB08F41D1FBA9B8915614
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free$EnvironmentVariable___from_strstr_to_strchr
                                                      • String ID:
                                                      • API String ID: 1282221369-0
                                                      • Opcode ID: 25ea1f23cc40d35af3d06cbb7fc5d54a5d6367fe4ba6e8b16529b494e14795a4
                                                      • Instruction ID: fe8dd19ac04ea27b3e7256d47128b552c4b5116a2b9408b64761d3a90be52154
                                                      • Opcode Fuzzy Hash: 25ea1f23cc40d35af3d06cbb7fc5d54a5d6367fe4ba6e8b16529b494e14795a4
                                                      • Instruction Fuzzy Hash: A4614C77906384EFDB32AFBA984966D7BA9AF0D310F04456DF940A7243D63D9D028B50
                                                      APIs
                                                      • SendMessageW.USER32(?,00002001,00000000,00000000), ref: 00845186
                                                      • ShowWindow.USER32(?,00000000), ref: 008451C7
                                                      • ShowWindow.USER32(?,00000005,?,00000000), ref: 008451CD
                                                      • SetFocus.USER32(?,?,00000005,?,00000000), ref: 008451D1
                                                        • Part of subcall function 00846FBA: DeleteObject.GDI32(00000000), ref: 00846FE6
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 0084520D
                                                      • SetWindowLongW.USER32(?,000000F0,00000000), ref: 0084521A
                                                      • InvalidateRect.USER32(?,00000000,00000001,?,00000001), ref: 0084524D
                                                      • SendMessageW.USER32(?,00001001,00000000,000000FE), ref: 00845287
                                                      • SendMessageW.USER32(?,00001026,00000000,000000FE), ref: 00845296
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$MessageSend$LongShow$DeleteFocusInvalidateObjectRect
                                                      • String ID:
                                                      • API String ID: 3210457359-0
                                                      • Opcode ID: 8f0a84837acae2106faca4cfe8207961aef71eed7c610e1a167031ebecd97dc6
                                                      • Instruction ID: 75e6c107adff9cb8b1013354cbe0fab6900dfba01e3ccc17adeb4e9faf1527d8
                                                      • Opcode Fuzzy Hash: 8f0a84837acae2106faca4cfe8207961aef71eed7c610e1a167031ebecd97dc6
                                                      • Instruction Fuzzy Hash: 6A519C30A41A1CFFEF609F28CC4AB9D7B65FB05325F148016FA25D62E2C7B5A980DB41
                                                      APIs
                                                      • LoadImageW.USER32(00000000,?,?,00000010,00000010,00000010), ref: 00806890
                                                      • ExtractIconExW.SHELL32(?,?,00000000,00000000,00000001), ref: 008068A9
                                                      • LoadImageW.USER32(00000000,?,00000001,00000000,00000000,00000050), ref: 008068B9
                                                      • ExtractIconExW.SHELL32(?,?,?,00000000,00000001), ref: 008068D1
                                                      • SendMessageW.USER32(00000000,00000080,00000000,00000000), ref: 008068F2
                                                      • DestroyIcon.USER32(00000000,?,00000010,00000010,00000010,?,?,?,?,?,007C8874,00000000,00000000,00000000,000000FF,00000000), ref: 00806901
                                                      • SendMessageW.USER32(00000000,00000080,00000001,00000000), ref: 0080691E
                                                      • DestroyIcon.USER32(00000000,?,00000010,00000010,00000010,?,?,?,?,?,007C8874,00000000,00000000,00000000,000000FF,00000000), ref: 0080692D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Icon$DestroyExtractImageLoadMessageSend
                                                      • String ID:
                                                      • API String ID: 1268354404-0
                                                      • Opcode ID: 711e42a9a0a428c5c1f22cd27fe0e912172af0326fa9979c58ea1f0744ffc6d0
                                                      • Instruction ID: 5e0b3aa9ee89f5fef339af56f5f62f411b8c91e415d8fa41549e1ec92fd17814
                                                      • Opcode Fuzzy Hash: 711e42a9a0a428c5c1f22cd27fe0e912172af0326fa9979c58ea1f0744ffc6d0
                                                      • Instruction Fuzzy Hash: DC5169B0600209EFDB608F28CC55FAA7BB9FB54750F10452CF906D62A0EB74ADA0DB50
                                                      APIs
                                                      • InternetConnectW.WININET(?,?,?,?,?,?,00000000,00000000), ref: 0082C182
                                                      • GetLastError.KERNEL32 ref: 0082C195
                                                      • SetEvent.KERNEL32(?), ref: 0082C1A9
                                                        • Part of subcall function 0082C253: InternetOpenUrlW.WININET(?,?,00000000,00000000,?,00000000), ref: 0082C272
                                                        • Part of subcall function 0082C253: GetLastError.KERNEL32 ref: 0082C322
                                                        • Part of subcall function 0082C253: SetEvent.KERNEL32(?), ref: 0082C336
                                                        • Part of subcall function 0082C253: InternetCloseHandle.WININET(00000000), ref: 0082C341
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Internet$ErrorEventLast$CloseConnectHandleOpen
                                                      • String ID:
                                                      • API String ID: 337547030-0
                                                      • Opcode ID: 1392931aa63f858ddfd21a0f10396e5e67c51c1ebaafeffc0c2336b9c4281c31
                                                      • Instruction ID: 1fad6b94899d83c3edd4abb21bee5866492c9e844697abbb36857ef45cc2a9d1
                                                      • Opcode Fuzzy Hash: 1392931aa63f858ddfd21a0f10396e5e67c51c1ebaafeffc0c2336b9c4281c31
                                                      • Instruction Fuzzy Hash: 1E317A75201A15EFDB219FA9ED44A7ABBECFF19300B00441EF956C3610DB71E894DBA0
                                                      APIs
                                                        • Part of subcall function 00813A3D: GetWindowThreadProcessId.USER32(?,00000000), ref: 00813A57
                                                        • Part of subcall function 00813A3D: GetCurrentThreadId.KERNEL32 ref: 00813A5E
                                                        • Part of subcall function 00813A3D: AttachThreadInput.USER32(00000000,?,00000000,00000000,?,008125B3), ref: 00813A65
                                                      • MapVirtualKeyW.USER32(00000025,00000000), ref: 008125BD
                                                      • PostMessageW.USER32(?,00000100,00000025,00000000), ref: 008125DB
                                                      • Sleep.KERNEL32(00000000,?,00000100,00000025,00000000), ref: 008125DF
                                                      • MapVirtualKeyW.USER32(00000025,00000000), ref: 008125E9
                                                      • PostMessageW.USER32(?,00000100,00000027,00000000), ref: 00812601
                                                      • Sleep.KERNEL32(00000000,?,00000100,00000027,00000000), ref: 00812605
                                                      • MapVirtualKeyW.USER32(00000025,00000000), ref: 0081260F
                                                      • PostMessageW.USER32(?,00000101,00000027,00000000), ref: 00812623
                                                      • Sleep.KERNEL32(00000000,?,00000101,00000027,00000000,?,00000100,00000027,00000000), ref: 00812627
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessagePostSleepThreadVirtual$AttachCurrentInputProcessWindow
                                                      • String ID:
                                                      • API String ID: 2014098862-0
                                                      • Opcode ID: 7b0984cd7907b28f8c79523810c55c46ad1e50261fb4f8d92e5bf4eee38d5269
                                                      • Instruction ID: 493717cd3c3f6c731c72a4779ce87681a4376879d2b4514bf4dd99fd7cefdc96
                                                      • Opcode Fuzzy Hash: 7b0984cd7907b28f8c79523810c55c46ad1e50261fb4f8d92e5bf4eee38d5269
                                                      • Instruction Fuzzy Hash: F001D430391624BBFB5067689C8AF993F5DFF5EB12F100005F318EE0D1C9E22484CAAA
                                                      APIs
                                                      • GetProcessHeap.KERNEL32(00000008,0000000C,?,00000000,?,00811449,?,?,00000000), ref: 0081180C
                                                      • HeapAlloc.KERNEL32(00000000,?,00811449,?,?,00000000), ref: 00811813
                                                      • GetCurrentProcess.KERNEL32(00000000,00000000,00000000,00000002,?,00811449,?,?,00000000), ref: 00811828
                                                      • GetCurrentProcess.KERNEL32(?,00000000,?,00811449,?,?,00000000), ref: 00811830
                                                      • DuplicateHandle.KERNEL32(00000000,?,00811449,?,?,00000000), ref: 00811833
                                                      • GetCurrentProcess.KERNEL32(00000000,00000000,00000000,00000002,?,00811449,?,?,00000000), ref: 00811843
                                                      • GetCurrentProcess.KERNEL32(00811449,00000000,?,00811449,?,?,00000000), ref: 0081184B
                                                      • DuplicateHandle.KERNEL32(00000000,?,00811449,?,?,00000000), ref: 0081184E
                                                      • CreateThread.KERNEL32(00000000,00000000,00811874,00000000,00000000,00000000), ref: 00811868
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process$Current$DuplicateHandleHeap$AllocCreateThread
                                                      • String ID:
                                                      • API String ID: 1957940570-0
                                                      • Opcode ID: fbffd52bbafdab8eaa33673d74369d63bcf9bc1551bdd7e9b8d689e1d5a860b4
                                                      • Instruction ID: e1545f617d9ed093512c0ae81740e26d641096b2133053a529326da6fffc7ba4
                                                      • Opcode Fuzzy Hash: fbffd52bbafdab8eaa33673d74369d63bcf9bc1551bdd7e9b8d689e1d5a860b4
                                                      • Instruction Fuzzy Hash: 9C01BF75241304BFE750AFA5DC4DF577B6CFB8AB11F004411FA05DB291C6749800CB20
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: __alldvrm$_strrchr
                                                      • String ID: }}}$}}}$}}}
                                                      • API String ID: 1036877536-3712723652
                                                      • Opcode ID: 190bec492484a18a97fe5f025dcdb3e473ceac46589bc02d4dbe4f94f5be8f6e
                                                      • Instruction ID: 2ef9044cc96cb930592fc49d528f646039efd0b3cf06b1c9450ee25cef0daeb1
                                                      • Opcode Fuzzy Hash: 190bec492484a18a97fe5f025dcdb3e473ceac46589bc02d4dbe4f94f5be8f6e
                                                      • Instruction Fuzzy Hash: 54A13672E023CA9FDB25CE1AC8957AEBBF4EF69350F1441ADE5859B282C23C9941C750
                                                      APIs
                                                        • Part of subcall function 0081D4DC: CreateToolhelp32Snapshot.KERNEL32 ref: 0081D501
                                                        • Part of subcall function 0081D4DC: Process32FirstW.KERNEL32(00000000,?), ref: 0081D50F
                                                        • Part of subcall function 0081D4DC: CloseHandle.KERNEL32(00000000), ref: 0081D5DC
                                                      • OpenProcess.KERNEL32(00000001,00000000,?), ref: 0083A16D
                                                      • GetLastError.KERNEL32 ref: 0083A180
                                                      • OpenProcess.KERNEL32(00000001,00000000,?), ref: 0083A1B3
                                                      • TerminateProcess.KERNEL32(00000000,00000000), ref: 0083A268
                                                      • GetLastError.KERNEL32(00000000), ref: 0083A273
                                                      • CloseHandle.KERNEL32(00000000), ref: 0083A2C4
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process$CloseErrorHandleLastOpen$CreateFirstProcess32SnapshotTerminateToolhelp32
                                                      • String ID: SeDebugPrivilege
                                                      • API String ID: 2533919879-2896544425
                                                      • Opcode ID: 7038e3876c954a1165d21933ded2b3adb27c224c5621ed6c7fdf5a6aeecb7a45
                                                      • Instruction ID: 4d846aa3c4f8722dd4e7e7ae55cdf7a52d50d44e2fa4fc403450ff3e8d7537ae
                                                      • Opcode Fuzzy Hash: 7038e3876c954a1165d21933ded2b3adb27c224c5621ed6c7fdf5a6aeecb7a45
                                                      • Instruction Fuzzy Hash: CA617C352042419FD724DF18C498F6ABBE5FF94318F18848CE4A68B7A2C776EC45CB92
                                                      APIs
                                                      • SendMessageW.USER32(00000000,00001036,00000010,00000010), ref: 00843925
                                                      • SendMessageW.USER32(00000000,00001036,00000000,?), ref: 0084393A
                                                      • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000000,00000013), ref: 00843954
                                                      • _wcslen.LIBCMT ref: 00843999
                                                      • SendMessageW.USER32(?,00001057,00000000,?), ref: 008439C6
                                                      • SendMessageW.USER32(?,00001061,?,0000000F), ref: 008439F4
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$Window_wcslen
                                                      • String ID: SysListView32
                                                      • API String ID: 2147712094-78025650
                                                      • Opcode ID: 516584b5e9d54be3f3f86b86adc7f4aa4f35022470e1b525bffc4f1d72398f33
                                                      • Instruction ID: c4156df9ba1ecace648a7964666f7849b244d3472a945f105902a763cd32c8c1
                                                      • Opcode Fuzzy Hash: 516584b5e9d54be3f3f86b86adc7f4aa4f35022470e1b525bffc4f1d72398f33
                                                      • Instruction Fuzzy Hash: AB419071A0021DABEF219F64CC49FEA7BA9FF18354F10052AF958E7281D7759A84CB90
                                                      APIs
                                                      • GetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 0081BCFD
                                                      • IsMenu.USER32(00000000), ref: 0081BD1D
                                                      • CreatePopupMenu.USER32 ref: 0081BD53
                                                      • GetMenuItemCount.USER32(017356B0), ref: 0081BDA4
                                                      • InsertMenuItemW.USER32(017356B0,?,00000001,00000030), ref: 0081BDCC
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Menu$Item$CountCreateInfoInsertPopup
                                                      • String ID: 0$2
                                                      • API String ID: 93392585-3793063076
                                                      • Opcode ID: d40a031f9b1c6e555172a7e0ff5f2f74f58140553fb3cbf8237a4a43a56fee47
                                                      • Instruction ID: 8c04d156cbcd072e3a0200ddd7f069fc3ae875498a4e437ceabaad1bdcd5e795
                                                      • Opcode Fuzzy Hash: d40a031f9b1c6e555172a7e0ff5f2f74f58140553fb3cbf8237a4a43a56fee47
                                                      • Instruction Fuzzy Hash: 6B519D70A002099BDB18CFA8E884BEEBBFCFF59354F144159E411D7291D7709981CB62
                                                      APIs
                                                      • _ValidateLocalCookies.LIBCMT ref: 007D2D4B
                                                      • ___except_validate_context_record.LIBVCRUNTIME ref: 007D2D53
                                                      • _ValidateLocalCookies.LIBCMT ref: 007D2DE1
                                                      • __IsNonwritableInCurrentImage.LIBCMT ref: 007D2E0C
                                                      • _ValidateLocalCookies.LIBCMT ref: 007D2E61
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                      • String ID: &H}$csm
                                                      • API String ID: 1170836740-1162412510
                                                      • Opcode ID: 8608dd33a8c4024f99c47c004bc79eaaa6db64ddcb8d5e521ab2ea8eeb40b62f
                                                      • Instruction ID: 118d084391ac4172cf6fee337a7ac770208e97e22df8aaa1233abafc2b610a67
                                                      • Opcode Fuzzy Hash: 8608dd33a8c4024f99c47c004bc79eaaa6db64ddcb8d5e521ab2ea8eeb40b62f
                                                      • Instruction Fuzzy Hash: 73418334A00209EBCF10DF68C849A9EBBB5BF55325F148156E814AB393D739EA07CBD1
                                                      APIs
                                                      • LoadIconW.USER32(00000000,00007F03), ref: 0081C913
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: IconLoad
                                                      • String ID: blank$info$question$stop$warning
                                                      • API String ID: 2457776203-404129466
                                                      • Opcode ID: 2ae56a1f4dc3212ac7c34fc668664f4e552b34b3bb489755a5fd78101758795b
                                                      • Instruction ID: 9807f232328a5f0a175306db4e8cf3e36ccffc431eef0a70c28afb61f8944fc9
                                                      • Opcode Fuzzy Hash: 2ae56a1f4dc3212ac7c34fc668664f4e552b34b3bb489755a5fd78101758795b
                                                      • Instruction Fuzzy Hash: 3F11EB316C970ABBE7055B64DCC3DEE6BACFF153A8B10402BF504EA382E7749D805268
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CleanupStartup_strcatgethostbynamegethostnameinet_ntoa
                                                      • String ID: 0.0.0.0
                                                      • API String ID: 642191829-3771769585
                                                      • Opcode ID: 544cc2d6566cefca5901b3a7a38654140cded48795a79ac0ab11eb7e5ea58679
                                                      • Instruction ID: ff9669d03a003c2c052ca9fd71111b7b7fce2ec781579f1f722ec9a6799b6424
                                                      • Opcode Fuzzy Hash: 544cc2d6566cefca5901b3a7a38654140cded48795a79ac0ab11eb7e5ea58679
                                                      • Instruction Fuzzy Hash: 82110671904208ABCB20AB74DC4AFEE77BCFF11712F00016AF445EA191EF789AC1CA60
                                                      APIs
                                                        • Part of subcall function 007C9BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 007C9BB2
                                                      • GetSystemMetrics.USER32(0000000F), ref: 00849FC7
                                                      • GetSystemMetrics.USER32(0000000F), ref: 00849FE7
                                                      • MoveWindow.USER32(00000003,?,?,?,?,00000000,?,?,?), ref: 0084A224
                                                      • SendMessageW.USER32(00000003,00000142,00000000,0000FFFF), ref: 0084A242
                                                      • SendMessageW.USER32(00000003,00000469,?,00000000), ref: 0084A263
                                                      • ShowWindow.USER32(00000003,00000000), ref: 0084A282
                                                      • InvalidateRect.USER32(?,00000000,00000001), ref: 0084A2A7
                                                      • DefDlgProcW.USER32(?,00000005,?,?), ref: 0084A2CA
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$MessageMetricsSendSystem$InvalidateLongMoveProcRectShow
                                                      • String ID:
                                                      • API String ID: 1211466189-0
                                                      • Opcode ID: cfa2600791feda47e4410ac7a1c10ca1013f761378e6637d5e52cee1dbe0d7db
                                                      • Instruction ID: 16be15c9631476998185123445340289ee5e948179f8a3665175c0a5948b9631
                                                      • Opcode Fuzzy Hash: cfa2600791feda47e4410ac7a1c10ca1013f761378e6637d5e52cee1dbe0d7db
                                                      • Instruction Fuzzy Hash: BEB1A831640229EFDF18CF68C9857AA7BB2FF48701F088169EC49DF295DB71AA40DB51
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$LocalTime
                                                      • String ID:
                                                      • API String ID: 952045576-0
                                                      • Opcode ID: 04c5372de8eb1873e21e32fb3d03d5a2fb39121935eb3c7a8b5c5d4eb1ae946c
                                                      • Instruction ID: 389caaa2f7e6486d3cd412b7bc9ee63a3f130b795d9126dbcf6affb63562bb78
                                                      • Opcode Fuzzy Hash: 04c5372de8eb1873e21e32fb3d03d5a2fb39121935eb3c7a8b5c5d4eb1ae946c
                                                      • Instruction Fuzzy Hash: 38413066C10118B6CB11ABA4CC8A9CFB7BCBF45710F508567E914E3221EB38F655C7A5
                                                      APIs
                                                      • ShowWindow.USER32(FFFFFFFF,000000FF,?,00000000,?,0080682C,00000004,00000000,00000000), ref: 007CF953
                                                      • ShowWindow.USER32(FFFFFFFF,00000006,?,00000000,?,0080682C,00000004,00000000,00000000), ref: 0080F3D1
                                                      • ShowWindow.USER32(FFFFFFFF,000000FF,?,00000000,?,0080682C,00000004,00000000,00000000), ref: 0080F454
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ShowWindow
                                                      • String ID:
                                                      • API String ID: 1268545403-0
                                                      • Opcode ID: dcc60f7b1e1924092b7bd7857935c668a3cbd63d90f476103a4c1dca10821bc4
                                                      • Instruction ID: a6453ec4c8fbcb9c122900d419848f6c3bd1d1ff11f5d25f6df2d3bbed559c43
                                                      • Opcode Fuzzy Hash: dcc60f7b1e1924092b7bd7857935c668a3cbd63d90f476103a4c1dca10821bc4
                                                      • Instruction Fuzzy Hash: 5D410B31604640BECFB99B2D8C88F6A7B97BB57314F15843DE547D6AA1C639B880CB11
                                                      APIs
                                                      • DeleteObject.GDI32(00000000), ref: 00842D1B
                                                      • GetDC.USER32(00000000), ref: 00842D23
                                                      • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00842D2E
                                                      • ReleaseDC.USER32(00000000,00000000), ref: 00842D3A
                                                      • CreateFontW.GDI32(?,00000000,00000000,00000000,?,00000000,00000000,00000000,00000001,00000004,00000000,?,00000000,?), ref: 00842D76
                                                      • SendMessageW.USER32(?,00000030,00000000,00000001), ref: 00842D87
                                                      • MoveWindow.USER32(?,?,?,?,?,00000000,?,?,00845A65,?,?,000000FF,00000000,?,000000FF,?), ref: 00842DC2
                                                      • SendMessageW.USER32(?,00000142,00000000,00000000), ref: 00842DE1
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$CapsCreateDeleteDeviceFontMoveObjectReleaseWindow
                                                      • String ID:
                                                      • API String ID: 3864802216-0
                                                      • Opcode ID: 2a8bf2ac24aa6f3025763c7968ff8f80a9c87bca0a46c706d2a769a39dc1b95d
                                                      • Instruction ID: 8d1d835def44a4b617544cbfb1d019268fe8f89c87f6e9589d48514b21c2f79b
                                                      • Opcode Fuzzy Hash: 2a8bf2ac24aa6f3025763c7968ff8f80a9c87bca0a46c706d2a769a39dc1b95d
                                                      • Instruction Fuzzy Hash: C5318B76202618BBEB618F548C8AFEB3BADFB1A715F044055FE08DA291C6759C40CBA0
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _memcmp
                                                      • String ID:
                                                      • API String ID: 2931989736-0
                                                      • Opcode ID: 9b1c59b45cdc702fe540f14d4b847d40414fb1de738304dc1a0ade642da27afd
                                                      • Instruction ID: 9933a1819148baa94e5a3b837b3675173f2c4f3209ea0b72ae873b3b79142542
                                                      • Opcode Fuzzy Hash: 9b1c59b45cdc702fe540f14d4b847d40414fb1de738304dc1a0ade642da27afd
                                                      • Instruction Fuzzy Hash: 0F21A461640A1DFBD21456219E82FFA336CFFB1398F840025FE05DA782F768ED5085E5
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: NULL Pointer assignment$Not an Object type
                                                      • API String ID: 0-572801152
                                                      • Opcode ID: da6cc382f42540bc0aafdb1968fd08e0b0682d8ec6718eb771f79730019e961a
                                                      • Instruction ID: d87ce0b7debc63f3d11874e6f96025d6e8097110919a3ee400aabcfa78b44c87
                                                      • Opcode Fuzzy Hash: da6cc382f42540bc0aafdb1968fd08e0b0682d8ec6718eb771f79730019e961a
                                                      • Instruction Fuzzy Hash: 4DD1B171A0060A9FDF14CFA8C891BAEB7B5FF88344F148469E915EB281E771DD45CB90
                                                      APIs
                                                      • GetCPInfo.KERNEL32(?,?), ref: 007F15CE
                                                      • MultiByteToWideChar.KERNEL32(?,00000009,?,?,00000000,00000000), ref: 007F1651
                                                      • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 007F16E4
                                                      • MultiByteToWideChar.KERNEL32(?,00000009,?,?,00000000,00000000), ref: 007F16FB
                                                        • Part of subcall function 007E3820: RtlAllocateHeap.NTDLL(00000000,?,00881444,?,007CFDF5,?,?,007BA976,00000010,00881440,007B13FC,?,007B13C6,?,007B1129), ref: 007E3852
                                                      • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 007F1777
                                                      • __freea.LIBCMT ref: 007F17A2
                                                      • __freea.LIBCMT ref: 007F17AE
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharMultiWide$__freea$AllocateHeapInfo
                                                      • String ID:
                                                      • API String ID: 2829977744-0
                                                      • Opcode ID: 13f48d208eae259ae6b90c8f67263c1a8beb31bb93aa49b45ec4708bf5d1ee54
                                                      • Instruction ID: f960eb553dcd8e8399dd4a0c7bd2b636a07a0008b8c6d75e4a4fc859b04bd888
                                                      • Opcode Fuzzy Hash: 13f48d208eae259ae6b90c8f67263c1a8beb31bb93aa49b45ec4708bf5d1ee54
                                                      • Instruction Fuzzy Hash: 3B91D272E0020EDADB209E75C885AFE7BB5AF49310F980659EA05E7341DB3DCC40CBA0
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Variant$ClearInit
                                                      • String ID: Incorrect Object type in FOR..IN loop$Null Object assignment in FOR..IN loop
                                                      • API String ID: 2610073882-625585964
                                                      • Opcode ID: e5224c18ddf5e37a2c2a1b718ee313e18b32647f7af8597f0df160c610ae46c7
                                                      • Instruction ID: b69d16cf29bdf4d5597274a6f0b3bd00897730b82014934abe181b4b8a4ff24a
                                                      • Opcode Fuzzy Hash: e5224c18ddf5e37a2c2a1b718ee313e18b32647f7af8597f0df160c610ae46c7
                                                      • Instruction Fuzzy Hash: 4C918071A00219ABDF20CFA4C849FAEBBB8FF86714F108559F515EB281D770A945CFA0
                                                      APIs
                                                      • SafeArrayGetVartype.OLEAUT32(00000001,?), ref: 0082125C
                                                      • SafeArrayAccessData.OLEAUT32(00000000,?), ref: 00821284
                                                      • SafeArrayUnaccessData.OLEAUT32(00000001), ref: 008212A8
                                                      • SafeArrayAccessData.OLEAUT32(00000001,?), ref: 008212D8
                                                      • SafeArrayAccessData.OLEAUT32(00000001,?), ref: 0082135F
                                                      • SafeArrayAccessData.OLEAUT32(00000001,?), ref: 008213C4
                                                      • SafeArrayAccessData.OLEAUT32(00000001,?), ref: 00821430
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ArraySafe$Data$Access$UnaccessVartype
                                                      • String ID:
                                                      • API String ID: 2550207440-0
                                                      • Opcode ID: 6baedcfb2dcb52a449c19a6e8ea6c4920b25094feb3bda93baa6ec8c69242a24
                                                      • Instruction ID: 69118c65de981e0fd4ed82761f028aa11aeaf672254865f0d3299f610373332c
                                                      • Opcode Fuzzy Hash: 6baedcfb2dcb52a449c19a6e8ea6c4920b25094feb3bda93baa6ec8c69242a24
                                                      • Instruction Fuzzy Hash: F391F875A00229DFDF10DF98E888BBEB7B6FF55314F204029E540E7291D778A981CB95
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ObjectSelect$BeginCreatePath
                                                      • String ID:
                                                      • API String ID: 3225163088-0
                                                      • Opcode ID: d1438ddd6a0d4058aef5065cda5dac30633742fd29149990b6214ed33295c35e
                                                      • Instruction ID: c39692197ff473fc4b91154692a539489bfa86297fe9fe4bd10bf905995b3f3f
                                                      • Opcode Fuzzy Hash: d1438ddd6a0d4058aef5065cda5dac30633742fd29149990b6214ed33295c35e
                                                      • Instruction Fuzzy Hash: 90912871D00219EFCB54CFA9CC88AEEBBB8FF49320F148459E515B7291D778AA51CB60
                                                      APIs
                                                      • VariantInit.OLEAUT32(?), ref: 0083396B
                                                      • CharUpperBuffW.USER32(?,?), ref: 00833A7A
                                                      • _wcslen.LIBCMT ref: 00833A8A
                                                      • VariantClear.OLEAUT32(?), ref: 00833C1F
                                                        • Part of subcall function 00820CDF: VariantInit.OLEAUT32(00000000), ref: 00820D1F
                                                        • Part of subcall function 00820CDF: VariantCopy.OLEAUT32(?,?), ref: 00820D28
                                                        • Part of subcall function 00820CDF: VariantClear.OLEAUT32(?), ref: 00820D34
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Variant$ClearInit$BuffCharCopyUpper_wcslen
                                                      • String ID: AUTOIT.ERROR$Incorrect Parameter format
                                                      • API String ID: 4137639002-1221869570
                                                      • Opcode ID: 6938be363450651657b940a4b5642adce8350f9ab51e42f3ba9d27e062ce3d29
                                                      • Instruction ID: 6daf9bec3c81aaeed986939b92f2ebdfce75beaf5306c47a06590a572782942d
                                                      • Opcode Fuzzy Hash: 6938be363450651657b940a4b5642adce8350f9ab51e42f3ba9d27e062ce3d29
                                                      • Instruction Fuzzy Hash: B19122746083059FC704EF28C48596ABBE4FF89314F14882DF89ADB351DB35EA45CB92
                                                      APIs
                                                        • Part of subcall function 0081000E: CLSIDFromProgID.OLE32(?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?,?,?,0081035E), ref: 0081002B
                                                        • Part of subcall function 0081000E: ProgIDFromCLSID.OLE32(?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?,?), ref: 00810046
                                                        • Part of subcall function 0081000E: lstrcmpiW.KERNEL32(?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?,?), ref: 00810054
                                                        • Part of subcall function 0081000E: CoTaskMemFree.OLE32(00000000,?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?), ref: 00810064
                                                      • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000002,00000003,00000000,00000000,00000000,00000001,?,?), ref: 00834C51
                                                      • _wcslen.LIBCMT ref: 00834D59
                                                      • CoCreateInstanceEx.OLE32(?,00000000,00000015,?,00000001,?), ref: 00834DCF
                                                      • CoTaskMemFree.OLE32(?), ref: 00834DDA
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FreeFromProgTask$CreateInitializeInstanceSecurity_wcslenlstrcmpi
                                                      • String ID: NULL Pointer assignment
                                                      • API String ID: 614568839-2785691316
                                                      • Opcode ID: 8197c466b9303bf2e389d5a8b1627b59e7f71fae024a986f9e8e7a4a52c2cac5
                                                      • Instruction ID: ea7331fc2bc5830537dbbc4625f427f2d856cb5394e85750d15b112607c18346
                                                      • Opcode Fuzzy Hash: 8197c466b9303bf2e389d5a8b1627b59e7f71fae024a986f9e8e7a4a52c2cac5
                                                      • Instruction Fuzzy Hash: B4910271D0021DEBDF10DFA4C895AEEB7B8FF48314F10816AE915A7251EB34AA45CFA0
                                                      APIs
                                                      • GetMenu.USER32(?), ref: 00842183
                                                      • GetMenuItemCount.USER32(00000000), ref: 008421B5
                                                      • GetMenuStringW.USER32(00000000,00000000,?,00007FFF,00000400), ref: 008421DD
                                                      • _wcslen.LIBCMT ref: 00842213
                                                      • GetMenuItemID.USER32(?,?), ref: 0084224D
                                                      • GetSubMenu.USER32(?,?), ref: 0084225B
                                                        • Part of subcall function 00813A3D: GetWindowThreadProcessId.USER32(?,00000000), ref: 00813A57
                                                        • Part of subcall function 00813A3D: GetCurrentThreadId.KERNEL32 ref: 00813A5E
                                                        • Part of subcall function 00813A3D: AttachThreadInput.USER32(00000000,?,00000000,00000000,?,008125B3), ref: 00813A65
                                                      • PostMessageW.USER32(?,00000111,00000000,00000000), ref: 008422E3
                                                        • Part of subcall function 0081E97B: Sleep.KERNEL32 ref: 0081E9F3
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Menu$Thread$Item$AttachCountCurrentInputMessagePostProcessSleepStringWindow_wcslen
                                                      • String ID:
                                                      • API String ID: 4196846111-0
                                                      • Opcode ID: 7f36c1bdbba4d988da66094ac2efb81a028b6562f2c494689bc4a50870b3f833
                                                      • Instruction ID: e6cda4d440ac6c76116605662989f93abe92810b6398822c8ff8b9d760ee3586
                                                      • Opcode Fuzzy Hash: 7f36c1bdbba4d988da66094ac2efb81a028b6562f2c494689bc4a50870b3f833
                                                      • Instruction Fuzzy Hash: 1B718D35A04219EFCB10EF68C885AAEB7B5FF88314F548499F816EB341DB74A941CB90
                                                      APIs
                                                      • IsWindow.USER32(01735570), ref: 00847F37
                                                      • IsWindowEnabled.USER32(01735570), ref: 00847F43
                                                      • SendMessageW.USER32(00000000,0000041C,00000000,00000000), ref: 0084801E
                                                      • SendMessageW.USER32(01735570,000000B0,?,?), ref: 00848051
                                                      • IsDlgButtonChecked.USER32(?,?), ref: 00848089
                                                      • GetWindowLongW.USER32(01735570,000000EC), ref: 008480AB
                                                      • SendMessageW.USER32(?,000000A1,00000002,00000000), ref: 008480C3
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSendWindow$ButtonCheckedEnabledLong
                                                      • String ID:
                                                      • API String ID: 4072528602-0
                                                      • Opcode ID: 315589bd96fecb5f8b0bed77a461c0223da951321f09e8f23d330467babf746d
                                                      • Instruction ID: 36cca413520b2b0f99ddd7e6c35bfe123b34de5d60a9fdc0c7cbeda76e369020
                                                      • Opcode Fuzzy Hash: 315589bd96fecb5f8b0bed77a461c0223da951321f09e8f23d330467babf746d
                                                      • Instruction Fuzzy Hash: 65717B34609648EFEF219F64CC84FAABBB9FF1A300F14445AE955D7261CB31AC49DB20
                                                      APIs
                                                      • GetParent.USER32(?), ref: 0081AEF9
                                                      • GetKeyboardState.USER32(?), ref: 0081AF0E
                                                      • SetKeyboardState.USER32(?), ref: 0081AF6F
                                                      • PostMessageW.USER32(?,00000101,00000010,?), ref: 0081AF9D
                                                      • PostMessageW.USER32(?,00000101,00000011,?), ref: 0081AFBC
                                                      • PostMessageW.USER32(?,00000101,00000012,?), ref: 0081AFFD
                                                      • PostMessageW.USER32(?,00000101,0000005B,?), ref: 0081B020
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessagePost$KeyboardState$Parent
                                                      • String ID:
                                                      • API String ID: 87235514-0
                                                      • Opcode ID: 7c2ff83f1b8bb5f65496e3c68cdd68329b750ec523ddf89554eb63cc92962717
                                                      • Instruction ID: daaef3bf9fbe884a05e94011962fe118d78b88c63b485cab95f6d9b616464a8f
                                                      • Opcode Fuzzy Hash: 7c2ff83f1b8bb5f65496e3c68cdd68329b750ec523ddf89554eb63cc92962717
                                                      • Instruction Fuzzy Hash: 0951D3A06056D53DFB364234C845BFA7EADBF06304F088489F1D9D54C2D798A8C9D761
                                                      APIs
                                                      • GetParent.USER32(00000000), ref: 0081AD19
                                                      • GetKeyboardState.USER32(?), ref: 0081AD2E
                                                      • SetKeyboardState.USER32(?), ref: 0081AD8F
                                                      • PostMessageW.USER32(00000000,00000100,00000010,?), ref: 0081ADBB
                                                      • PostMessageW.USER32(00000000,00000100,00000011,?), ref: 0081ADD8
                                                      • PostMessageW.USER32(00000000,00000100,00000012,?), ref: 0081AE17
                                                      • PostMessageW.USER32(00000000,00000100,0000005B,?), ref: 0081AE38
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessagePost$KeyboardState$Parent
                                                      • String ID:
                                                      • API String ID: 87235514-0
                                                      • Opcode ID: 66876ec56975f88d7a196934986750a947e2f527e023f05b9cf515eba92e285a
                                                      • Instruction ID: 64e42eea90bc66f171473a7e24b011b4b9dee5810eefa3c1de4163f44fdc658d
                                                      • Opcode Fuzzy Hash: 66876ec56975f88d7a196934986750a947e2f527e023f05b9cf515eba92e285a
                                                      • Instruction Fuzzy Hash: 2C51C5A15057D53DFB3A8264CC95BFA7E9CBF46304F088488E1D9C58C2D294ACD8D752
                                                      APIs
                                                      • GetConsoleCP.KERNEL32(007F3CD6,?,?,?,?,?,?,?,?,007E5BA3,?,?,007F3CD6,?,?), ref: 007E5470
                                                      • __fassign.LIBCMT ref: 007E54EB
                                                      • __fassign.LIBCMT ref: 007E5506
                                                      • WideCharToMultiByte.KERNEL32(?,00000000,?,00000001,007F3CD6,00000005,00000000,00000000), ref: 007E552C
                                                      • WriteFile.KERNEL32(?,007F3CD6,00000000,007E5BA3,00000000,?,?,?,?,?,?,?,?,?,007E5BA3,?), ref: 007E554B
                                                      • WriteFile.KERNEL32(?,?,00000001,007E5BA3,00000000,?,?,?,?,?,?,?,?,?,007E5BA3,?), ref: 007E5584
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FileWrite__fassign$ByteCharConsoleMultiWide
                                                      • String ID:
                                                      • API String ID: 1324828854-0
                                                      • Opcode ID: 68a802c488cecacd979064e183d00ecd0cc90d5eb5bf0403831b2718933f3c8c
                                                      • Instruction ID: dacc7c6475ec322bf08e78eeec23da1f53e2c8c9574a45080d5e5ac792db6e95
                                                      • Opcode Fuzzy Hash: 68a802c488cecacd979064e183d00ecd0cc90d5eb5bf0403831b2718933f3c8c
                                                      • Instruction Fuzzy Hash: DD51F370A016889FDB10CFA9D845AEEBBFAFF0D304F14401AF555E7292E734AA50CB60
                                                      APIs
                                                        • Part of subcall function 0083304E: inet_addr.WSOCK32(?), ref: 0083307A
                                                        • Part of subcall function 0083304E: _wcslen.LIBCMT ref: 0083309B
                                                      • socket.WSOCK32(00000002,00000001,00000006), ref: 00831112
                                                      • WSAGetLastError.WSOCK32 ref: 00831121
                                                      • WSAGetLastError.WSOCK32 ref: 008311C9
                                                      • closesocket.WSOCK32(00000000), ref: 008311F9
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorLast$_wcslenclosesocketinet_addrsocket
                                                      • String ID:
                                                      • API String ID: 2675159561-0
                                                      • Opcode ID: aa80fb04d662afc9f981e1a1107a232f5b826f3ea205324764ac09d89f51b4fd
                                                      • Instruction ID: 8fc72b3eb03d402af1503b91e775391a531c19a66e874b557d7537fc45723185
                                                      • Opcode Fuzzy Hash: aa80fb04d662afc9f981e1a1107a232f5b826f3ea205324764ac09d89f51b4fd
                                                      • Instruction Fuzzy Hash: CF41C035600208AFDB109F18C889BEEBBA9FF85768F148059F915DB291C774AD41CBE1
                                                      APIs
                                                        • Part of subcall function 0081DDE0: GetFullPathNameW.KERNEL32(00000000,00007FFF,?,?,?,?,?,?,0081CF22,?), ref: 0081DDFD
                                                        • Part of subcall function 0081DDE0: GetFullPathNameW.KERNEL32(?,00007FFF,?,?,?,?,?,0081CF22,?), ref: 0081DE16
                                                      • lstrcmpiW.KERNEL32(?,?), ref: 0081CF45
                                                      • MoveFileW.KERNEL32(?,?), ref: 0081CF7F
                                                      • _wcslen.LIBCMT ref: 0081D005
                                                      • _wcslen.LIBCMT ref: 0081D01B
                                                      • SHFileOperationW.SHELL32(?), ref: 0081D061
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FileFullNamePath_wcslen$MoveOperationlstrcmpi
                                                      • String ID: \*.*
                                                      • API String ID: 3164238972-1173974218
                                                      • Opcode ID: 02ccf2360dced0eb2229c3ff1ece7d7324274acd33aa8fda42f86dc179f51871
                                                      • Instruction ID: b6d8cd6df0018168083554ed81900cc52b34d5308be313d6f0a8a5e3fcfb86c9
                                                      • Opcode Fuzzy Hash: 02ccf2360dced0eb2229c3ff1ece7d7324274acd33aa8fda42f86dc179f51871
                                                      • Instruction Fuzzy Hash: 55415FB18452199FDF12EFA4D985ADEB7BDFF08380F1000A6E505EB141EE74A689CB50
                                                      APIs
                                                      • SendMessageW.USER32(?,000000F0,00000000,00000000), ref: 00842E1C
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00842E4F
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00842E84
                                                      • SendMessageW.USER32(?,000000F1,00000000,00000000), ref: 00842EB6
                                                      • SendMessageW.USER32(?,000000F1,00000001,00000000), ref: 00842EE0
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00842EF1
                                                      • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00842F0B
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: LongWindow$MessageSend
                                                      • String ID:
                                                      • API String ID: 2178440468-0
                                                      • Opcode ID: 05960b333e27ea0bedafb902aafc1eb931dd9eebbd26dd56047a1d36ada3867f
                                                      • Instruction ID: db0c86f74fd0b533bcee217cc3ab0a5ff1fa3f74fdfeea95374af0de6c00b9bf
                                                      • Opcode Fuzzy Hash: 05960b333e27ea0bedafb902aafc1eb931dd9eebbd26dd56047a1d36ada3867f
                                                      • Instruction Fuzzy Hash: 47311234609248AFEB60CF58DC88F653BE8FB9A714F9501A4F915CB2B2CB71AC41DB01
                                                      APIs
                                                      • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 00817769
                                                      • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 0081778F
                                                      • SysAllocString.OLEAUT32(00000000), ref: 00817792
                                                      • SysAllocString.OLEAUT32(?), ref: 008177B0
                                                      • SysFreeString.OLEAUT32(?), ref: 008177B9
                                                      • StringFromGUID2.OLE32(?,?,00000028), ref: 008177DE
                                                      • SysAllocString.OLEAUT32(?), ref: 008177EC
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: String$Alloc$ByteCharMultiWide$FreeFrom
                                                      • String ID:
                                                      • API String ID: 3761583154-0
                                                      • Opcode ID: 67f4a1ca6e1a5083ea61e65757e80f5f701ec7ba5e786367624034930cb98d8c
                                                      • Instruction ID: c09d96912ef472a9659014b43281c070289188b6ff4d46ee32eca98d83a8cad1
                                                      • Opcode Fuzzy Hash: 67f4a1ca6e1a5083ea61e65757e80f5f701ec7ba5e786367624034930cb98d8c
                                                      • Instruction Fuzzy Hash: DD219C7A605219AFDB10AFA8CC88DFA73ACFF09364B048429FA15DB191D6749C81C764
                                                      APIs
                                                      • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 00817842
                                                      • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 00817868
                                                      • SysAllocString.OLEAUT32(00000000), ref: 0081786B
                                                      • SysAllocString.OLEAUT32 ref: 0081788C
                                                      • SysFreeString.OLEAUT32 ref: 00817895
                                                      • StringFromGUID2.OLE32(?,?,00000028), ref: 008178AF
                                                      • SysAllocString.OLEAUT32(?), ref: 008178BD
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: String$Alloc$ByteCharMultiWide$FreeFrom
                                                      • String ID:
                                                      • API String ID: 3761583154-0
                                                      • Opcode ID: 7681bd24a57248b3c3fa65ffba1721cbbfd214dea498866a5450d465e65844cd
                                                      • Instruction ID: 15a0a2aa352e7835d3628aaa5ccc35edd1ae092a56bd61a10fab9e2e7b81d063
                                                      • Opcode Fuzzy Hash: 7681bd24a57248b3c3fa65ffba1721cbbfd214dea498866a5450d465e65844cd
                                                      • Instruction Fuzzy Hash: F0213E75609208AF9B10AFA8DC88DEA77BCFF097607108139F915CB2A1D674DC81CB78
                                                      APIs
                                                      • GetStdHandle.KERNEL32(0000000C), ref: 008204F2
                                                      • CreatePipe.KERNEL32(?,?,0000000C,00000000), ref: 0082052E
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CreateHandlePipe
                                                      • String ID: nul
                                                      • API String ID: 1424370930-2873401336
                                                      • Opcode ID: 4eadd0d0f406ed8b37d85d1a844c9417d68d7bf44d1dd90423ea920de8a05be2
                                                      • Instruction ID: 8f387ed2f0c2db72fc2c2410181b423b9adc0da78c6ef4113ae05e63b9ebc45c
                                                      • Opcode Fuzzy Hash: 4eadd0d0f406ed8b37d85d1a844c9417d68d7bf44d1dd90423ea920de8a05be2
                                                      • Instruction Fuzzy Hash: 9F216275600329ABDB209F69ED44A5A77F8FF45724F204A19F8A1E62E1D7B09980CF60
                                                      APIs
                                                      • GetStdHandle.KERNEL32(000000F6), ref: 008205C6
                                                      • CreatePipe.KERNEL32(?,?,0000000C,00000000), ref: 00820601
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CreateHandlePipe
                                                      • String ID: nul
                                                      • API String ID: 1424370930-2873401336
                                                      • Opcode ID: d1d30adf5126f0eb903041bf036a9491207d0c5c8829c9e4900feedd0499b632
                                                      • Instruction ID: 0a50b54d4eef082041caebc020258a3c34bedfe85ce6e8c1ce5863e85a8a15e9
                                                      • Opcode Fuzzy Hash: d1d30adf5126f0eb903041bf036a9491207d0c5c8829c9e4900feedd0499b632
                                                      • Instruction Fuzzy Hash: 28216775500325AFDB209F69EC44A5A77E8FF95724F200A19F8A1E72E6D7B099A0CF10
                                                      APIs
                                                        • Part of subcall function 007B600E: CreateWindowExW.USER32(?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 007B604C
                                                        • Part of subcall function 007B600E: GetStockObject.GDI32(00000011), ref: 007B6060
                                                        • Part of subcall function 007B600E: SendMessageW.USER32(00000000,00000030,00000000), ref: 007B606A
                                                      • SendMessageW.USER32(00000000,00002001,00000000,FF000000), ref: 00844112
                                                      • SendMessageW.USER32(?,00000409,00000000,FF000000), ref: 0084411F
                                                      • SendMessageW.USER32(?,00000402,00000000,00000000), ref: 0084412A
                                                      • SendMessageW.USER32(?,00000401,00000000,00640000), ref: 00844139
                                                      • SendMessageW.USER32(?,00000404,00000001,00000000), ref: 00844145
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$CreateObjectStockWindow
                                                      • String ID: Msctls_Progress32
                                                      • API String ID: 1025951953-3636473452
                                                      • Opcode ID: 74233505dac18087fe67519f97f4bef570f99e2ec352a1962b501147ec7b8ae8
                                                      • Instruction ID: 48f1f3db62b34d7c1d21f2766930cbb49648fec5eaff06b5cc8e436533e29a80
                                                      • Opcode Fuzzy Hash: 74233505dac18087fe67519f97f4bef570f99e2ec352a1962b501147ec7b8ae8
                                                      • Instruction Fuzzy Hash: B41190B214021DBEEF119E64CC86EE77F5DFF18798F014111BA18E2150CA769C21DBA4
                                                      APIs
                                                        • Part of subcall function 007ED7A3: _free.LIBCMT ref: 007ED7CC
                                                      • _free.LIBCMT ref: 007ED82D
                                                        • Part of subcall function 007E29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000), ref: 007E29DE
                                                        • Part of subcall function 007E29C8: GetLastError.KERNEL32(00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000,00000000), ref: 007E29F0
                                                      • _free.LIBCMT ref: 007ED838
                                                      • _free.LIBCMT ref: 007ED843
                                                      • _free.LIBCMT ref: 007ED897
                                                      • _free.LIBCMT ref: 007ED8A2
                                                      • _free.LIBCMT ref: 007ED8AD
                                                      • _free.LIBCMT ref: 007ED8B8
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free$ErrorFreeHeapLast
                                                      • String ID:
                                                      • API String ID: 776569668-0
                                                      • Opcode ID: d5e9bbcb1dbdafe4c8d3bd98f36014f41f46dc5d4a3df644b036f3c2391e0fc8
                                                      • Instruction ID: bb49280d3295ce41be947cc3099dc98e118f2387f72571b85a4e8dd66a6e4271
                                                      • Opcode Fuzzy Hash: d5e9bbcb1dbdafe4c8d3bd98f36014f41f46dc5d4a3df644b036f3c2391e0fc8
                                                      • Instruction Fuzzy Hash: 3E112171542B88EAD531BFB2CC4FFCB7BDC6F08700F404825B699A64A3DA6DB9064A50
                                                      APIs
                                                      • GetModuleHandleW.KERNEL32(00000000,?,?,00000100,00000000), ref: 0081DA74
                                                      • LoadStringW.USER32(00000000), ref: 0081DA7B
                                                      • GetModuleHandleW.KERNEL32(00000000,00001389,?,00000100), ref: 0081DA91
                                                      • LoadStringW.USER32(00000000), ref: 0081DA98
                                                      • MessageBoxW.USER32(00000000,?,?,00011010), ref: 0081DADC
                                                      Strings
                                                      • %s (%d) : ==> %s: %s %s, xrefs: 0081DAB9
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: HandleLoadModuleString$Message
                                                      • String ID: %s (%d) : ==> %s: %s %s
                                                      • API String ID: 4072794657-3128320259
                                                      • Opcode ID: 0c10b0d34af12b616334150b5399298cc02a490a04e45654805d7876532d5ec1
                                                      • Instruction ID: 397092b9d2479e009854f95dc3065eeb54fcf66dcdef4eb4466dc10a41d40ec7
                                                      • Opcode Fuzzy Hash: 0c10b0d34af12b616334150b5399298cc02a490a04e45654805d7876532d5ec1
                                                      • Instruction Fuzzy Hash: 6D016DF69002187FE750EBE49D89EEB376CFB09305F404496B746E2041EA749E848F74
                                                      APIs
                                                      • InterlockedExchange.KERNEL32(0172DFB8,0172DFB8), ref: 0082097B
                                                      • EnterCriticalSection.KERNEL32(0172DF98,00000000), ref: 0082098D
                                                      • TerminateThread.KERNEL32(?,000001F6), ref: 0082099B
                                                      • WaitForSingleObject.KERNEL32(?,000003E8), ref: 008209A9
                                                      • CloseHandle.KERNEL32(?), ref: 008209B8
                                                      • InterlockedExchange.KERNEL32(0172DFB8,000001F6), ref: 008209C8
                                                      • LeaveCriticalSection.KERNEL32(0172DF98), ref: 008209CF
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CriticalExchangeInterlockedSection$CloseEnterHandleLeaveObjectSingleTerminateThreadWait
                                                      • String ID:
                                                      • API String ID: 3495660284-0
                                                      • Opcode ID: f8f19885ec25f99b793cb3409d946e5655ed91dabc2f03c6761e76172889a649
                                                      • Instruction ID: c27ea578c84097ac68dfa3844e3a88c0e6e700d7df2165cc86b00996453fc88a
                                                      • Opcode Fuzzy Hash: f8f19885ec25f99b793cb3409d946e5655ed91dabc2f03c6761e76172889a649
                                                      • Instruction Fuzzy Hash: EFF0EC36543A22BBD7915FA4EE8DBD6BB39FF06702F402025F202908A1C7B594A5CF90
                                                      APIs
                                                      • GetClientRect.USER32(?,?), ref: 007B5D30
                                                      • GetWindowRect.USER32(?,?), ref: 007B5D71
                                                      • ScreenToClient.USER32(?,?), ref: 007B5D99
                                                      • GetClientRect.USER32(?,?), ref: 007B5ED7
                                                      • GetWindowRect.USER32(?,?), ref: 007B5EF8
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Rect$Client$Window$Screen
                                                      • String ID:
                                                      • API String ID: 1296646539-0
                                                      • Opcode ID: 4d16a9b7c4e20251a851246524c987ba5d43520c1eeac7b6ca8907a455d86baf
                                                      • Instruction ID: 735e8d0b6caff71039bd0a7ef852065b70e4b6c7056a287e9183832cdee80c16
                                                      • Opcode Fuzzy Hash: 4d16a9b7c4e20251a851246524c987ba5d43520c1eeac7b6ca8907a455d86baf
                                                      • Instruction Fuzzy Hash: 00B15739A00A4ADBDB10CFA9C4807FAB7F1FF58310F14851AE9A9D7250DB38EA51DB54
                                                      APIs
                                                      • __allrem.LIBCMT ref: 007E00BA
                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 007E00D6
                                                      • __allrem.LIBCMT ref: 007E00ED
                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 007E010B
                                                      • __allrem.LIBCMT ref: 007E0122
                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 007E0140
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@
                                                      • String ID:
                                                      • API String ID: 1992179935-0
                                                      • Opcode ID: c0aa086816e9a6b10c8594d9af3fc1b6618250ddc70608c46d0048b3e4fbc764
                                                      • Instruction ID: b20514696396fda7d49a5843c09301fa8ca21e88b1e6ecd21a39ffc6a3bbf7db
                                                      • Opcode Fuzzy Hash: c0aa086816e9a6b10c8594d9af3fc1b6618250ddc70608c46d0048b3e4fbc764
                                                      • Instruction Fuzzy Hash: 49810672602746EBE7209F2ACC45B6F73F9AF49324F24453AF511DA381E7B8D9408790
                                                      APIs
                                                        • Part of subcall function 00833149: select.WSOCK32(00000000,?,00000000,00000000,?), ref: 00833195
                                                      • __WSAFDIsSet.WSOCK32(00000000,?), ref: 00831DC0
                                                      • #17.WSOCK32(00000000,?,?,00000000,?,00000010), ref: 00831DE1
                                                      • WSAGetLastError.WSOCK32 ref: 00831DF2
                                                      • inet_ntoa.WSOCK32(?), ref: 00831E8C
                                                      • htons.WSOCK32(?), ref: 00831EDB
                                                      • _strlen.LIBCMT ref: 00831F35
                                                        • Part of subcall function 008139E8: _strlen.LIBCMT ref: 008139F2
                                                        • Part of subcall function 007B6D9E: MultiByteToWideChar.KERNEL32(00000000,00000001,?,?,00000000,00000000,00000002,?,?,?,?,007CCF58,?,?,?), ref: 007B6DBA
                                                        • Part of subcall function 007B6D9E: MultiByteToWideChar.KERNEL32(00000000,00000001,?,?,00000000,?,?,?,007CCF58,?,?,?), ref: 007B6DED
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharMultiWide_strlen$ErrorLasthtonsinet_ntoaselect
                                                      • String ID:
                                                      • API String ID: 1923757996-0
                                                      • Opcode ID: 4eebfdf1abf936de8f9db1d45a0fc00a3b2e52c0591a44ac401cbef1fbf1ca4f
                                                      • Instruction ID: a91da524c14d3de9e1775de7390000fda70d04a2ea3ebf8fcd2f2a43937bb32b
                                                      • Opcode Fuzzy Hash: 4eebfdf1abf936de8f9db1d45a0fc00a3b2e52c0591a44ac401cbef1fbf1ca4f
                                                      • Instruction Fuzzy Hash: CAA1CE30204340AFC724DB24C889F6ABBA5FFC5718F54895CF5569B2A2CB75ED42CB92
                                                      APIs
                                                      • MultiByteToWideChar.KERNEL32(00000001,00000000,?,?,00000000,00000000,?,007D82D9,007D82D9,?,?,?,007E644F,00000001,00000001,8BE85006), ref: 007E6258
                                                      • MultiByteToWideChar.KERNEL32(00000001,00000001,?,?,00000000,?,?,?,?,007E644F,00000001,00000001,8BE85006,?,?,?), ref: 007E62DE
                                                      • WideCharToMultiByte.KERNEL32(00000001,00000000,00000000,00000000,?,8BE85006,00000000,00000000,?,00000400,00000000,?,00000000,00000000,00000000,00000000), ref: 007E63D8
                                                      • __freea.LIBCMT ref: 007E63E5
                                                        • Part of subcall function 007E3820: RtlAllocateHeap.NTDLL(00000000,?,00881444,?,007CFDF5,?,?,007BA976,00000010,00881440,007B13FC,?,007B13C6,?,007B1129), ref: 007E3852
                                                      • __freea.LIBCMT ref: 007E63EE
                                                      • __freea.LIBCMT ref: 007E6413
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharMultiWide__freea$AllocateHeap
                                                      • String ID:
                                                      • API String ID: 1414292761-0
                                                      • Opcode ID: 9402296ca708fc4792ad87e211bd88c132335c43ffb9a3d687f62096d0bfe413
                                                      • Instruction ID: 156c82dfe7b9aa2514b5020d008673c770ba74f8bdd7a0ea57b22a5bbd12d1d8
                                                      • Opcode Fuzzy Hash: 9402296ca708fc4792ad87e211bd88c132335c43ffb9a3d687f62096d0bfe413
                                                      • Instruction Fuzzy Hash: 7E510472602296ABDB258F66CC85EBF77A9EF58790F144629FD05D7180EB38DC40C6A0
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 0083C998: CharUpperBuffW.USER32(?,?,?,?,?,?,?,0083B6AE,?,?), ref: 0083C9B5
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083C9F1
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083CA68
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083CA9E
                                                      • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 0083BCCA
                                                      • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 0083BD25
                                                      • RegCloseKey.ADVAPI32(00000000), ref: 0083BD6A
                                                      • RegEnumValueW.ADVAPI32(?,-00000001,?,?,00000000,?,00000000,00000000), ref: 0083BD99
                                                      • RegCloseKey.ADVAPI32(?,?,00000000), ref: 0083BDF3
                                                      • RegCloseKey.ADVAPI32(?), ref: 0083BDFF
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$Close$BuffCharConnectEnumOpenRegistryUpperValue
                                                      • String ID:
                                                      • API String ID: 1120388591-0
                                                      • Opcode ID: ca870c8a068ea850fdccf6525713b15c595d9a4ff4f10a131849780150bf1f34
                                                      • Instruction ID: 2a2830a9a89c550ffab2c42ac810b7802420bb4711ecf27d7a727d71da4d3fae
                                                      • Opcode Fuzzy Hash: ca870c8a068ea850fdccf6525713b15c595d9a4ff4f10a131849780150bf1f34
                                                      • Instruction Fuzzy Hash: 7281A070208241EFD714DF24C895E6ABBE5FF84308F14895DF6598B2A2DB31ED45CB92
                                                      APIs
                                                      • VariantInit.OLEAUT32(00000035), ref: 0080F7B9
                                                      • SysAllocString.OLEAUT32(00000001), ref: 0080F860
                                                      • VariantCopy.OLEAUT32(0080FA64,00000000), ref: 0080F889
                                                      • VariantClear.OLEAUT32(0080FA64), ref: 0080F8AD
                                                      • VariantCopy.OLEAUT32(0080FA64,00000000), ref: 0080F8B1
                                                      • VariantClear.OLEAUT32(?), ref: 0080F8BB
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Variant$ClearCopy$AllocInitString
                                                      • String ID:
                                                      • API String ID: 3859894641-0
                                                      • Opcode ID: c0daa87be509465dc15cb7dc44de345f60b467517157a08ccb9cd5abaf162445
                                                      • Instruction ID: 4b932705aeb3ec34ec0f726314d81d7ebfaa5aede649a36723e624c1718585a2
                                                      • Opcode Fuzzy Hash: c0daa87be509465dc15cb7dc44de345f60b467517157a08ccb9cd5abaf162445
                                                      • Instruction Fuzzy Hash: E7511731600314EADFB0AB65DC95B69B7A8FF45314B20C42AEA02DF6D3D7748C40C796
                                                      APIs
                                                        • Part of subcall function 007B7620: _wcslen.LIBCMT ref: 007B7625
                                                        • Part of subcall function 007B6B57: _wcslen.LIBCMT ref: 007B6B6A
                                                      • GetOpenFileNameW.COMDLG32(00000058), ref: 008294E5
                                                      • _wcslen.LIBCMT ref: 00829506
                                                      • _wcslen.LIBCMT ref: 0082952D
                                                      • GetSaveFileNameW.COMDLG32(00000058), ref: 00829585
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$FileName$OpenSave
                                                      • String ID: X
                                                      • API String ID: 83654149-3081909835
                                                      • Opcode ID: 9485bcc7ac1a8acc7fd18ff802b66d8be47f5078eb84f1a6b5cede8c1c77c6c4
                                                      • Instruction ID: 2fbcf54583fa761b377acb6f7820c5eccfc9df1326cc8bcf9d45b17c50c0e9f8
                                                      • Opcode Fuzzy Hash: 9485bcc7ac1a8acc7fd18ff802b66d8be47f5078eb84f1a6b5cede8c1c77c6c4
                                                      • Instruction Fuzzy Hash: 71E1AE31604310DFC724EF24D889BAAB7E4FF84314F14896DE9999B2A2DB34DD45CB92
                                                      APIs
                                                        • Part of subcall function 007C9BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 007C9BB2
                                                      • BeginPaint.USER32(?,?,?), ref: 007C9241
                                                      • GetWindowRect.USER32(?,?), ref: 007C92A5
                                                      • ScreenToClient.USER32(?,?), ref: 007C92C2
                                                      • SetViewportOrgEx.GDI32(00000000,?,?,00000000), ref: 007C92D3
                                                      • EndPaint.USER32(?,?,?,?,?), ref: 007C9321
                                                      • Rectangle.GDI32(00000000,00000000,00000000,?,?), ref: 008071EA
                                                        • Part of subcall function 007C9339: BeginPath.GDI32(00000000), ref: 007C9357
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: BeginPaintWindow$ClientLongPathRectRectangleScreenViewport
                                                      • String ID:
                                                      • API String ID: 3050599898-0
                                                      • Opcode ID: e331c05b1789766830afaba4f11a83c2b7602612c1e4d8683a46b1080adbbe3f
                                                      • Instruction ID: ac66086d4325e7e2a011fe797acfbd339b212d36ffc8b43932e60ec032e0dff3
                                                      • Opcode Fuzzy Hash: e331c05b1789766830afaba4f11a83c2b7602612c1e4d8683a46b1080adbbe3f
                                                      • Instruction Fuzzy Hash: 1E418C70505201EFDB51DF28CC88FAA7BA8FB56320F14066DFA95C72E1CB35A846DB61
                                                      APIs
                                                      • InterlockedExchange.KERNEL32(?,000001F5), ref: 0082080C
                                                      • ReadFile.KERNEL32(?,?,0000FFFF,?,00000000), ref: 00820847
                                                      • EnterCriticalSection.KERNEL32(?), ref: 00820863
                                                      • LeaveCriticalSection.KERNEL32(?), ref: 008208DC
                                                      • ReadFile.KERNEL32(?,?,0000FFFF,00000000,00000000), ref: 008208F3
                                                      • InterlockedExchange.KERNEL32(?,000001F6), ref: 00820921
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CriticalExchangeFileInterlockedReadSection$EnterLeave
                                                      • String ID:
                                                      • API String ID: 3368777196-0
                                                      • Opcode ID: 7d0ce0ab9e20f6e0f3d5c86711fc7bb73abc4e2c24b16ddb4b8683cafb48649b
                                                      • Instruction ID: 05cd6cd3e21b83c3ee9e1bfccf5d61e33f8d31a31e4c79350daf2c97486b4793
                                                      • Opcode Fuzzy Hash: 7d0ce0ab9e20f6e0f3d5c86711fc7bb73abc4e2c24b16ddb4b8683cafb48649b
                                                      • Instruction Fuzzy Hash: F6416B71900215EBDF14AF64DC89A6A77B9FF04300F1440A9ED04DA297DB74DEA1DFA4
                                                      APIs
                                                      • ShowWindow.USER32(FFFFFFFF,00000000,?,00000000,00000000,?,0080F3AB,00000000,?,?,00000000,?,0080682C,00000004,00000000,00000000), ref: 0084824C
                                                      • EnableWindow.USER32(?,00000000), ref: 00848272
                                                      • ShowWindow.USER32(FFFFFFFF,00000000), ref: 008482D1
                                                      • ShowWindow.USER32(?,00000004), ref: 008482E5
                                                      • EnableWindow.USER32(?,00000001), ref: 0084830B
                                                      • SendMessageW.USER32(?,0000130C,00000000,00000000), ref: 0084832F
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Show$Enable$MessageSend
                                                      • String ID:
                                                      • API String ID: 642888154-0
                                                      • Opcode ID: d34b490438f3b770e3ca7d68df8556ec132c2bfecfd2a476fa43e1cda6e6b118
                                                      • Instruction ID: 560e613173ccbea6f468740666c0c89179e7c25fd6238db91fbc56e709dabd04
                                                      • Opcode Fuzzy Hash: d34b490438f3b770e3ca7d68df8556ec132c2bfecfd2a476fa43e1cda6e6b118
                                                      • Instruction Fuzzy Hash: BB41A534601658EFDF51CF29CC99BE87BE5FB0A714F185269E5188B262CB71AC41CB50
                                                      APIs
                                                      • IsWindowVisible.USER32(?), ref: 00814C95
                                                      • SendMessageW.USER32(?,0000000E,00000000,00000000), ref: 00814CB2
                                                      • SendMessageW.USER32(?,0000000D,00000001,00000000), ref: 00814CEA
                                                      • _wcslen.LIBCMT ref: 00814D08
                                                      • CharUpperBuffW.USER32(00000000,00000000,?,?,?,?), ref: 00814D10
                                                      • _wcsstr.LIBVCRUNTIME ref: 00814D1A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$BuffCharUpperVisibleWindow_wcslen_wcsstr
                                                      • String ID:
                                                      • API String ID: 72514467-0
                                                      • Opcode ID: 3564b8b54709cf5a26147709583640c375eae3186e9a79249835ddfb1a1fd464
                                                      • Instruction ID: dafa1353e084389a723a73f2631bd3020530227d14f701c609522a2e58ba2d6b
                                                      • Opcode Fuzzy Hash: 3564b8b54709cf5a26147709583640c375eae3186e9a79249835ddfb1a1fd464
                                                      • Instruction Fuzzy Hash: 9E213876205204BBEB555B39EC09EBB7BACEF45750F10907EF809CA192EA75DC81D2A0
                                                      APIs
                                                        • Part of subcall function 007B3AA2: GetFullPathNameW.KERNEL32(?,00007FFF,?,00000000,?,?,007B3A97,?,?,007B2E7F,?,?,?,00000000), ref: 007B3AC2
                                                      • _wcslen.LIBCMT ref: 0082587B
                                                      • CoInitialize.OLE32(00000000), ref: 00825995
                                                      • CoCreateInstance.OLE32(0084FCF8,00000000,00000001,0084FB68,?), ref: 008259AE
                                                      • CoUninitialize.OLE32 ref: 008259CC
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CreateFullInitializeInstanceNamePathUninitialize_wcslen
                                                      • String ID: .lnk
                                                      • API String ID: 3172280962-24824748
                                                      • Opcode ID: f07f93dbc57686f00b6ebbb5e2df5cd26396f75515e79a0778075418720a209a
                                                      • Instruction ID: 3aa551f535abcae5cf4e8a6e1f23ddd9778886301623694da6f0f7d8d77352cb
                                                      • Opcode Fuzzy Hash: f07f93dbc57686f00b6ebbb5e2df5cd26396f75515e79a0778075418720a209a
                                                      • Instruction Fuzzy Hash: 6CD15071608611DFC714DF24D488A6ABBE5FF89720F148859F88ADB361DB31EC85CB92
                                                      APIs
                                                        • Part of subcall function 00810FB4: GetTokenInformation.ADVAPI32(?,00000002,?,00000000,?), ref: 00810FCA
                                                        • Part of subcall function 00810FB4: GetLastError.KERNEL32(?,00000002,?,00000000,?), ref: 00810FD6
                                                        • Part of subcall function 00810FB4: GetProcessHeap.KERNEL32(00000008,?,?,00000002,?,00000000,?), ref: 00810FE5
                                                        • Part of subcall function 00810FB4: HeapAlloc.KERNEL32(00000000,?,00000002,?,00000000,?), ref: 00810FEC
                                                        • Part of subcall function 00810FB4: GetTokenInformation.ADVAPI32(?,00000002,00000000,?,?,?,00000002,?,00000000,?), ref: 00811002
                                                      • GetLengthSid.ADVAPI32(?,00000000,00811335), ref: 008117AE
                                                      • GetProcessHeap.KERNEL32(00000008,00000000), ref: 008117BA
                                                      • HeapAlloc.KERNEL32(00000000), ref: 008117C1
                                                      • CopySid.ADVAPI32(00000000,00000000,?), ref: 008117DA
                                                      • GetProcessHeap.KERNEL32(00000000,00000000,00811335), ref: 008117EE
                                                      • HeapFree.KERNEL32(00000000), ref: 008117F5
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Heap$Process$AllocInformationToken$CopyErrorFreeLastLength
                                                      • String ID:
                                                      • API String ID: 3008561057-0
                                                      • Opcode ID: 43388ad88ae111a0e3ddeab9fe74fcf3b32928b59066d5211acfefd5fbdad174
                                                      • Instruction ID: 1791a53b9c0f37753701697067b9e25a0c276fe39f103af1701c0a300f2c51dc
                                                      • Opcode Fuzzy Hash: 43388ad88ae111a0e3ddeab9fe74fcf3b32928b59066d5211acfefd5fbdad174
                                                      • Instruction Fuzzy Hash: BB118636602609EBDF109FA4CC49FEE7BADFF42359F104818E581E7294C736A980CB60
                                                      APIs
                                                      • GetCurrentProcess.KERNEL32(0000000A,00000004), ref: 008114FF
                                                      • OpenProcessToken.ADVAPI32(00000000), ref: 00811506
                                                      • CreateEnvironmentBlock.USERENV(?,00000004,00000001), ref: 00811515
                                                      • CloseHandle.KERNEL32(00000004), ref: 00811520
                                                      • CreateProcessWithLogonW.ADVAPI32(?,?,?,00000000,00000000,?,?,00000000,?,?,?), ref: 0081154F
                                                      • DestroyEnvironmentBlock.USERENV(00000000), ref: 00811563
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process$BlockCreateEnvironment$CloseCurrentDestroyHandleLogonOpenTokenWith
                                                      • String ID:
                                                      • API String ID: 1413079979-0
                                                      • Opcode ID: a206740ca971809b4b692bdef07b1e2c230afe89498ca4c7da505547bb625867
                                                      • Instruction ID: befebe8f913ca5f7072692a5b3c4c8e4d74bc3703ab63a3da87fb2a367805a30
                                                      • Opcode Fuzzy Hash: a206740ca971809b4b692bdef07b1e2c230afe89498ca4c7da505547bb625867
                                                      • Instruction Fuzzy Hash: BC11297660220DABDF118F98DD49FDE7BAEFF49744F044015FA05A2160C3758EA0DB61
                                                      APIs
                                                      • GetLastError.KERNEL32(?,?,007D3379,007D2FE5), ref: 007D3390
                                                      • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 007D339E
                                                      • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 007D33B7
                                                      • SetLastError.KERNEL32(00000000,?,007D3379,007D2FE5), ref: 007D3409
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorLastValue___vcrt_
                                                      • String ID:
                                                      • API String ID: 3852720340-0
                                                      • Opcode ID: 70e49fe5c61183378dc5af9fa03b35a25b56d7f2a5985bd5c2fd3d1a2ca4324b
                                                      • Instruction ID: 5a2af98d07fef3641b7fd9a02d44239554d3a57a71ada4ed1d44270af326a66c
                                                      • Opcode Fuzzy Hash: 70e49fe5c61183378dc5af9fa03b35a25b56d7f2a5985bd5c2fd3d1a2ca4324b
                                                      • Instruction Fuzzy Hash: 3D012432209711FEAA242BB4BC8D5262AB8FB05379320022FF414963F1EF198D819186
                                                      APIs
                                                      • GetLastError.KERNEL32(?,?,007E5686,007F3CD6,?,00000000,?,007E5B6A,?,?,?,?,?,007DE6D1,?,00878A48), ref: 007E2D78
                                                      • _free.LIBCMT ref: 007E2DAB
                                                      • _free.LIBCMT ref: 007E2DD3
                                                      • SetLastError.KERNEL32(00000000,?,?,?,?,007DE6D1,?,00878A48,00000010,007B4F4A,?,?,00000000,007F3CD6), ref: 007E2DE0
                                                      • SetLastError.KERNEL32(00000000,?,?,?,?,007DE6D1,?,00878A48,00000010,007B4F4A,?,?,00000000,007F3CD6), ref: 007E2DEC
                                                      • _abort.LIBCMT ref: 007E2DF2
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorLast$_free$_abort
                                                      • String ID:
                                                      • API String ID: 3160817290-0
                                                      • Opcode ID: e93bfc6934da2f4a25e364690007e6ed43a82ea4da71ee528bf0c2ab896f23e9
                                                      • Instruction ID: dcd59a9627bac9f6fcdb89895675d94b15d61b2987c9438e7278907d289b71f5
                                                      • Opcode Fuzzy Hash: e93bfc6934da2f4a25e364690007e6ed43a82ea4da71ee528bf0c2ab896f23e9
                                                      • Instruction Fuzzy Hash: 8DF0F935607580B7C25267376C0EA1A265DBBCA7A4F314119F624D32A3EE2C88034160
                                                      APIs
                                                        • Part of subcall function 007C9639: ExtCreatePen.GDI32(?,?,00000000,00000000,00000000,?,00000000), ref: 007C9693
                                                        • Part of subcall function 007C9639: SelectObject.GDI32(?,00000000), ref: 007C96A2
                                                        • Part of subcall function 007C9639: BeginPath.GDI32(?), ref: 007C96B9
                                                        • Part of subcall function 007C9639: SelectObject.GDI32(?,00000000), ref: 007C96E2
                                                      • MoveToEx.GDI32(?,-00000002,00000000,00000000), ref: 00848A4E
                                                      • LineTo.GDI32(?,00000003,00000000), ref: 00848A62
                                                      • MoveToEx.GDI32(?,00000000,-00000002,00000000), ref: 00848A70
                                                      • LineTo.GDI32(?,00000000,00000003), ref: 00848A80
                                                      • EndPath.GDI32(?), ref: 00848A90
                                                      • StrokePath.GDI32(?), ref: 00848AA0
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Path$LineMoveObjectSelect$BeginCreateStroke
                                                      • String ID:
                                                      • API String ID: 43455801-0
                                                      • Opcode ID: 3d321a40a4a2f199871ad92441e7804a5175939dfea7f1ba3df9303118f39fef
                                                      • Instruction ID: 6fc316a5b477960c6d52a3f73b5bf95c4b115089fbf2906a7f119267e4524209
                                                      • Opcode Fuzzy Hash: 3d321a40a4a2f199871ad92441e7804a5175939dfea7f1ba3df9303118f39fef
                                                      • Instruction Fuzzy Hash: F411057600111CFFEF129F94DC88EAA7F6CFB09394F048022FA199A1A1C771AD55DBA0
                                                      APIs
                                                      • GetDC.USER32(00000000), ref: 00815218
                                                      • GetDeviceCaps.GDI32(00000000,00000058), ref: 00815229
                                                      • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00815230
                                                      • ReleaseDC.USER32(00000000,00000000), ref: 00815238
                                                      • MulDiv.KERNEL32(000009EC,?,00000000), ref: 0081524F
                                                      • MulDiv.KERNEL32(000009EC,00000001,?), ref: 00815261
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CapsDevice$Release
                                                      • String ID:
                                                      • API String ID: 1035833867-0
                                                      • Opcode ID: 2b35a14a6b9404fa82cd2ee3cf8cede32e987296bda9735f90f77c51db30cb75
                                                      • Instruction ID: 26fcf05aff55e071b714a06cb8017ff89b591e320e8addc1cc98217dd0ef9d72
                                                      • Opcode Fuzzy Hash: 2b35a14a6b9404fa82cd2ee3cf8cede32e987296bda9735f90f77c51db30cb75
                                                      • Instruction Fuzzy Hash: B1014F75A01719BBEB109BA69C49A5EBFBCFF49751F048066FA04E7291DA709800CFA0
                                                      APIs
                                                      • MapVirtualKeyW.USER32(0000005B,00000000), ref: 007B1BF4
                                                      • MapVirtualKeyW.USER32(00000010,00000000), ref: 007B1BFC
                                                      • MapVirtualKeyW.USER32(000000A0,00000000), ref: 007B1C07
                                                      • MapVirtualKeyW.USER32(000000A1,00000000), ref: 007B1C12
                                                      • MapVirtualKeyW.USER32(00000011,00000000), ref: 007B1C1A
                                                      • MapVirtualKeyW.USER32(00000012,00000000), ref: 007B1C22
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Virtual
                                                      • String ID:
                                                      • API String ID: 4278518827-0
                                                      • Opcode ID: 63b053ac44c51eae03ab861f12dd4979592de3ca2760f43d626d9661ffc6f3f0
                                                      • Instruction ID: 3f8686ace90b27130a065b1dffd0cc3d05dc5a0dd8acd1c2a841b472654460b8
                                                      • Opcode Fuzzy Hash: 63b053ac44c51eae03ab861f12dd4979592de3ca2760f43d626d9661ffc6f3f0
                                                      • Instruction Fuzzy Hash: B10167B0902B5ABDE3008F6A8C85B52FFA8FF19354F00411BA15C4BA42C7F5A864CFE5
                                                      APIs
                                                      • PostMessageW.USER32(?,00000010,00000000,00000000), ref: 0081EB30
                                                      • SendMessageTimeoutW.USER32(?,00000010,00000000,00000000,00000002,000001F4,?), ref: 0081EB46
                                                      • GetWindowThreadProcessId.USER32(?,?), ref: 0081EB55
                                                      • OpenProcess.KERNEL32(001F0FFF,00000000,?,?,?,?,00000010,00000000,00000000,00000002,000001F4,?,?,00000010,00000000,00000000), ref: 0081EB64
                                                      • TerminateProcess.KERNEL32(00000000,00000000,?,?,?,00000010,00000000,00000000,00000002,000001F4,?,?,00000010,00000000,00000000), ref: 0081EB6E
                                                      • CloseHandle.KERNEL32(00000000,?,?,?,00000010,00000000,00000000,00000002,000001F4,?,?,00000010,00000000,00000000), ref: 0081EB75
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process$Message$CloseHandleOpenPostSendTerminateThreadTimeoutWindow
                                                      • String ID:
                                                      • API String ID: 839392675-0
                                                      • Opcode ID: e66797af8c43b99b37343f043edbcd3cdcb46727e616ce3037a06bf5ea47335d
                                                      • Instruction ID: 901d6b6c9596cd258f93bb76504fc56fc0e80b314647739ba9a3f5df6893303c
                                                      • Opcode Fuzzy Hash: e66797af8c43b99b37343f043edbcd3cdcb46727e616ce3037a06bf5ea47335d
                                                      • Instruction Fuzzy Hash: D1F0BEBA202158BBE7605B629C0EEEF3E7CFFCBB11F004158FA02E1090D7A01A01C6B4
                                                      APIs
                                                      • GetClientRect.USER32(?), ref: 00807452
                                                      • SendMessageW.USER32(?,00001328,00000000,?), ref: 00807469
                                                      • GetWindowDC.USER32(?), ref: 00807475
                                                      • GetPixel.GDI32(00000000,?,?), ref: 00807484
                                                      • ReleaseDC.USER32(?,00000000), ref: 00807496
                                                      • GetSysColor.USER32(00000005), ref: 008074B0
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClientColorMessagePixelRectReleaseSendWindow
                                                      • String ID:
                                                      • API String ID: 272304278-0
                                                      • Opcode ID: acb979966e7a7a8ae8b3401b6dc3d0b94f7d225158ff5ee21d12e7a87cc43d1b
                                                      • Instruction ID: a1a110e5c03d7311928d127f5015a7cefbee78a13102714282868b4eb6ec928e
                                                      • Opcode Fuzzy Hash: acb979966e7a7a8ae8b3401b6dc3d0b94f7d225158ff5ee21d12e7a87cc43d1b
                                                      • Instruction Fuzzy Hash: 6D018635801605EFEB905FA4DC08BAE7BB9FB05321F224068FA16A21A1CB312E41EB14
                                                      APIs
                                                      • WaitForSingleObject.KERNEL32(?,000000FF), ref: 0081187F
                                                      • UnloadUserProfile.USERENV(?,?), ref: 0081188B
                                                      • CloseHandle.KERNEL32(?), ref: 00811894
                                                      • CloseHandle.KERNEL32(?), ref: 0081189C
                                                      • GetProcessHeap.KERNEL32(00000000,?), ref: 008118A5
                                                      • HeapFree.KERNEL32(00000000), ref: 008118AC
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CloseHandleHeap$FreeObjectProcessProfileSingleUnloadUserWait
                                                      • String ID:
                                                      • API String ID: 146765662-0
                                                      • Opcode ID: 16a481885e78c2fa61b1b01d01873b95588c74c7b80c024a57098c4260f90122
                                                      • Instruction ID: 1c0937363f03f0a46bf8fc9774ef32a150b21399f27d2067bf766a607b505bf1
                                                      • Opcode Fuzzy Hash: 16a481885e78c2fa61b1b01d01873b95588c74c7b80c024a57098c4260f90122
                                                      • Instruction Fuzzy Hash: B1E0E53A206101BBDB415FA5ED0C90AFF3DFF4AB22B108220F22581170CB329420DF50
                                                      APIs
                                                        • Part of subcall function 007B7620: _wcslen.LIBCMT ref: 007B7625
                                                      • GetMenuItemInfoW.USER32(?,?,00000000,?), ref: 0081C6EE
                                                      • _wcslen.LIBCMT ref: 0081C735
                                                      • SetMenuItemInfoW.USER32(?,?,00000000,?), ref: 0081C79C
                                                      • SetMenuDefaultItem.USER32(?,000000FF,00000000), ref: 0081C7CA
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ItemMenu$Info_wcslen$Default
                                                      • String ID: 0
                                                      • API String ID: 1227352736-4108050209
                                                      • Opcode ID: d378e557efb11aed9cfaead9b92d2c877bff3fb23bc0d371c9f8dd0be77a9531
                                                      • Instruction ID: eb8bf6c51b4bbe777219372a5a75404beadabe73d54c1f13d426a15ea12e24b4
                                                      • Opcode Fuzzy Hash: d378e557efb11aed9cfaead9b92d2c877bff3fb23bc0d371c9f8dd0be77a9531
                                                      • Instruction Fuzzy Hash: FE51AD716843019BD714AF28C889BEA77ECFF59314F040A2DF996D21E1DBA4D984CB52
                                                      APIs
                                                      • ShellExecuteExW.SHELL32(0000003C), ref: 0083AEA3
                                                        • Part of subcall function 007B7620: _wcslen.LIBCMT ref: 007B7625
                                                      • GetProcessId.KERNEL32(00000000), ref: 0083AF38
                                                      • CloseHandle.KERNEL32(00000000), ref: 0083AF67
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CloseExecuteHandleProcessShell_wcslen
                                                      • String ID: <$@
                                                      • API String ID: 146682121-1426351568
                                                      • Opcode ID: a1e8e54d99908530fd31c87e4971018f6bd14dc05f2c7eeb71df1fd777beea8e
                                                      • Instruction ID: 0e93e18584d8fd4e031ba74f8871918c6b0a72136bb4e8682d7f72f6ddc2bcfa
                                                      • Opcode Fuzzy Hash: a1e8e54d99908530fd31c87e4971018f6bd14dc05f2c7eeb71df1fd777beea8e
                                                      • Instruction Fuzzy Hash: 87718A75A00619DFCB18DF54C489A9EBBF4FF48314F048499E856AB3A2CB78ED41CB91
                                                      APIs
                                                      • CoCreateInstance.OLE32(?,00000000,00000005,?,?,?,?,?,?,?,?,?,?,?), ref: 00817206
                                                      • SetErrorMode.KERNEL32(00000001,?,?,?,?,?,?,?,?,?), ref: 0081723C
                                                      • GetProcAddress.KERNEL32(?,DllGetClassObject), ref: 0081724D
                                                      • SetErrorMode.KERNEL32(00000000,?,?,?,?,?,?,?,?,?), ref: 008172CF
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorMode$AddressCreateInstanceProc
                                                      • String ID: DllGetClassObject
                                                      • API String ID: 753597075-1075368562
                                                      • Opcode ID: 38a6ffc5ca8cbca647b1fc7f10cd762c66a8f94732e9ebd2ada5964b33278f4b
                                                      • Instruction ID: 1ca5c98b3e6a3f8f05037f39f97756a81cdd12291725abb556c542c6cfa0c9e7
                                                      • Opcode Fuzzy Hash: 38a6ffc5ca8cbca647b1fc7f10cd762c66a8f94732e9ebd2ada5964b33278f4b
                                                      • Instruction Fuzzy Hash: D9412971A04205AFDB15CF54C884ADA7BBDFF49314B1480ADBD0ADF20AD7B1D985CBA0
                                                      APIs
                                                      • GetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 00843E35
                                                      • IsMenu.USER32(?), ref: 00843E4A
                                                      • InsertMenuItemW.USER32(?,?,00000001,00000030), ref: 00843E92
                                                      • DrawMenuBar.USER32 ref: 00843EA5
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Menu$Item$DrawInfoInsert
                                                      • String ID: 0
                                                      • API String ID: 3076010158-4108050209
                                                      • Opcode ID: 45180c6f9bd4b2ccfb32527353aac6a5f9f7ddb61013cd8a837b161c1244ee81
                                                      • Instruction ID: b52c46acbfc5dd71368a9f03236ddabf6cb1de7dcc274b189626b5d1a03da5cf
                                                      • Opcode Fuzzy Hash: 45180c6f9bd4b2ccfb32527353aac6a5f9f7ddb61013cd8a837b161c1244ee81
                                                      • Instruction Fuzzy Hash: CF414575A0220DEFDB10EF64D884AAABBB9FF49354F044129E915EB650D730AE45CF60
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 00813CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00813CCA
                                                      • SendMessageW.USER32(?,00000188,00000000,00000000), ref: 00811E66
                                                      • SendMessageW.USER32(?,0000018A,00000000,00000000), ref: 00811E79
                                                      • SendMessageW.USER32(?,00000189,?,00000000), ref: 00811EA9
                                                        • Part of subcall function 007B6B57: _wcslen.LIBCMT ref: 007B6B6A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$_wcslen$ClassName
                                                      • String ID: ComboBox$ListBox
                                                      • API String ID: 2081771294-1403004172
                                                      • Opcode ID: a53d673d4eddfad0e43288959870c60e66c2f82700560289a58195870686ea9a
                                                      • Instruction ID: 6dd28082749322f52527f9083762dc85afc477b2eb9fa2f146637e5ffa25ed64
                                                      • Opcode Fuzzy Hash: a53d673d4eddfad0e43288959870c60e66c2f82700560289a58195870686ea9a
                                                      • Instruction Fuzzy Hash: 6B210771A00108BADF14ABA4DC4DDFFB7BDFF45354B104119FA26E71E1DB3849459620
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen
                                                      • String ID: HKEY_LOCAL_MACHINE$HKLM
                                                      • API String ID: 176396367-4004644295
                                                      • Opcode ID: 96e607f1653f1de3847f50a58d7f48ca195059fd82775beab904785784a4a181
                                                      • Instruction ID: ad75427804bba44a9bc872dc04acdd8cf432934fbf873aaaf5179b6f6b166b7d
                                                      • Opcode Fuzzy Hash: 96e607f1653f1de3847f50a58d7f48ca195059fd82775beab904785784a4a181
                                                      • Instruction Fuzzy Hash: 6A31B1B2A001798BCB20EF6D98545BE33A1FBE1754F154029E855FB349EA75CD44D3E0
                                                      APIs
                                                      • SendMessageW.USER32(00000000,00000467,00000000,?), ref: 00842F8D
                                                      • LoadLibraryW.KERNEL32(?), ref: 00842F94
                                                      • SendMessageW.USER32(?,00000467,00000000,00000000), ref: 00842FA9
                                                      • DestroyWindow.USER32(?), ref: 00842FB1
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$DestroyLibraryLoadWindow
                                                      • String ID: SysAnimate32
                                                      • API String ID: 3529120543-1011021900
                                                      • Opcode ID: 62840c4a7149199b99da4e1aa952f25cc0ae62149e190b09335d082f571e427d
                                                      • Instruction ID: d45e6647133c00990e823b7ae1700e6fe0e827252d86e0245c9451369a3b9770
                                                      • Opcode Fuzzy Hash: 62840c4a7149199b99da4e1aa952f25cc0ae62149e190b09335d082f571e427d
                                                      • Instruction Fuzzy Hash: 5821AE7120820DABEB205F64DC84EBB77BDFB69364F904218F950D2190DB71DC559760
                                                      APIs
                                                      • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,?,007D4D1E,007E28E9,?,007D4CBE,007E28E9,008788B8,0000000C,007D4E15,007E28E9,00000002), ref: 007D4D8D
                                                      • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 007D4DA0
                                                      • FreeLibrary.KERNEL32(00000000,?,?,?,007D4D1E,007E28E9,?,007D4CBE,007E28E9,008788B8,0000000C,007D4E15,007E28E9,00000002,00000000), ref: 007D4DC3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: AddressFreeHandleLibraryModuleProc
                                                      • String ID: CorExitProcess$mscoree.dll
                                                      • API String ID: 4061214504-1276376045
                                                      • Opcode ID: 8400c6adf447e1ce7be9f633a421b9195ce8996fef8a6b3035f2c9ce3c026de3
                                                      • Instruction ID: 009cc838ae82663efe9e218ba111b8a39ed9961825e89eb936bcd1728044c400
                                                      • Opcode Fuzzy Hash: 8400c6adf447e1ce7be9f633a421b9195ce8996fef8a6b3035f2c9ce3c026de3
                                                      • Instruction Fuzzy Hash: A6F04F35A41208BBDB519F90DC49BADBFB9FF48756F0000A9F909A2360DB359940CED0
                                                      APIs
                                                      • LoadLibraryA.KERNEL32 ref: 0080D3AD
                                                      • GetProcAddress.KERNEL32(00000000,GetSystemWow64DirectoryW), ref: 0080D3BF
                                                      • FreeLibrary.KERNEL32(00000000), ref: 0080D3E5
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Library$AddressFreeLoadProc
                                                      • String ID: GetSystemWow64DirectoryW$X64
                                                      • API String ID: 145871493-2590602151
                                                      • Opcode ID: 803d85b4c19a42dda54a395bf521526526d6d7a17e6ad91fb263cb61b7087ae2
                                                      • Instruction ID: 50cf7d2b85a3fb04d981a5bf85736a1ed49d82a929f3706e93277faa45b8956b
                                                      • Opcode Fuzzy Hash: 803d85b4c19a42dda54a395bf521526526d6d7a17e6ad91fb263cb61b7087ae2
                                                      • Instruction Fuzzy Hash: 9EF05C75407714EBD7F117904C08A197718FF11705B558059F801E12C9EB24DD44C795
                                                      APIs
                                                      • LoadLibraryA.KERNEL32(kernel32.dll,?,?,007B4EDD,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4E9C
                                                      • GetProcAddress.KERNEL32(00000000,Wow64DisableWow64FsRedirection), ref: 007B4EAE
                                                      • FreeLibrary.KERNEL32(00000000,?,?,007B4EDD,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4EC0
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Library$AddressFreeLoadProc
                                                      • String ID: Wow64DisableWow64FsRedirection$kernel32.dll
                                                      • API String ID: 145871493-3689287502
                                                      • Opcode ID: 91501abc1e4e3c3b6cebd153be5206cabbfd4d53cfcfcd39315af6641b26217c
                                                      • Instruction ID: 2cf28801316f23443af8c7466a14622f30a442b876fc85099be98b51582b6bda
                                                      • Opcode Fuzzy Hash: 91501abc1e4e3c3b6cebd153be5206cabbfd4d53cfcfcd39315af6641b26217c
                                                      • Instruction Fuzzy Hash: 05E01D39A036225BD3B11B296C19B9F755CFF82F667050115FD05D2256DB6CCD01C5A1
                                                      APIs
                                                      • LoadLibraryA.KERNEL32(kernel32.dll,?,?,007F3CDE,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4E62
                                                      • GetProcAddress.KERNEL32(00000000,Wow64RevertWow64FsRedirection), ref: 007B4E74
                                                      • FreeLibrary.KERNEL32(00000000,?,?,007F3CDE,?,00881418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 007B4E87
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Library$AddressFreeLoadProc
                                                      • String ID: Wow64RevertWow64FsRedirection$kernel32.dll
                                                      • API String ID: 145871493-1355242751
                                                      • Opcode ID: 7891c0e88bb014a026f9a1884b5abb12965c8ba9d4e8197aa0781b516d3ca84e
                                                      • Instruction ID: 9e149030d5132c0ccb954c4f8892cf3a71f8393d6646c3f192616eb68c94063c
                                                      • Opcode Fuzzy Hash: 7891c0e88bb014a026f9a1884b5abb12965c8ba9d4e8197aa0781b516d3ca84e
                                                      • Instruction Fuzzy Hash: 97D01239503A615756A21B256C1CECB7B1CFF86B653054515B905E2215CF69CD01C5E1
                                                      APIs
                                                      • DeleteFileW.KERNEL32(?,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004), ref: 00822C05
                                                      • DeleteFileW.KERNEL32(?), ref: 00822C87
                                                      • CopyFileW.KERNEL32(?,?,00000000,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004,00000001), ref: 00822C9D
                                                      • DeleteFileW.KERNEL32(?,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004), ref: 00822CAE
                                                      • DeleteFileW.KERNEL32(?,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004), ref: 00822CC0
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: File$Delete$Copy
                                                      • String ID:
                                                      • API String ID: 3226157194-0
                                                      • Opcode ID: e1418647f15477fc153d24a79e0b4b6c33fe898b344572febf70c5b13b463224
                                                      • Instruction ID: 63e30089b1e106abe8d7d06f8cbb448471273090a60a21a06621a022785827c6
                                                      • Opcode Fuzzy Hash: e1418647f15477fc153d24a79e0b4b6c33fe898b344572febf70c5b13b463224
                                                      • Instruction Fuzzy Hash: BFB14E71900129ABDF21EBA4DC89EDEB77DFF49350F1040A6F509E6251EA349A848B61
                                                      APIs
                                                      • GetCurrentProcessId.KERNEL32 ref: 0083A427
                                                      • OpenProcess.KERNEL32(00000410,00000000,00000000), ref: 0083A435
                                                      • GetProcessIoCounters.KERNEL32(00000000,?), ref: 0083A468
                                                      • CloseHandle.KERNEL32(?), ref: 0083A63D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process$CloseCountersCurrentHandleOpen
                                                      • String ID:
                                                      • API String ID: 3488606520-0
                                                      • Opcode ID: 60f922a95c2249ce0db227c371199d53537d4d707d0c83f6ba1aab96960eadcf
                                                      • Instruction ID: e88a837d78b4ac00a62b3dc50a748321c95022841be92e8bd062cacdef286bf5
                                                      • Opcode Fuzzy Hash: 60f922a95c2249ce0db227c371199d53537d4d707d0c83f6ba1aab96960eadcf
                                                      • Instruction Fuzzy Hash: 15A18B71604300AFD724DF24C886F2AB7E5AF84714F14885DF99ADB292DBB4ED41CB92
                                                      APIs
                                                        • Part of subcall function 0081DDE0: GetFullPathNameW.KERNEL32(00000000,00007FFF,?,?,?,?,?,?,0081CF22,?), ref: 0081DDFD
                                                        • Part of subcall function 0081DDE0: GetFullPathNameW.KERNEL32(?,00007FFF,?,?,?,?,?,0081CF22,?), ref: 0081DE16
                                                        • Part of subcall function 0081E199: GetFileAttributesW.KERNEL32(?,0081CF95), ref: 0081E19A
                                                      • lstrcmpiW.KERNEL32(?,?), ref: 0081E473
                                                      • MoveFileW.KERNEL32(?,?), ref: 0081E4AC
                                                      • _wcslen.LIBCMT ref: 0081E5EB
                                                      • _wcslen.LIBCMT ref: 0081E603
                                                      • SHFileOperationW.SHELL32(?,?,?,?,?,?), ref: 0081E650
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: File$FullNamePath_wcslen$AttributesMoveOperationlstrcmpi
                                                      • String ID:
                                                      • API String ID: 3183298772-0
                                                      • Opcode ID: 51147a078b55d69c0d916ce7ce82d8b678ecd426660258f6de41b1658309781f
                                                      • Instruction ID: 26cac6b81c3406e3b3c6c13bf8bc32650a8d8f255ae7dd6e01368d19f0ea68fa
                                                      • Opcode Fuzzy Hash: 51147a078b55d69c0d916ce7ce82d8b678ecd426660258f6de41b1658309781f
                                                      • Instruction Fuzzy Hash: 765162B24087459BC724DBA4DC859DBB3ECEF85340F00491EFA89D3151EF74A688C76A
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 0083C998: CharUpperBuffW.USER32(?,?,?,?,?,?,?,0083B6AE,?,?), ref: 0083C9B5
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083C9F1
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083CA68
                                                        • Part of subcall function 0083C998: _wcslen.LIBCMT ref: 0083CA9E
                                                      • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 0083BAA5
                                                      • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 0083BB00
                                                      • RegEnumKeyExW.ADVAPI32(?,-00000001,?,?,00000000,00000000,00000000,?), ref: 0083BB63
                                                      • RegCloseKey.ADVAPI32(?,?), ref: 0083BBA6
                                                      • RegCloseKey.ADVAPI32(00000000), ref: 0083BBB3
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$Close$BuffCharConnectEnumOpenRegistryUpper
                                                      • String ID:
                                                      • API String ID: 826366716-0
                                                      • Opcode ID: 976e26c04b20bc5a12d954d09e38dc3fbec1d8eeaebcadf6e6dbb938daf35e18
                                                      • Instruction ID: 915a1bf8fdf480946be1e8e1bf6379da5583708308921a02e4bb1aa5b71d09d6
                                                      • Opcode Fuzzy Hash: 976e26c04b20bc5a12d954d09e38dc3fbec1d8eeaebcadf6e6dbb938daf35e18
                                                      • Instruction Fuzzy Hash: D161BE71209241EFC314DF24C494E6ABBE9FF84318F14899CF5998B2A2DB31ED45CB92
                                                      APIs
                                                      • VariantInit.OLEAUT32(?), ref: 00818BCD
                                                      • VariantClear.OLEAUT32 ref: 00818C3E
                                                      • VariantClear.OLEAUT32 ref: 00818C9D
                                                      • VariantClear.OLEAUT32(?), ref: 00818D10
                                                      • VariantChangeType.OLEAUT32(?,?,00000000,00000013), ref: 00818D3B
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Variant$Clear$ChangeInitType
                                                      • String ID:
                                                      • API String ID: 4136290138-0
                                                      • Opcode ID: a192d7347853d5542ce2014cbe6a5da05734a6ca6751ca69ea49e780e344b7ca
                                                      • Instruction ID: 0717e7c583a6d0fa4bff7d2146e98a97055155ff2052df60ec8de89695b084e9
                                                      • Opcode Fuzzy Hash: a192d7347853d5542ce2014cbe6a5da05734a6ca6751ca69ea49e780e344b7ca
                                                      • Instruction Fuzzy Hash: 0A5167B5A00219EFCB10CF68D884AAAB7F8FF89314B158559F909DB350E730E911CF90
                                                      APIs
                                                      • GetPrivateProfileSectionW.KERNEL32(00000003,?,00007FFF,?), ref: 00828BAE
                                                      • GetPrivateProfileSectionW.KERNEL32(?,00000003,00000003,?), ref: 00828BDA
                                                      • WritePrivateProfileSectionW.KERNEL32(?,?,?), ref: 00828C32
                                                      • WritePrivateProfileStringW.KERNEL32(00000003,00000000,00000000,?), ref: 00828C57
                                                      • WritePrivateProfileStringW.KERNEL32(00000000,00000000,00000000,?), ref: 00828C5F
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: PrivateProfile$SectionWrite$String
                                                      • String ID:
                                                      • API String ID: 2832842796-0
                                                      • Opcode ID: 2b984eb55d4475901035b574e47172ee16e081fb628804f5c909e8120298431a
                                                      • Instruction ID: fa45f049807b4b4658e5e3b8ac8dea22e9d34fc12c947db5d23689723375dc57
                                                      • Opcode Fuzzy Hash: 2b984eb55d4475901035b574e47172ee16e081fb628804f5c909e8120298431a
                                                      • Instruction Fuzzy Hash: 75514A35A00215EFCB15DF64C885EA9BBF5FF49314F088498E849AB362DB35ED51CBA0
                                                      APIs
                                                      • LoadLibraryW.KERNEL32(?,00000000,?), ref: 00838F40
                                                      • GetProcAddress.KERNEL32(00000000,?), ref: 00838FD0
                                                      • GetProcAddress.KERNEL32(00000000,00000000), ref: 00838FEC
                                                      • GetProcAddress.KERNEL32(00000000,?), ref: 00839032
                                                      • FreeLibrary.KERNEL32(00000000), ref: 00839052
                                                        • Part of subcall function 007CF6C9: WideCharToMultiByte.KERNEL32(00000000,00000000,?,?,00000000,00000000,00000000,00000000,?,00000000,?,?,?,00821043,?,753CE610), ref: 007CF6E6
                                                        • Part of subcall function 007CF6C9: WideCharToMultiByte.KERNEL32(00000000,00000000,?,?,00000000,0080FA64,00000000,00000000,?,?,00821043,?,753CE610,?,0080FA64), ref: 007CF70D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: AddressProc$ByteCharLibraryMultiWide$FreeLoad
                                                      • String ID:
                                                      • API String ID: 666041331-0
                                                      • Opcode ID: 60b51738f433137863be13f074e00037ba21b3dfdb835d238feef0e5b49281e2
                                                      • Instruction ID: a0350f6636dbbd63f69f6436dd1a36ffdc0ec5de9dcb23ca5d10eb111f0f1044
                                                      • Opcode Fuzzy Hash: 60b51738f433137863be13f074e00037ba21b3dfdb835d238feef0e5b49281e2
                                                      • Instruction Fuzzy Hash: FE514834605205DFCB14DF68C4989ADBBF1FF89314F0480A8E90AAB362DB75ED85CB90
                                                      APIs
                                                      • SetWindowLongW.USER32(00000002,000000F0,?), ref: 00846C33
                                                      • SetWindowLongW.USER32(?,000000EC,?), ref: 00846C4A
                                                      • SendMessageW.USER32(00000002,00001036,00000000,?), ref: 00846C73
                                                      • ShowWindow.USER32(00000002,00000000,00000002,00000002,?,?,?,?,?,?,?,0082AB79,00000000,00000000), ref: 00846C98
                                                      • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000000,00000027,00000002,?,00000001,00000002,00000002,?,?,?), ref: 00846CC7
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Long$MessageSendShow
                                                      • String ID:
                                                      • API String ID: 3688381893-0
                                                      • Opcode ID: 0bd301e41e89acbcd5a0d1cf7fe45fc9cea840b2b52f67f29b0494202971e972
                                                      • Instruction ID: bf290d726349df6672adf69598dc108a22ab4fab9ab384f58dcfef6a0b400646
                                                      • Opcode Fuzzy Hash: 0bd301e41e89acbcd5a0d1cf7fe45fc9cea840b2b52f67f29b0494202971e972
                                                      • Instruction Fuzzy Hash: EB41D935A0410CAFD724CF68CC98FA57BA9FB0B364F150258F895D72E0E771AD61DA41
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free
                                                      • String ID:
                                                      • API String ID: 269201875-0
                                                      • Opcode ID: 0eb78f96a2d8b70f85663c875dd3ea4a588c74c1f7e835f28c071646dbfae687
                                                      • Instruction ID: a2ace22b2959035da55e73dfb98ff87d8fb33481e20233f5ce4637c4b0a496d2
                                                      • Opcode Fuzzy Hash: 0eb78f96a2d8b70f85663c875dd3ea4a588c74c1f7e835f28c071646dbfae687
                                                      • Instruction Fuzzy Hash: FB41E232A01204DFCB24DF79C885A5DB3B9EF89310F1545ADE515EB392EA35EE02CB80
                                                      APIs
                                                      • GetCursorPos.USER32(?), ref: 007C9141
                                                      • ScreenToClient.USER32(00000000,?), ref: 007C915E
                                                      • GetAsyncKeyState.USER32(00000001), ref: 007C9183
                                                      • GetAsyncKeyState.USER32(00000002), ref: 007C919D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: AsyncState$ClientCursorScreen
                                                      • String ID:
                                                      • API String ID: 4210589936-0
                                                      • Opcode ID: c7a1f87ea00286cef786fa22f82dcbcdb86e55a9ef9ba07dfde3bf59a246bcbc
                                                      • Instruction ID: 53753f3889a0405dc13dd51329f2ab2f2b46feab1224bd42bfdc1a860809580f
                                                      • Opcode Fuzzy Hash: c7a1f87ea00286cef786fa22f82dcbcdb86e55a9ef9ba07dfde3bf59a246bcbc
                                                      • Instruction Fuzzy Hash: 0C416C31A0860AFBDF559F68C849BEEB774FB05324F248229E529A32E0C7346950CB91
                                                      APIs
                                                      • GetInputState.USER32 ref: 008238CB
                                                      • TranslateAcceleratorW.USER32(?,00000000,?), ref: 00823922
                                                      • TranslateMessage.USER32(?), ref: 0082394B
                                                      • DispatchMessageW.USER32(?), ref: 00823955
                                                      • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00823966
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Message$Translate$AcceleratorDispatchInputPeekState
                                                      • String ID:
                                                      • API String ID: 2256411358-0
                                                      • Opcode ID: 4894f866e29422d1f4e86404c3d0eb82b22f019ffc277909dcf7b52d18bac3a0
                                                      • Instruction ID: 83b34daef70e1c388b4c92db7a439930e9093cfff362392c97868da0fd45ed9a
                                                      • Opcode Fuzzy Hash: 4894f866e29422d1f4e86404c3d0eb82b22f019ffc277909dcf7b52d18bac3a0
                                                      • Instruction Fuzzy Hash: 6831C6709043659EEF25CB38A869BB67FACFB07304F04056DE462D65A0E7BCA6C5CB11
                                                      APIs
                                                      • InternetQueryDataAvailable.WININET(?,?,00000000,00000000,00000000,?,00000000,?,?,?,0082C21E,00000000), ref: 0082CF38
                                                      • InternetReadFile.WININET(?,00000000,?,?), ref: 0082CF6F
                                                      • GetLastError.KERNEL32(?,00000000,?,?,?,0082C21E,00000000), ref: 0082CFB4
                                                      • SetEvent.KERNEL32(?,?,00000000,?,?,?,0082C21E,00000000), ref: 0082CFC8
                                                      • SetEvent.KERNEL32(?,?,00000000,?,?,?,0082C21E,00000000), ref: 0082CFF2
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: EventInternet$AvailableDataErrorFileLastQueryRead
                                                      • String ID:
                                                      • API String ID: 3191363074-0
                                                      • Opcode ID: 4101f05bc9bef8b04cb31701f682e2626987dc3601f44185d5e31de2c06d7a4e
                                                      • Instruction ID: bc3f59297ca6893e6a1530d6481a83bac904f5691e828558d9d1594bb90b8d49
                                                      • Opcode Fuzzy Hash: 4101f05bc9bef8b04cb31701f682e2626987dc3601f44185d5e31de2c06d7a4e
                                                      • Instruction Fuzzy Hash: 12314C71600615EFDB20DFA5E984ABFBBFAFB15354B10442EF516D2150DBB0AE80DB60
                                                      APIs
                                                      • GetWindowRect.USER32(?,?), ref: 00811915
                                                      • PostMessageW.USER32(00000001,00000201,00000001), ref: 008119C1
                                                      • Sleep.KERNEL32(00000000,?,?,?), ref: 008119C9
                                                      • PostMessageW.USER32(00000001,00000202,00000000), ref: 008119DA
                                                      • Sleep.KERNEL32(00000000,?,?,?,?), ref: 008119E2
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessagePostSleep$RectWindow
                                                      • String ID:
                                                      • API String ID: 3382505437-0
                                                      • Opcode ID: 9ac17af2adc12d955f4c2c8da24d0e2a6d1db0afabe856773213eb118223bd26
                                                      • Instruction ID: 53003239f63097f18dc77db06ff1d4ddf5325693e3a1fbcb74e5d9ae406b500b
                                                      • Opcode Fuzzy Hash: 9ac17af2adc12d955f4c2c8da24d0e2a6d1db0afabe856773213eb118223bd26
                                                      • Instruction Fuzzy Hash: 40318A75A00219AFCB00CFA8C999ADE3BB9FF05315F108229FA21E72D1C7709984CB91
                                                      APIs
                                                      • SendMessageW.USER32(?,00001053,000000FF,?), ref: 00845745
                                                      • SendMessageW.USER32(?,00001074,?,00000001), ref: 0084579D
                                                      • _wcslen.LIBCMT ref: 008457AF
                                                      • _wcslen.LIBCMT ref: 008457BA
                                                      • SendMessageW.USER32(?,00001002,00000000,?), ref: 00845816
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$_wcslen
                                                      • String ID:
                                                      • API String ID: 763830540-0
                                                      • Opcode ID: 1dd6da03817f53a8a0e6af1bad776a351c0ddc6e953d428ac5c19a5d563f32e6
                                                      • Instruction ID: fa9c51b16bf1c031e6374f46f664e51548d8e4c4e0cd00c7353d73df8f0b3b50
                                                      • Opcode Fuzzy Hash: 1dd6da03817f53a8a0e6af1bad776a351c0ddc6e953d428ac5c19a5d563f32e6
                                                      • Instruction Fuzzy Hash: 7C21A57590461CEBDB209F64CC85AEE7BBCFF15328F108226E929EA181D7709985CF50
                                                      APIs
                                                      • GetSysColor.USER32(00000008), ref: 007C98CC
                                                      • SetTextColor.GDI32(?,?), ref: 007C98D6
                                                      • SetBkMode.GDI32(?,00000001), ref: 007C98E9
                                                      • GetStockObject.GDI32(00000005), ref: 007C98F1
                                                      • GetWindowLongW.USER32(?,000000EB), ref: 007C9952
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Color$LongModeObjectStockTextWindow
                                                      • String ID:
                                                      • API String ID: 1860813098-0
                                                      • Opcode ID: c4ed082e7e131905690d74d6f5a63ff9b4ed92afd4dc3dd7b5dcfad2ffd47669
                                                      • Instruction ID: 459d8688670ddd7a197c83ef38b021c48ac8ab32e0af3e4620f31a56cfac5fce
                                                      • Opcode Fuzzy Hash: c4ed082e7e131905690d74d6f5a63ff9b4ed92afd4dc3dd7b5dcfad2ffd47669
                                                      • Instruction Fuzzy Hash: DA2147314462909FCBA24F34EC5CFE53FA4AF67321F09018EE6928B1E2D7396941CB10
                                                      APIs
                                                      • IsWindow.USER32(00000000), ref: 00830951
                                                      • GetForegroundWindow.USER32 ref: 00830968
                                                      • GetDC.USER32(00000000), ref: 008309A4
                                                      • GetPixel.GDI32(00000000,?,00000003), ref: 008309B0
                                                      • ReleaseDC.USER32(00000000,00000003), ref: 008309E8
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$ForegroundPixelRelease
                                                      • String ID:
                                                      • API String ID: 4156661090-0
                                                      • Opcode ID: fad088969bae27dec0015164babe6d7ddea8e4be3ed3f0492359b1ebcb207726
                                                      • Instruction ID: 0aeea945fbd0d7a8874ef899441b9a99aabc184ccc356da6eecc438e4b021767
                                                      • Opcode Fuzzy Hash: fad088969bae27dec0015164babe6d7ddea8e4be3ed3f0492359b1ebcb207726
                                                      • Instruction Fuzzy Hash: A0219239A00214AFD714EF68D848AAEBBE9FF49700F04806DE846D7362CB74AD44CB90
                                                      APIs
                                                      • GetEnvironmentStringsW.KERNEL32 ref: 007ECDC6
                                                      • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 007ECDE9
                                                        • Part of subcall function 007E3820: RtlAllocateHeap.NTDLL(00000000,?,00881444,?,007CFDF5,?,?,007BA976,00000010,00881440,007B13FC,?,007B13C6,?,007B1129), ref: 007E3852
                                                      • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,00000000,?,00000000,00000000), ref: 007ECE0F
                                                      • _free.LIBCMT ref: 007ECE22
                                                      • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 007ECE31
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharEnvironmentMultiStringsWide$AllocateFreeHeap_free
                                                      • String ID:
                                                      • API String ID: 336800556-0
                                                      • Opcode ID: 33aceb5797cb3254fc29298eab8c0a9a4fcdae383b1d93a68b22f95d3662e208
                                                      • Instruction ID: 3f4d337ff001e79b0e2f16a6c807ff4035643e2d2ce196f07aea564aa84c5f84
                                                      • Opcode Fuzzy Hash: 33aceb5797cb3254fc29298eab8c0a9a4fcdae383b1d93a68b22f95d3662e208
                                                      • Instruction Fuzzy Hash: 8E01847A6032957F23261ABB6C8DD7B796DEECBBA1315012DF905D7201EA698D0381B0
                                                      APIs
                                                      • ExtCreatePen.GDI32(?,?,00000000,00000000,00000000,?,00000000), ref: 007C9693
                                                      • SelectObject.GDI32(?,00000000), ref: 007C96A2
                                                      • BeginPath.GDI32(?), ref: 007C96B9
                                                      • SelectObject.GDI32(?,00000000), ref: 007C96E2
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ObjectSelect$BeginCreatePath
                                                      • String ID:
                                                      • API String ID: 3225163088-0
                                                      • Opcode ID: b42091aa466ea46f667b2776bdd57513d1511fca4c010dcca144438f9a1a5a80
                                                      • Instruction ID: 1c4e9ed553ffd97d0fef64e10dfb18dad075f3b0158eb04e6aff39dba5337549
                                                      • Opcode Fuzzy Hash: b42091aa466ea46f667b2776bdd57513d1511fca4c010dcca144438f9a1a5a80
                                                      • Instruction Fuzzy Hash: 58215B30802305EBDF519F68EC1CBA97FACBB51765F50421EF910A61F0DB78A892CB94
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _memcmp
                                                      • String ID:
                                                      • API String ID: 2931989736-0
                                                      • Opcode ID: c7d7e5386ca98366bc7bcdfea1c093dc8d2f8b73e55b4e78a695707d4bc12b90
                                                      • Instruction ID: 25413c5e84caaaa0e60dcf7b542649df44b55df32e25dd2d924a241bb88e8c26
                                                      • Opcode Fuzzy Hash: c7d7e5386ca98366bc7bcdfea1c093dc8d2f8b73e55b4e78a695707d4bc12b90
                                                      • Instruction Fuzzy Hash: 550192A564161DFAE20855109D83EFA635CFFA13A8B404425FE14DA382F664ED9086A0
                                                      APIs
                                                      • GetLastError.KERNEL32(?,?,?,007DF2DE,007E3863,00881444,?,007CFDF5,?,?,007BA976,00000010,00881440,007B13FC,?,007B13C6), ref: 007E2DFD
                                                      • _free.LIBCMT ref: 007E2E32
                                                      • _free.LIBCMT ref: 007E2E59
                                                      • SetLastError.KERNEL32(00000000,007B1129), ref: 007E2E66
                                                      • SetLastError.KERNEL32(00000000,007B1129), ref: 007E2E6F
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorLast$_free
                                                      • String ID:
                                                      • API String ID: 3170660625-0
                                                      • Opcode ID: 1b9756db23e8d1b384e8c3bc0d3fc19be507eaafed595afa77b9696706d23b73
                                                      • Instruction ID: 521cf5eebcaeb6d580a6a3d346326abb610d3a6f98020daf690945c2b78d19fc
                                                      • Opcode Fuzzy Hash: 1b9756db23e8d1b384e8c3bc0d3fc19be507eaafed595afa77b9696706d23b73
                                                      • Instruction Fuzzy Hash: 3001F436207690A7C61227776C4ED2B265DBBCE7A5B214028F425E32A3EA2CCC034520
                                                      APIs
                                                      • CLSIDFromProgID.OLE32(?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?,?,?,0081035E), ref: 0081002B
                                                      • ProgIDFromCLSID.OLE32(?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?,?), ref: 00810046
                                                      • lstrcmpiW.KERNEL32(?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?,?), ref: 00810054
                                                      • CoTaskMemFree.OLE32(00000000,?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?), ref: 00810064
                                                      • CLSIDFromString.OLE32(?,?,?,?,?,00000000,?,?,?,-C000001E,00000001,?,0080FF41,80070057,?,?), ref: 00810070
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: From$Prog$FreeStringTasklstrcmpi
                                                      • String ID:
                                                      • API String ID: 3897988419-0
                                                      • Opcode ID: 96e983b06c80bb4208fd40589a61af3a1b8881d834301e66dc24c616ca5249da
                                                      • Instruction ID: 64bdcb67ccf686346d9b879e84e4b9dc447b9c5ab1003b6c487e764d4845096f
                                                      • Opcode Fuzzy Hash: 96e983b06c80bb4208fd40589a61af3a1b8881d834301e66dc24c616ca5249da
                                                      • Instruction Fuzzy Hash: BE018F7A601608BFDB504F68DC04BEA7AADFF48791F144124F905D2211E7B1DE80CBA0
                                                      APIs
                                                      • QueryPerformanceCounter.KERNEL32(?), ref: 0081E997
                                                      • QueryPerformanceFrequency.KERNEL32(?), ref: 0081E9A5
                                                      • Sleep.KERNEL32(00000000), ref: 0081E9AD
                                                      • QueryPerformanceCounter.KERNEL32(?), ref: 0081E9B7
                                                      • Sleep.KERNEL32 ref: 0081E9F3
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: PerformanceQuery$CounterSleep$Frequency
                                                      • String ID:
                                                      • API String ID: 2833360925-0
                                                      • Opcode ID: 5231acbe761e7f8d81d2d6ec7d405eb1b813db9adbe56b3f7e54c47b760429ce
                                                      • Instruction ID: edec36c4912ebf244bc602849d9cdb259264adeb50844a12292837b97211c565
                                                      • Opcode Fuzzy Hash: 5231acbe761e7f8d81d2d6ec7d405eb1b813db9adbe56b3f7e54c47b760429ce
                                                      • Instruction Fuzzy Hash: 9201203580262DDBCF40ABA4D849AEDBF7CFF0A700F000546E902B2241DB309690CBA2
                                                      APIs
                                                      • GetUserObjectSecurity.USER32(?,00000004,?,00000000,?), ref: 00811114
                                                      • GetLastError.KERNEL32(?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 00811120
                                                      • GetProcessHeap.KERNEL32(00000008,?,?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 0081112F
                                                      • HeapAlloc.KERNEL32(00000000,?,00000000,00000000,?,?,00810B9B,?,?,?), ref: 00811136
                                                      • GetUserObjectSecurity.USER32(?,00000004,00000000,?,?), ref: 0081114D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: HeapObjectSecurityUser$AllocErrorLastProcess
                                                      • String ID:
                                                      • API String ID: 842720411-0
                                                      • Opcode ID: cb6f4c165fb0fb4777619a384924a86f03e72a424da3677912162897220db374
                                                      • Instruction ID: 4948babb6b55032bf9debff093acc5b7f3d2f3789d98eebd645afd4b7d59864a
                                                      • Opcode Fuzzy Hash: cb6f4c165fb0fb4777619a384924a86f03e72a424da3677912162897220db374
                                                      • Instruction Fuzzy Hash: 37011D79101205BFDB514FA5DC4DAAA7B6EFF86364B104419FA45D7360DA31DC40DA60
                                                      APIs
                                                      • GetTokenInformation.ADVAPI32(?,00000002,?,00000000,?), ref: 00810FCA
                                                      • GetLastError.KERNEL32(?,00000002,?,00000000,?), ref: 00810FD6
                                                      • GetProcessHeap.KERNEL32(00000008,?,?,00000002,?,00000000,?), ref: 00810FE5
                                                      • HeapAlloc.KERNEL32(00000000,?,00000002,?,00000000,?), ref: 00810FEC
                                                      • GetTokenInformation.ADVAPI32(?,00000002,00000000,?,?,?,00000002,?,00000000,?), ref: 00811002
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: HeapInformationToken$AllocErrorLastProcess
                                                      • String ID:
                                                      • API String ID: 44706859-0
                                                      • Opcode ID: 567998ea6ecc569b2c923c110b2fb9ce9f7666ecd1e892198d061c37184415d0
                                                      • Instruction ID: ccb2c210ecf68ee371e23e2ba8fff4d4b211dd63b5159a1e00ef72f49331ce83
                                                      • Opcode Fuzzy Hash: 567998ea6ecc569b2c923c110b2fb9ce9f7666ecd1e892198d061c37184415d0
                                                      • Instruction Fuzzy Hash: 62F06D39602701EBDB214FA4DC4DF963BADFF8ABA2F104415FA45C7251CA70DC80CA60
                                                      APIs
                                                      • GetTokenInformation.ADVAPI32(?,00000003(TokenIntegrityLevel),?,00000000,?), ref: 0081102A
                                                      • GetLastError.KERNEL32(?,TokenIntegrityLevel,?,00000000,?), ref: 00811036
                                                      • GetProcessHeap.KERNEL32(00000008,?,?,TokenIntegrityLevel,?,00000000,?), ref: 00811045
                                                      • HeapAlloc.KERNEL32(00000000,?,TokenIntegrityLevel,?,00000000,?), ref: 0081104C
                                                      • GetTokenInformation.ADVAPI32(?,00000003(TokenIntegrityLevel),00000000,?,?,?,TokenIntegrityLevel,?,00000000,?), ref: 00811062
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: HeapInformationToken$AllocErrorLastProcess
                                                      • String ID:
                                                      • API String ID: 44706859-0
                                                      • Opcode ID: 7fe515ebbb15722272c67178beac765ac5fc3883313d04f2c9e8ba271953a579
                                                      • Instruction ID: 2bcc944d465dc3453d9a31218299b08047f1b907c3da8dc3b30b59fb1ac4fd26
                                                      • Opcode Fuzzy Hash: 7fe515ebbb15722272c67178beac765ac5fc3883313d04f2c9e8ba271953a579
                                                      • Instruction Fuzzy Hash: 4CF06D39602701EBDB219FA5EC4DF963BADFF8A761F100415FA45C7250CA70D880CA60
                                                      APIs
                                                      • CloseHandle.KERNEL32(?,?,?,?,0082017D,?,008232FC,?,00000001,007F2592,?), ref: 00820324
                                                      • CloseHandle.KERNEL32(?,?,?,?,0082017D,?,008232FC,?,00000001,007F2592,?), ref: 00820331
                                                      • CloseHandle.KERNEL32(?,?,?,?,0082017D,?,008232FC,?,00000001,007F2592,?), ref: 0082033E
                                                      • CloseHandle.KERNEL32(?,?,?,?,0082017D,?,008232FC,?,00000001,007F2592,?), ref: 0082034B
                                                      • CloseHandle.KERNEL32(?,?,?,?,0082017D,?,008232FC,?,00000001,007F2592,?), ref: 00820358
                                                      • CloseHandle.KERNEL32(?,?,?,?,0082017D,?,008232FC,?,00000001,007F2592,?), ref: 00820365
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID:
                                                      • API String ID: 2962429428-0
                                                      • Opcode ID: df780eb3b1c922f1286d6ed0b8409bec9e61ab02a9f457bb54375860e4e4e8bd
                                                      • Instruction ID: 0c63a696e60e79dc9cb794e17bf8f878aa9cfbcbd47e62372855c1293170ac94
                                                      • Opcode Fuzzy Hash: df780eb3b1c922f1286d6ed0b8409bec9e61ab02a9f457bb54375860e4e4e8bd
                                                      • Instruction Fuzzy Hash: B101A272801B259FC7309F66E880412FBF9FF503153158A3FD19692A32C371A994CF80
                                                      APIs
                                                      • _free.LIBCMT ref: 007ED752
                                                        • Part of subcall function 007E29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000), ref: 007E29DE
                                                        • Part of subcall function 007E29C8: GetLastError.KERNEL32(00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000,00000000), ref: 007E29F0
                                                      • _free.LIBCMT ref: 007ED764
                                                      • _free.LIBCMT ref: 007ED776
                                                      • _free.LIBCMT ref: 007ED788
                                                      • _free.LIBCMT ref: 007ED79A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free$ErrorFreeHeapLast
                                                      • String ID:
                                                      • API String ID: 776569668-0
                                                      • Opcode ID: b69ccbe27691a6ec38b43fee12e742f1ca277f1da36e9e5f952b85330fe1c2ec
                                                      • Instruction ID: bd6ebfb9ac73924f51d1c557277c2270fc09ce7cbed4464583d9af027d63b1f6
                                                      • Opcode Fuzzy Hash: b69ccbe27691a6ec38b43fee12e742f1ca277f1da36e9e5f952b85330fe1c2ec
                                                      • Instruction Fuzzy Hash: D7F01232546288AB8671EB66F9CAC1A7BDDBB4C710B951819F058E7517C73CFCC08A64
                                                      APIs
                                                      • GetDlgItem.USER32(?,000003E9), ref: 00815C58
                                                      • GetWindowTextW.USER32(00000000,?,00000100), ref: 00815C6F
                                                      • MessageBeep.USER32(00000000), ref: 00815C87
                                                      • KillTimer.USER32(?,0000040A), ref: 00815CA3
                                                      • EndDialog.USER32(?,00000001), ref: 00815CBD
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: BeepDialogItemKillMessageTextTimerWindow
                                                      • String ID:
                                                      • API String ID: 3741023627-0
                                                      • Opcode ID: 16a0ae5c4d2fb85fe2779daa1bf284a94340040d0ceeb1ee761a69c692672ea0
                                                      • Instruction ID: 627e3dc209650ed2377011df1c5101c19bfdd2a64e2d2a11bb0c088bb66bd2da
                                                      • Opcode Fuzzy Hash: 16a0ae5c4d2fb85fe2779daa1bf284a94340040d0ceeb1ee761a69c692672ea0
                                                      • Instruction Fuzzy Hash: D6016D74501B04EBEB205F50DD5EFE677BCFF51B05F010559A692A10E1DBF4AA84CA90
                                                      APIs
                                                      • _free.LIBCMT ref: 007E22BE
                                                        • Part of subcall function 007E29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000), ref: 007E29DE
                                                        • Part of subcall function 007E29C8: GetLastError.KERNEL32(00000000,?,007ED7D1,00000000,00000000,00000000,00000000,?,007ED7F8,00000000,00000007,00000000,?,007EDBF5,00000000,00000000), ref: 007E29F0
                                                      • _free.LIBCMT ref: 007E22D0
                                                      • _free.LIBCMT ref: 007E22E3
                                                      • _free.LIBCMT ref: 007E22F4
                                                      • _free.LIBCMT ref: 007E2305
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free$ErrorFreeHeapLast
                                                      • String ID:
                                                      • API String ID: 776569668-0
                                                      • Opcode ID: 472bfd149c02a6b76c73b535e97fe7867db6861468b3eff27b41f24d0901512c
                                                      • Instruction ID: cd97b96eb10b8c821550071798ada21c1691fc384d3c32d3a7ed59b2041cd924
                                                      • Opcode Fuzzy Hash: 472bfd149c02a6b76c73b535e97fe7867db6861468b3eff27b41f24d0901512c
                                                      • Instruction Fuzzy Hash: 1CF030714021548B8A22AF59BC0A8083B6CFB1C760702551AF514E72B7CB3854539FA5
                                                      APIs
                                                      • EndPath.GDI32(?), ref: 007C95D4
                                                      • StrokeAndFillPath.GDI32(?,?,008071F7,00000000,?,?,?), ref: 007C95F0
                                                      • SelectObject.GDI32(?,00000000), ref: 007C9603
                                                      • DeleteObject.GDI32 ref: 007C9616
                                                      • StrokePath.GDI32(?), ref: 007C9631
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Path$ObjectStroke$DeleteFillSelect
                                                      • String ID:
                                                      • API String ID: 2625713937-0
                                                      • Opcode ID: 6eb0c816d0a68dbc80c67721d84fa3572191dbeab04b35dca851d55096734527
                                                      • Instruction ID: 1e9463c47b0783279e18cc86912bea91b78c9048441a6df0216494a48cf85610
                                                      • Opcode Fuzzy Hash: 6eb0c816d0a68dbc80c67721d84fa3572191dbeab04b35dca851d55096734527
                                                      • Instruction Fuzzy Hash: C7F04934006A08EBDFA65F69ED1CBA43F69BB02322F448218F525650F0DB3499A2DF20
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: __freea$_free
                                                      • String ID: a/p$am/pm
                                                      • API String ID: 3432400110-3206640213
                                                      • Opcode ID: 98798344badbd48bda0d0f144e126e0b5095605fee537814fbbcf2a6dcf91ed8
                                                      • Instruction ID: 3db4e4a99945eb99a5924fc0ee9c9661e8a8a4c076818f38f0d67e60aeb86a7a
                                                      • Opcode Fuzzy Hash: 98798344badbd48bda0d0f144e126e0b5095605fee537814fbbcf2a6dcf91ed8
                                                      • Instruction Fuzzy Hash: 2DD11771A02285CACB249F6AC85BBFEB7B5FF0E300FA44159E6019B654D37D9D80CB91
                                                      APIs
                                                        • Part of subcall function 007D0242: EnterCriticalSection.KERNEL32(0088070C,00881884,?,?,007C198B,00882518,?,?,?,007B12F9,00000000), ref: 007D024D
                                                        • Part of subcall function 007D0242: LeaveCriticalSection.KERNEL32(0088070C,?,007C198B,00882518,?,?,?,007B12F9,00000000), ref: 007D028A
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 007D00A3: __onexit.LIBCMT ref: 007D00A9
                                                      • __Init_thread_footer.LIBCMT ref: 00837BFB
                                                        • Part of subcall function 007D01F8: EnterCriticalSection.KERNEL32(0088070C,?,?,007C8747,00882514), ref: 007D0202
                                                        • Part of subcall function 007D01F8: LeaveCriticalSection.KERNEL32(0088070C,?,007C8747,00882514), ref: 007D0235
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CriticalSection$EnterLeave$Init_thread_footer__onexit_wcslen
                                                      • String ID: 5$G$Variable must be of type 'Object'.
                                                      • API String ID: 535116098-3733170431
                                                      • Opcode ID: 66a08e135c1d1e6d268eee57146bbd1769b425eb253d553f9993e53c73791bb7
                                                      • Instruction ID: 6cad68b10ba1a0657eed0d5186ee161fd164dd21ed18c516b8b9852417ea3775
                                                      • Opcode Fuzzy Hash: 66a08e135c1d1e6d268eee57146bbd1769b425eb253d553f9993e53c73791bb7
                                                      • Instruction Fuzzy Hash: 65917CB0A04209EFCB24EF98D8959ADB7B1FF85304F108059F806DB292DB75EE45CB91
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: JO{
                                                      • API String ID: 0-846867066
                                                      • Opcode ID: db4b4780b453edcbef913ad2e4f8ff9962b886cba1727ce5e0cb94b67ae62a1b
                                                      • Instruction ID: 79a090f00dfc20f44a4340e164f320a29d4891ace195dfdb7bcb15e5fb5ce256
                                                      • Opcode Fuzzy Hash: db4b4780b453edcbef913ad2e4f8ff9962b886cba1727ce5e0cb94b67ae62a1b
                                                      • Instruction Fuzzy Hash: AD51D771D0268EDFCB119FA6C849FAE7BB4BF0D318F14005AF405A72A2D6799901CB61
                                                      APIs
                                                      • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,00000002,00000000,?,?,?,00000000,?,?,?,?), ref: 007E8B6E
                                                      • GetLastError.KERNEL32(?,?,00000000,?,?,?,?,?,?,?,?,00000000,00001000,?), ref: 007E8B7A
                                                      • __dosmaperr.LIBCMT ref: 007E8B81
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharErrorLastMultiWide__dosmaperr
                                                      • String ID: .}
                                                      • API String ID: 2434981716-2266125135
                                                      • Opcode ID: d46a6e18b7d10b955ebdf18155fa8791c0d367eb3b81288f56b547a0cad9b8e8
                                                      • Instruction ID: 2bd3054b87ab96cd1e0d88641f715f099e9ff838e6c2bbe03631b14d30f6a939
                                                      • Opcode Fuzzy Hash: d46a6e18b7d10b955ebdf18155fa8791c0d367eb3b81288f56b547a0cad9b8e8
                                                      • Instruction Fuzzy Hash: F8417EF06051C5AFC7659F5AC880A7D7FA6EF8D304B1881AAF45D8B242DE35CC02C751
                                                      APIs
                                                        • Part of subcall function 0081B403: WriteProcessMemory.KERNEL32(?,?,?,00000000,00000000,00000000,?,008121D0,?,?,00000034,00000800,?,00000034), ref: 0081B42D
                                                      • SendMessageW.USER32(?,00001104,00000000,00000000), ref: 00812760
                                                        • Part of subcall function 0081B3CE: ReadProcessMemory.KERNEL32(?,?,?,00000000,00000000,00000000,?,008121FF,?,?,00000800,?,00001073,00000000,?,?), ref: 0081B3F8
                                                        • Part of subcall function 0081B32A: GetWindowThreadProcessId.USER32(?,?), ref: 0081B355
                                                        • Part of subcall function 0081B32A: OpenProcess.KERNEL32(00000438,00000000,?,?,?,00812194,00000034,?,?,00001004,00000000,00000000), ref: 0081B365
                                                        • Part of subcall function 0081B32A: VirtualAllocEx.KERNEL32(00000000,00000000,?,00001000,00000004,?,?,00812194,00000034,?,?,00001004,00000000,00000000), ref: 0081B37B
                                                      • SendMessageW.USER32(?,00001111,00000000,00000000), ref: 008127CD
                                                      • SendMessageW.USER32(?,00001111,00000000,00000000), ref: 0081281A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process$MessageSend$Memory$AllocOpenReadThreadVirtualWindowWrite
                                                      • String ID: @
                                                      • API String ID: 4150878124-2766056989
                                                      • Opcode ID: 1cf53c891e77df89c195903dfc5316426fe48ed5dadcc877db4e6a7f0bf23a84
                                                      • Instruction ID: 667b42cc3c2581723e5112010567061f9352b72673e8ad9c43916afa68b1c857
                                                      • Opcode Fuzzy Hash: 1cf53c891e77df89c195903dfc5316426fe48ed5dadcc877db4e6a7f0bf23a84
                                                      • Instruction Fuzzy Hash: 63410E76900218AFDB10DFA8CD85ADEBBB8FF09700F108099FA55B7181DB706E95CB61
                                                      APIs
                                                      • GetModuleFileNameW.KERNEL32(00000000,C:\Users\user\Desktop\file.exe,00000104), ref: 007E1769
                                                      • _free.LIBCMT ref: 007E1834
                                                      • _free.LIBCMT ref: 007E183E
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free$FileModuleName
                                                      • String ID: C:\Users\user\Desktop\file.exe
                                                      • API String ID: 2506810119-1957095476
                                                      • Opcode ID: c60b4b2e19d71f017cd5cf9c9ca7eb3fb29e52fa69ab0629d7c72ab802417951
                                                      • Instruction ID: a0fd80694d2f3a71f29ce4c1abd4ed44b8140ca84823a14b1729bd03d08485c0
                                                      • Opcode Fuzzy Hash: c60b4b2e19d71f017cd5cf9c9ca7eb3fb29e52fa69ab0629d7c72ab802417951
                                                      • Instruction Fuzzy Hash: 9931C271A01298EFCB21DB9A9C8AD9EBBFCEF89720B504166F404D7211D7749E41CB90
                                                      APIs
                                                      • GetMenuItemInfoW.USER32(00000004,00000000,00000000,?), ref: 0081C306
                                                      • DeleteMenu.USER32(?,00000007,00000000), ref: 0081C34C
                                                      • DeleteMenu.USER32(?,00000000,00000000,?,00000000,00000000,00881990,017356B0), ref: 0081C395
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Menu$Delete$InfoItem
                                                      • String ID: 0
                                                      • API String ID: 135850232-4108050209
                                                      • Opcode ID: c313f3190f4823057509d40e889098223ec995e6ca8d8f40c877ca769163f721
                                                      • Instruction ID: 4a42474d967ae21da25cfcc707abacc5cb04267dab61fcf0dce14183c7c1ebaa
                                                      • Opcode Fuzzy Hash: c313f3190f4823057509d40e889098223ec995e6ca8d8f40c877ca769163f721
                                                      • Instruction Fuzzy Hash: 5341AD312443019FD724DF29D884B9ABBE8FF85324F008A1EF9A5D7391D730A985CB62
                                                      APIs
                                                      • SetWindowPos.USER32(00000000,00000000,00000000,00000000,00000000,00000000,00000013,?,?,SysTreeView32,0084CC08,00000000,?,?,?,?), ref: 008444AA
                                                      • GetWindowLongW.USER32 ref: 008444C7
                                                      • SetWindowLongW.USER32(?,000000F0,00000000), ref: 008444D7
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Long
                                                      • String ID: SysTreeView32
                                                      • API String ID: 847901565-1698111956
                                                      • Opcode ID: 52808132590bf9e2a57b25bb5eced0ced1c14ba158a16bd354e300b9e096eed3
                                                      • Instruction ID: 678c2a2f8208d07a7f7510120fe2889aac02b48f39ad2e0540155f51894a3524
                                                      • Opcode Fuzzy Hash: 52808132590bf9e2a57b25bb5eced0ced1c14ba158a16bd354e300b9e096eed3
                                                      • Instruction Fuzzy Hash: B7319C32201209ABDF209E38DC45BEA7BA9FB08334F219329F979E21D0D774EC509B50
                                                      APIs
                                                        • Part of subcall function 0083335B: WideCharToMultiByte.KERNEL32(00000000,00000000,?,?,00000000,00000000,00000000,00000000,?,?,?,?,?,00833077,?,?), ref: 00833378
                                                      • inet_addr.WSOCK32(?), ref: 0083307A
                                                      • _wcslen.LIBCMT ref: 0083309B
                                                      • htons.WSOCK32(00000000), ref: 00833106
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharMultiWide_wcslenhtonsinet_addr
                                                      • String ID: 255.255.255.255
                                                      • API String ID: 946324512-2422070025
                                                      • Opcode ID: 43439361629196dba8ee1a38035ea421ab47a523dacf2b87cfc29215e0f4e42c
                                                      • Instruction ID: 1c35f26416379ed4bb949ce7da4d8c9fa5caf21feb0274e9bbfe3d4d2330df1b
                                                      • Opcode Fuzzy Hash: 43439361629196dba8ee1a38035ea421ab47a523dacf2b87cfc29215e0f4e42c
                                                      • Instruction Fuzzy Hash: 4031B039604605DFCB24CF68C595AAA77E0FF94318F248059E915CB3A2DB72EE45C7A0
                                                      APIs
                                                      • SendMessageW.USER32(00000000,00001009,00000000,?), ref: 00843F40
                                                      • SetWindowPos.USER32(?,00000000,?,?,?,?,00000004), ref: 00843F54
                                                      • SendMessageW.USER32(?,00001002,00000000,?), ref: 00843F78
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$Window
                                                      • String ID: SysMonthCal32
                                                      • API String ID: 2326795674-1439706946
                                                      • Opcode ID: 85439976975d445f7486fb9a8b411f8c13875e0c0f436af981f40ef5680dba5f
                                                      • Instruction ID: 44d0af4b02267bb7c0b32a61af1e5b3b1c41195c778b067b962fa4f5c5e83f2d
                                                      • Opcode Fuzzy Hash: 85439976975d445f7486fb9a8b411f8c13875e0c0f436af981f40ef5680dba5f
                                                      • Instruction Fuzzy Hash: 2321BC32600219BBDF219F94DC46FEA3B79FF48728F110214FE15AB1D0DAB5A854CBA0
                                                      APIs
                                                      • SendMessageW.USER32(00000000,00000469,?,00000000), ref: 00844705
                                                      • SendMessageW.USER32(00000000,00000465,00000000,80017FFF), ref: 00844713
                                                      • DestroyWindow.USER32(00000000,00000000,?,?,?,00000000,msctls_updown32,00000000,00000000,00000000,00000000,00000000,00000000,?,?,00000000), ref: 0084471A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$DestroyWindow
                                                      • String ID: msctls_updown32
                                                      • API String ID: 4014797782-2298589950
                                                      • Opcode ID: 1665c2315baae876d40db1625875509403ae9e949d2281dab25a0b37a9c37495
                                                      • Instruction ID: a576bc07c0e531e035fb7637e39ad36ca8bf837efffc3141a1335f1b97ab0764
                                                      • Opcode Fuzzy Hash: 1665c2315baae876d40db1625875509403ae9e949d2281dab25a0b37a9c37495
                                                      • Instruction Fuzzy Hash: 93214CB560020DAFEB10DF68DC85EA737ADFB5A394B050059FA15DB351CB34EC12CA60
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen
                                                      • String ID: #OnAutoItStartRegister$#notrayicon$#requireadmin
                                                      • API String ID: 176396367-2734436370
                                                      • Opcode ID: 82b2bc4142944ed2496f4d944823270937b1d51264a430e921d53c122f974ed4
                                                      • Instruction ID: c6fd24059aa02734bf3c7c14bc548ab0e3f2c20839342834fe7621f9b4ea49f3
                                                      • Opcode Fuzzy Hash: 82b2bc4142944ed2496f4d944823270937b1d51264a430e921d53c122f974ed4
                                                      • Instruction Fuzzy Hash: 74215B32104514A6D331AB24DC26FF773EDFFA1314F50402AF99AE7142EB59ADC1C2A5
                                                      APIs
                                                      • SendMessageW.USER32(00000000,00000180,00000000,?), ref: 00843840
                                                      • SendMessageW.USER32(?,00000186,00000000,00000000), ref: 00843850
                                                      • MoveWindow.USER32(00000000,?,?,?,?,00000000,?,?,Listbox,00000000,00000000,?,?,?,?,?), ref: 00843876
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend$MoveWindow
                                                      • String ID: Listbox
                                                      • API String ID: 3315199576-2633736733
                                                      • Opcode ID: f29e4770825a1aaa6f1549ae238ac7c92cf446dcfe312e45bf2ceb6e67f85814
                                                      • Instruction ID: 2ca54342396679de7e0696ffc64cd80124c3b7fb04e23d79aa855f5d3a1e9d10
                                                      • Opcode Fuzzy Hash: f29e4770825a1aaa6f1549ae238ac7c92cf446dcfe312e45bf2ceb6e67f85814
                                                      • Instruction Fuzzy Hash: 5C21BE7260021CBBEF219F54CC85FAB7B6EFF89764F108124F9449B190CA75DC5287A0
                                                      APIs
                                                      • SetErrorMode.KERNEL32(00000001), ref: 00824A08
                                                      • GetVolumeInformationW.KERNEL32(?,?,00007FFF,?,00000000,00000000,00000000,00000000), ref: 00824A5C
                                                      • SetErrorMode.KERNEL32(00000000,?,?,0084CC08), ref: 00824AD0
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorMode$InformationVolume
                                                      • String ID: %lu
                                                      • API String ID: 2507767853-685833217
                                                      • Opcode ID: 230fdffe052b330e5cb6c6c4761f7ac9f27bea84096d0347f6a16eb042cc4470
                                                      • Instruction ID: a5bb1de06864e3dba977b6e363c4ab67559932025201e3dba44c93468f5fd2ec
                                                      • Opcode Fuzzy Hash: 230fdffe052b330e5cb6c6c4761f7ac9f27bea84096d0347f6a16eb042cc4470
                                                      • Instruction Fuzzy Hash: 1F313E75A00219EFDB10DF64C885EAA7BF8FF09308F1480A9E909DB252D775EE45CB61
                                                      APIs
                                                      • SendMessageW.USER32(00000000,00000405,00000000,00000000), ref: 0084424F
                                                      • SendMessageW.USER32(?,00000406,00000000,00640000), ref: 00844264
                                                      • SendMessageW.USER32(?,00000414,0000000A,00000000), ref: 00844271
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend
                                                      • String ID: msctls_trackbar32
                                                      • API String ID: 3850602802-1010561917
                                                      • Opcode ID: 52fa0a5feae4908afdc35cd9b845dcb3983bb6329d7fb6f835eda5ee8b94b8af
                                                      • Instruction ID: fd4c9d430e0483fbc0d19a81c24f16447997f07d4de477dfa704de68f15cdca4
                                                      • Opcode Fuzzy Hash: 52fa0a5feae4908afdc35cd9b845dcb3983bb6329d7fb6f835eda5ee8b94b8af
                                                      • Instruction Fuzzy Hash: F811A03124024CBEEF205E69CC06FAB3BACFF95B64F114624FA55E60A0D6B1D8519B20
                                                      APIs
                                                        • Part of subcall function 007B6B57: _wcslen.LIBCMT ref: 007B6B6A
                                                        • Part of subcall function 00812DA7: SendMessageTimeoutW.USER32(?,00000000,00000000,00000000,00000002,00001388,?), ref: 00812DC5
                                                        • Part of subcall function 00812DA7: GetWindowThreadProcessId.USER32(?,00000000), ref: 00812DD6
                                                        • Part of subcall function 00812DA7: GetCurrentThreadId.KERNEL32 ref: 00812DDD
                                                        • Part of subcall function 00812DA7: AttachThreadInput.USER32(00000000,?,00000000,00000000), ref: 00812DE4
                                                      • GetFocus.USER32 ref: 00812F78
                                                        • Part of subcall function 00812DEE: GetParent.USER32(00000000), ref: 00812DF9
                                                      • GetClassNameW.USER32(?,?,00000100), ref: 00812FC3
                                                      • EnumChildWindows.USER32(?,0081303B), ref: 00812FEB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Thread$AttachChildClassCurrentEnumFocusInputMessageNameParentProcessSendTimeoutWindowWindows_wcslen
                                                      • String ID: %s%d
                                                      • API String ID: 1272988791-1110647743
                                                      • Opcode ID: 7605e713fbe674ab2f0055302b50a4e49f4aff4dfee9a38fcc9cb182caac3481
                                                      • Instruction ID: 6d864dc5c5774d7c430060042c3e1e0f4e23c3d1d4aab316c091cbe00412f79b
                                                      • Opcode Fuzzy Hash: 7605e713fbe674ab2f0055302b50a4e49f4aff4dfee9a38fcc9cb182caac3481
                                                      • Instruction Fuzzy Hash: 0811C0B5200209ABCF446F64DC99FEE37AEFF98304F048079B909DB252DE3499858B70
                                                      APIs
                                                      • GetMenuItemInfoW.USER32(?,?,?,00000030), ref: 008458C1
                                                      • SetMenuItemInfoW.USER32(?,?,?,00000030), ref: 008458EE
                                                      • DrawMenuBar.USER32(?), ref: 008458FD
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Menu$InfoItem$Draw
                                                      • String ID: 0
                                                      • API String ID: 3227129158-4108050209
                                                      • Opcode ID: ef89c0a736d63e01c89feb787392cf19c2d6ccc178ab7829fe7ac453c9ea2b9f
                                                      • Instruction ID: 7aceac91597fe60d071b630399a89228b7d90c313046ff354b747c3d9f79646c
                                                      • Opcode Fuzzy Hash: ef89c0a736d63e01c89feb787392cf19c2d6ccc178ab7829fe7ac453c9ea2b9f
                                                      • Instruction Fuzzy Hash: DE016D3150121CEFDB619F11EC48BAEBFB9FB45764F108099E849DA152EB348A84EF21
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: f7d1563dfdedfb384480aa6b12b83faa3fe602aea29808be2f7e8236cb936180
                                                      • Instruction ID: a866da967c318a4f187228eb2b4e7c0d2a871cc6cb3fb0c5c370d03d6d2ce90d
                                                      • Opcode Fuzzy Hash: f7d1563dfdedfb384480aa6b12b83faa3fe602aea29808be2f7e8236cb936180
                                                      • Instruction Fuzzy Hash: 86C13A75A0020AEFDB15CFA8C894AAEB7B9FF48704F208598E515EB251D771EDC1CB90
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Variant$ClearInitInitializeUninitialize
                                                      • String ID:
                                                      • API String ID: 1998397398-0
                                                      • Opcode ID: 75b7353d982eb1e510f8e53a2ef54d8a8db8d23973a5207a08eea0dae982b883
                                                      • Instruction ID: 92ce67a49cefdf139c223b5cde8093c237f6fd10137c43dda0d27d38cd258d19
                                                      • Opcode Fuzzy Hash: 75b7353d982eb1e510f8e53a2ef54d8a8db8d23973a5207a08eea0dae982b883
                                                      • Instruction Fuzzy Hash: 23A10575604200DFC714DF28C58AA6AB7E5FF89714F048859F98ADB362DB34EE41CB92
                                                      APIs
                                                      • ProgIDFromCLSID.OLE32(?,00000000,?,00000000,00000800,00000000,?,0084FC08,?), ref: 008105F0
                                                      • CoTaskMemFree.OLE32(00000000,00000000,?,00000000,00000800,00000000,?,0084FC08,?), ref: 00810608
                                                      • CLSIDFromProgID.OLE32(?,?,00000000,0084CC40,000000FF,?,00000000,00000800,00000000,?,0084FC08,?), ref: 0081062D
                                                      • _memcmp.LIBVCRUNTIME ref: 0081064E
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FromProg$FreeTask_memcmp
                                                      • String ID:
                                                      • API String ID: 314563124-0
                                                      • Opcode ID: c65a2eaed473acbcabbf1b14353dca9d19b167a6e3a89d09569248e735c725f5
                                                      • Instruction ID: 6dc64e35e544a9c4072dd6513a524f173a7db8d840d7a988e65c304a5456cd02
                                                      • Opcode Fuzzy Hash: c65a2eaed473acbcabbf1b14353dca9d19b167a6e3a89d09569248e735c725f5
                                                      • Instruction Fuzzy Hash: 2481B775A00209EFCB04DF94C984AEEB7B9FF89315F204558E516EB250DB71AE86CF60
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _free
                                                      • String ID:
                                                      • API String ID: 269201875-0
                                                      • Opcode ID: e204988bb32e63fe7620c2732fb3bf5e134e094ab50f2c1225211a3016b20148
                                                      • Instruction ID: f3aa2bdd580eb7ddab53caec05328eafaf2aee629d84bff199b61a06b2966724
                                                      • Opcode Fuzzy Hash: e204988bb32e63fe7620c2732fb3bf5e134e094ab50f2c1225211a3016b20148
                                                      • Instruction Fuzzy Hash: C441313250018CEBDB256BFD9C496BE3AB4FF85370F544226F619D7392E63C48415671
                                                      APIs
                                                      • GetWindowRect.USER32(?,?), ref: 008462E2
                                                      • ScreenToClient.USER32(?,?), ref: 00846315
                                                      • MoveWindow.USER32(?,?,?,?,000000FF,00000001,?,?,?,?,?), ref: 00846382
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$ClientMoveRectScreen
                                                      • String ID:
                                                      • API String ID: 3880355969-0
                                                      • Opcode ID: 2828b9dcdc0ff39fcd2a647ef75036aed9943d27a0681dfa6a50cc024acf4ee1
                                                      • Instruction ID: bb55c95fea430547b117a4c240ea1e73ca96b1ca5a051c331e0bd50b3f548383
                                                      • Opcode Fuzzy Hash: 2828b9dcdc0ff39fcd2a647ef75036aed9943d27a0681dfa6a50cc024acf4ee1
                                                      • Instruction Fuzzy Hash: 0A513A74A00249EFCF14DF68D884AAE7BB5FB46364F108259F815DB290E770ED91CB51
                                                      APIs
                                                      • socket.WSOCK32(00000002,00000002,00000011), ref: 00831AFD
                                                      • WSAGetLastError.WSOCK32 ref: 00831B0B
                                                      • #21.WSOCK32(?,0000FFFF,00000020,00000002,00000004), ref: 00831B8A
                                                      • WSAGetLastError.WSOCK32 ref: 00831B94
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorLast$socket
                                                      • String ID:
                                                      • API String ID: 1881357543-0
                                                      • Opcode ID: 6665deaf2a74a8f154abda4d0dcd73083c38112c0f1c769ecec0018287a561a9
                                                      • Instruction ID: edd746a5e746f2c5cc8df41684abfb45bdde96bb1e0a2ce7b018a806f65d2597
                                                      • Opcode Fuzzy Hash: 6665deaf2a74a8f154abda4d0dcd73083c38112c0f1c769ecec0018287a561a9
                                                      • Instruction Fuzzy Hash: 0E419035600200AFEB20AF24C88AF6677E5EB85718F54849CFA1A9F2D2D776DD41CBD0
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 9108068d1149ba4d5a2882e77cbfdcb03d7c964b29cede1f05f572c0f4e29ca0
                                                      • Instruction ID: 17ec7b6c3e38fc777425bb7cecab36a53ab7f859e837c94d787e9d951dba0b42
                                                      • Opcode Fuzzy Hash: 9108068d1149ba4d5a2882e77cbfdcb03d7c964b29cede1f05f572c0f4e29ca0
                                                      • Instruction Fuzzy Hash: 2741E4B2A01384EFD7249F79CC45B6BBFA9EB8D710F10452AF542DB2C2D779A9118780
                                                      APIs
                                                      • CreateHardLinkW.KERNEL32(00000002,?,00000000), ref: 00825783
                                                      • GetLastError.KERNEL32(?,00000000), ref: 008257A9
                                                      • DeleteFileW.KERNEL32(00000002,?,00000000), ref: 008257CE
                                                      • CreateHardLinkW.KERNEL32(00000002,?,00000000,?,00000000), ref: 008257FA
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CreateHardLink$DeleteErrorFileLast
                                                      • String ID:
                                                      • API String ID: 3321077145-0
                                                      • Opcode ID: 98d15047776dfd438f62c5f904add460fbdc1dd46be7705f111a0fc12e407fe0
                                                      • Instruction ID: c7ba3682f19bdefb39a0457eb554ffafce1564d766c87f88b9f208be4261ab9e
                                                      • Opcode Fuzzy Hash: 98d15047776dfd438f62c5f904add460fbdc1dd46be7705f111a0fc12e407fe0
                                                      • Instruction Fuzzy Hash: 58412B39600610DFCB25DF15C445A5EBBE6FF89320B18C498E84AAB762CB74FD40CB91
                                                      APIs
                                                      • MultiByteToWideChar.KERNEL32(?,00000000,?,007D6D71,00000000,00000000,007D82D9,?,007D82D9,?,00000001,007D6D71,?,00000001,007D82D9,007D82D9), ref: 007ED910
                                                      • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 007ED999
                                                      • GetStringTypeW.KERNEL32(?,00000000,00000000,?), ref: 007ED9AB
                                                      • __freea.LIBCMT ref: 007ED9B4
                                                        • Part of subcall function 007E3820: RtlAllocateHeap.NTDLL(00000000,?,00881444,?,007CFDF5,?,?,007BA976,00000010,00881440,007B13FC,?,007B13C6,?,007B1129), ref: 007E3852
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharMultiWide$AllocateHeapStringType__freea
                                                      • String ID:
                                                      • API String ID: 2652629310-0
                                                      • Opcode ID: a8d5c3998b6dea91c73d238f89002388254ce34ab4ff39e2401e3b881ae8f801
                                                      • Instruction ID: 62d11487300ae86361eefad162754f9d9428c169aa3a29dc2cd312f2552c3e88
                                                      • Opcode Fuzzy Hash: a8d5c3998b6dea91c73d238f89002388254ce34ab4ff39e2401e3b881ae8f801
                                                      • Instruction Fuzzy Hash: AD31FE72A0124AABDF24CF66DC45EAE7BA5EF45310F054169FC04DB252EB39ED50CBA0
                                                      APIs
                                                      • SendMessageW.USER32(?,00001024,00000000,?), ref: 00845352
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00845375
                                                      • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00845382
                                                      • InvalidateRect.USER32(?,00000000,00000001,?,?,?), ref: 008453A8
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: LongWindow$InvalidateMessageRectSend
                                                      • String ID:
                                                      • API String ID: 3340791633-0
                                                      • Opcode ID: e62ed31fd5d1e050d23eba2cf42c4e8730d469434b17556289a5c05035504dc3
                                                      • Instruction ID: 1155d0d8da569597d5be3e2e3f786d0f05c4c3c0c44215608415496398a0ba32
                                                      • Opcode Fuzzy Hash: e62ed31fd5d1e050d23eba2cf42c4e8730d469434b17556289a5c05035504dc3
                                                      • Instruction Fuzzy Hash: D7319E34A55A0CEFEB209E14CC19BED77A5FB06394F584145FA11D63E2C7B49D40DB41
                                                      APIs
                                                      • GetKeyboardState.USER32(?,75C0C0D0,?,00008000), ref: 0081ABF1
                                                      • SetKeyboardState.USER32(00000080,?,00008000), ref: 0081AC0D
                                                      • PostMessageW.USER32(00000000,00000101,00000000), ref: 0081AC74
                                                      • SendInput.USER32(00000001,?,0000001C,75C0C0D0,?,00008000), ref: 0081ACC6
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: KeyboardState$InputMessagePostSend
                                                      • String ID:
                                                      • API String ID: 432972143-0
                                                      • Opcode ID: 32992018e734a913a8e53b8ba64cb2e32f1250e21b4bcc7aea413c9b6f1279a0
                                                      • Instruction ID: 6f33f02a91c2618ca841ad655a6c3c4291f9daa839fc37c28b1edfc861fe1440
                                                      • Opcode Fuzzy Hash: 32992018e734a913a8e53b8ba64cb2e32f1250e21b4bcc7aea413c9b6f1279a0
                                                      • Instruction Fuzzy Hash: 1E31F270A02618AFEB39CB69C8047FA7BAEFF89310F04421AE485D22D1D37589C587D2
                                                      APIs
                                                      • ClientToScreen.USER32(?,?), ref: 0084769A
                                                      • GetWindowRect.USER32(?,?), ref: 00847710
                                                      • PtInRect.USER32(?,?,00848B89), ref: 00847720
                                                      • MessageBeep.USER32(00000000), ref: 0084778C
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Rect$BeepClientMessageScreenWindow
                                                      • String ID:
                                                      • API String ID: 1352109105-0
                                                      • Opcode ID: ee4ace036fc9b6b76380c39d2c90543b1b0013ae8466de1f196d4961695f139d
                                                      • Instruction ID: 2192f2049da4cba4b1fbd9aed070848eecea182820d74dfd39f7364943461e58
                                                      • Opcode Fuzzy Hash: ee4ace036fc9b6b76380c39d2c90543b1b0013ae8466de1f196d4961695f139d
                                                      • Instruction Fuzzy Hash: 3F41A038605259DFDB11CF58C898EA9BBF9FF49314F9680A9E414DB261C730E942CF90
                                                      APIs
                                                      • GetForegroundWindow.USER32 ref: 008416EB
                                                        • Part of subcall function 00813A3D: GetWindowThreadProcessId.USER32(?,00000000), ref: 00813A57
                                                        • Part of subcall function 00813A3D: GetCurrentThreadId.KERNEL32 ref: 00813A5E
                                                        • Part of subcall function 00813A3D: AttachThreadInput.USER32(00000000,?,00000000,00000000,?,008125B3), ref: 00813A65
                                                      • GetCaretPos.USER32(?), ref: 008416FF
                                                      • ClientToScreen.USER32(00000000,?), ref: 0084174C
                                                      • GetForegroundWindow.USER32 ref: 00841752
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ThreadWindow$Foreground$AttachCaretClientCurrentInputProcessScreen
                                                      • String ID:
                                                      • API String ID: 2759813231-0
                                                      • Opcode ID: a91f512321ac22e7cbdf84f4e58311c564d3f0978e94eedf9e6c75f0ef576d72
                                                      • Instruction ID: 0b8d8c4da40f51820a425779c94815b291c13322725b086a4ab5455a2d8e6567
                                                      • Opcode Fuzzy Hash: a91f512321ac22e7cbdf84f4e58311c564d3f0978e94eedf9e6c75f0ef576d72
                                                      • Instruction Fuzzy Hash: 28313D75D00149AFCB04EFA9C8859EEBBFDFF48304B5480AAE415E7211D6359E45CBA1
                                                      APIs
                                                        • Part of subcall function 007B7620: _wcslen.LIBCMT ref: 007B7625
                                                      • _wcslen.LIBCMT ref: 0081DFCB
                                                      • _wcslen.LIBCMT ref: 0081DFE2
                                                      • _wcslen.LIBCMT ref: 0081E00D
                                                      • GetTextExtentPoint32W.GDI32(?,00000000,00000000,?), ref: 0081E018
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$ExtentPoint32Text
                                                      • String ID:
                                                      • API String ID: 3763101759-0
                                                      • Opcode ID: 22fabb79f9fbbd2daafa28e131aebcb667a28093c113d98fa66a7745a542ecb0
                                                      • Instruction ID: ff5705144ecf747d79a906bb6658590d888e378fda7c29b0378acbda2546a94a
                                                      • Opcode Fuzzy Hash: 22fabb79f9fbbd2daafa28e131aebcb667a28093c113d98fa66a7745a542ecb0
                                                      • Instruction Fuzzy Hash: 9921BF71900614EFCB209FA8D881BAEB7F8FF49750F144069E805FB342D6749E41CBA1
                                                      APIs
                                                      • CreateToolhelp32Snapshot.KERNEL32 ref: 0081D501
                                                      • Process32FirstW.KERNEL32(00000000,?), ref: 0081D50F
                                                      • Process32NextW.KERNEL32(00000000,?), ref: 0081D52F
                                                      • CloseHandle.KERNEL32(00000000), ref: 0081D5DC
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32
                                                      • String ID:
                                                      • API String ID: 420147892-0
                                                      • Opcode ID: a1ccf2014cc592bab459987a593b026a3ea143ba6fd07ef37e8f8eeb29746ffd
                                                      • Instruction ID: 3aeea90104eb74051dd1f5db9c70921e7c62b55fc94638c7c2f57f4c9a66b9a1
                                                      • Opcode Fuzzy Hash: a1ccf2014cc592bab459987a593b026a3ea143ba6fd07ef37e8f8eeb29746ffd
                                                      • Instruction Fuzzy Hash: B1314D711083009FD301EF54C889BEABBE9FF99354F14092DF685861A1EB719985CB92
                                                      APIs
                                                        • Part of subcall function 007C9BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 007C9BB2
                                                      • GetCursorPos.USER32(?), ref: 00849001
                                                      • TrackPopupMenuEx.USER32(?,00000000,?,?,?,00000000,?,00807711,?,?,?,?,?), ref: 00849016
                                                      • GetCursorPos.USER32(?), ref: 0084905E
                                                      • DefDlgProcW.USER32(?,0000007B,?,?,?,?,?,?,?,?,?,?,00807711,?,?,?), ref: 00849094
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Cursor$LongMenuPopupProcTrackWindow
                                                      • String ID:
                                                      • API String ID: 2864067406-0
                                                      • Opcode ID: 9c3dc55b092400d9bd754e59ab5f6aa56974abd71316e4b1acb6b22b8b7d18a7
                                                      • Instruction ID: 895513a63db2c0a3cc037b4a17a9b0046352f141bfd8e24ea4f8b01b62a8e786
                                                      • Opcode Fuzzy Hash: 9c3dc55b092400d9bd754e59ab5f6aa56974abd71316e4b1acb6b22b8b7d18a7
                                                      • Instruction Fuzzy Hash: 9F21AB35601418EFDB25CF98CC58EEB7BB9FB8A350F014069F9458B261C735A990DB60
                                                      APIs
                                                      • GetFileAttributesW.KERNEL32(?,0084CB68), ref: 0081D2FB
                                                      • GetLastError.KERNEL32 ref: 0081D30A
                                                      • CreateDirectoryW.KERNEL32(?,00000000), ref: 0081D319
                                                      • CreateDirectoryW.KERNEL32(?,00000000,00000000,000000FF,0084CB68), ref: 0081D376
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory$AttributesErrorFileLast
                                                      • String ID:
                                                      • API String ID: 2267087916-0
                                                      • Opcode ID: 8b54ba8a630571cf7ead8ff8fb40e39efc4b37852b22a00fb85a8c930b7c5dcf
                                                      • Instruction ID: a462225bb752836ea9add0e225db0aaadaa41b232c6f82c28d2365f80847a51a
                                                      • Opcode Fuzzy Hash: 8b54ba8a630571cf7ead8ff8fb40e39efc4b37852b22a00fb85a8c930b7c5dcf
                                                      • Instruction Fuzzy Hash: 90216D74509301DF8710DF28C885AAAB7ECFE56364F104A1DF4A9C73A1EB359986CB93
                                                      APIs
                                                        • Part of subcall function 00811014: GetTokenInformation.ADVAPI32(?,00000003(TokenIntegrityLevel),?,00000000,?), ref: 0081102A
                                                        • Part of subcall function 00811014: GetLastError.KERNEL32(?,TokenIntegrityLevel,?,00000000,?), ref: 00811036
                                                        • Part of subcall function 00811014: GetProcessHeap.KERNEL32(00000008,?,?,TokenIntegrityLevel,?,00000000,?), ref: 00811045
                                                        • Part of subcall function 00811014: HeapAlloc.KERNEL32(00000000,?,TokenIntegrityLevel,?,00000000,?), ref: 0081104C
                                                        • Part of subcall function 00811014: GetTokenInformation.ADVAPI32(?,00000003(TokenIntegrityLevel),00000000,?,?,?,TokenIntegrityLevel,?,00000000,?), ref: 00811062
                                                      • LookupPrivilegeValueW.ADVAPI32(00000000,?,?), ref: 008115BE
                                                      • _memcmp.LIBVCRUNTIME ref: 008115E1
                                                      • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00811617
                                                      • HeapFree.KERNEL32(00000000), ref: 0081161E
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Heap$InformationProcessToken$AllocErrorFreeLastLookupPrivilegeValue_memcmp
                                                      • String ID:
                                                      • API String ID: 1592001646-0
                                                      • Opcode ID: 5b592aac3eb90ee84384de33dfdb77ccadc5c668f7b27132b5841e26f9b9f257
                                                      • Instruction ID: 2f0dd5b005da9f80202475da1c0be02c6201c66e130a7a0070ef5d4b5b12f4bd
                                                      • Opcode Fuzzy Hash: 5b592aac3eb90ee84384de33dfdb77ccadc5c668f7b27132b5841e26f9b9f257
                                                      • Instruction Fuzzy Hash: 0C215531E01108ABDF00DFA4C949BEEB7B9FF94344F084459E541AB241E731AA85CBA0
                                                      APIs
                                                      • GetWindowLongW.USER32(?,000000EC), ref: 0084280A
                                                      • SetWindowLongW.USER32(?,000000EC,00000000), ref: 00842824
                                                      • SetWindowLongW.USER32(?,000000EC,00000000), ref: 00842832
                                                      • SetLayeredWindowAttributes.USER32(?,00000000,?,00000002), ref: 00842840
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Long$AttributesLayered
                                                      • String ID:
                                                      • API String ID: 2169480361-0
                                                      • Opcode ID: 8743e5a52421e55d385458beaa0c5f62ca1de7c5a47c725df5cee526104246de
                                                      • Instruction ID: 6d6edc6f218f67560697b2ee54c1284ed801a6fc73095bf80e1ca62de043452d
                                                      • Opcode Fuzzy Hash: 8743e5a52421e55d385458beaa0c5f62ca1de7c5a47c725df5cee526104246de
                                                      • Instruction Fuzzy Hash: 7021D335209119AFD714DB24C844FAA7B99FF46324F158258F826CB6E2CB75FC42CB91
                                                      APIs
                                                        • Part of subcall function 00818D7D: lstrlenW.KERNEL32(?,00000002,000000FF,?,?,?,0081790A,?,000000FF,?,00818754,00000000,?,0000001C,?,?), ref: 00818D8C
                                                        • Part of subcall function 00818D7D: lstrcpyW.KERNEL32(00000000,?,?,0081790A,?,000000FF,?,00818754,00000000,?,0000001C,?,?,00000000), ref: 00818DB2
                                                        • Part of subcall function 00818D7D: lstrcmpiW.KERNEL32(00000000,?,0081790A,?,000000FF,?,00818754,00000000,?,0000001C,?,?), ref: 00818DE3
                                                      • lstrlenW.KERNEL32(?,00000002,000000FF,?,000000FF,?,00818754,00000000,?,0000001C,?,?,00000000), ref: 00817923
                                                      • lstrcpyW.KERNEL32(00000000,?,?,00818754,00000000,?,0000001C,?,?,00000000), ref: 00817949
                                                      • lstrcmpiW.KERNEL32(00000002,cdecl,?,00818754,00000000,?,0000001C,?,?,00000000), ref: 00817984
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: lstrcmpilstrcpylstrlen
                                                      • String ID: cdecl
                                                      • API String ID: 4031866154-3896280584
                                                      • Opcode ID: a89660e2b35abb6c13fdb6a1ac615492b6f359d3664075f7f3230b8d64516ecd
                                                      • Instruction ID: fa8c2db5284cc1c2cf2ba900f07e2d27de3cadca98e5b613c606a79864a0dbb5
                                                      • Opcode Fuzzy Hash: a89660e2b35abb6c13fdb6a1ac615492b6f359d3664075f7f3230b8d64516ecd
                                                      • Instruction Fuzzy Hash: AA11D33A201302ABCB159F38D845EBA7BBDFF95350B50802EF946C72A4EB359855C7A1
                                                      APIs
                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00847D0B
                                                      • SetWindowLongW.USER32(00000000,000000F0,?), ref: 00847D2A
                                                      • SetWindowLongW.USER32(00000000,000000EC,000000FF), ref: 00847D42
                                                      • SetWindowPos.USER32(00000000,00000000,00000000,00000000,00000000,00000000,?,?,?,?,?,?,?,?,0082B7AD,00000000), ref: 00847D6B
                                                        • Part of subcall function 007C9BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 007C9BB2
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$Long
                                                      • String ID:
                                                      • API String ID: 847901565-0
                                                      • Opcode ID: c050399ff5e834137a3bcc14b2a59bbf8e53bebd721d06c56e078df5a18b5a02
                                                      • Instruction ID: 87094aa5715eee062c8cb7f1d4169a6ab2205526acabfd8d8aded194f60d2b02
                                                      • Opcode Fuzzy Hash: c050399ff5e834137a3bcc14b2a59bbf8e53bebd721d06c56e078df5a18b5a02
                                                      • Instruction Fuzzy Hash: DC117235615619AFCB109F68CC08B6A3BA9FF46360B158728F939D72F0E7349D51CB50
                                                      APIs
                                                      • SendMessageW.USER32(?,00001060,?,00000004), ref: 008456BB
                                                      • _wcslen.LIBCMT ref: 008456CD
                                                      • _wcslen.LIBCMT ref: 008456D8
                                                      • SendMessageW.USER32(?,00001002,00000000,?), ref: 00845816
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend_wcslen
                                                      • String ID:
                                                      • API String ID: 455545452-0
                                                      • Opcode ID: 0e4d1f276634818fcb86b1a879e1d557200c8c2cdf8c1fb243c237ff707999ff
                                                      • Instruction ID: 3484552f2f3c67d321c276cb60f82bb38d1ce680c39090847b957b44be3e2dbf
                                                      • Opcode Fuzzy Hash: 0e4d1f276634818fcb86b1a879e1d557200c8c2cdf8c1fb243c237ff707999ff
                                                      • Instruction Fuzzy Hash: 9111D67560060CA7DF209F65DC85AEE7B7CFF11768B104026F915D6182EB74D984CB64
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 2dd7fd04ca75169d278e244f8c769b7cbeca5733714f943e9683eb9237c5b1c0
                                                      • Instruction ID: fe290e7e2c72f60db6776a24b9c03c6fedfcdf2f563bb5cfae85e83dbc079d88
                                                      • Opcode Fuzzy Hash: 2dd7fd04ca75169d278e244f8c769b7cbeca5733714f943e9683eb9237c5b1c0
                                                      • Instruction Fuzzy Hash: 880126B230768A7EF620567A6CC6F27261CEF893B8F710325F520611D2DB788C008230
                                                      APIs
                                                      • SendMessageW.USER32(?,000000B0,?,?), ref: 00811A47
                                                      • SendMessageW.USER32(?,000000C9,?,00000000), ref: 00811A59
                                                      • SendMessageW.USER32(?,000000C9,?,00000000), ref: 00811A6F
                                                      • SendMessageW.USER32(?,000000C9,?,00000000), ref: 00811A8A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend
                                                      • String ID:
                                                      • API String ID: 3850602802-0
                                                      • Opcode ID: fbab5c9d7572e63aaca50371be4c4583fe74d3473cbe7cff835f32adddc45524
                                                      • Instruction ID: c4ce0156bd020ed29fc44fdca4a23a53a34c0b2258e02c5a40e9d9a51a564818
                                                      • Opcode Fuzzy Hash: fbab5c9d7572e63aaca50371be4c4583fe74d3473cbe7cff835f32adddc45524
                                                      • Instruction Fuzzy Hash: 3811157A901229FFEF109BA48985FADBB78FF08750F200091EA00B7290D6716E50DB94
                                                      APIs
                                                      • GetCurrentThreadId.KERNEL32 ref: 0081E1FD
                                                      • MessageBoxW.USER32(?,?,?,?), ref: 0081E230
                                                      • WaitForSingleObject.KERNEL32(00000000,000000FF,?,?,?,?), ref: 0081E246
                                                      • CloseHandle.KERNEL32(00000000,?,?,?,?), ref: 0081E24D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CloseCurrentHandleMessageObjectSingleThreadWait
                                                      • String ID:
                                                      • API String ID: 2880819207-0
                                                      • Opcode ID: f93c5fd011f796ec07efb20c578a342a3d16b6d9f3852c41420741f68444ab7d
                                                      • Instruction ID: 5ed4ae3820332df490a8b6845d92a328e42ffdddab12b8037817139b0a97c0fd
                                                      • Opcode Fuzzy Hash: f93c5fd011f796ec07efb20c578a342a3d16b6d9f3852c41420741f68444ab7d
                                                      • Instruction Fuzzy Hash: 4511A176A04258ABCB119FACAC09ADA7BACFF46320F144255F925E3391D7B49D4487A0
                                                      APIs
                                                      • CreateThread.KERNEL32(00000000,?,007DCFF9,00000000,00000004,00000000), ref: 007DD218
                                                      • GetLastError.KERNEL32 ref: 007DD224
                                                      • __dosmaperr.LIBCMT ref: 007DD22B
                                                      • ResumeThread.KERNEL32(00000000), ref: 007DD249
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Thread$CreateErrorLastResume__dosmaperr
                                                      • String ID:
                                                      • API String ID: 173952441-0
                                                      • Opcode ID: 352b6130a77ccbddf48526a7e6c906f66062611a2b1cc07181f9c0b731c8a6d0
                                                      • Instruction ID: e6c4c804c30b0d03289cef334efb6de2e75e4b90f32bfcfe37204c785bc332aa
                                                      • Opcode Fuzzy Hash: 352b6130a77ccbddf48526a7e6c906f66062611a2b1cc07181f9c0b731c8a6d0
                                                      • Instruction Fuzzy Hash: 7E01D236806208BBCB215BA5DC09BAE7A7DFF82330F10021BF925923D0DB799D01C6A0
                                                      APIs
                                                        • Part of subcall function 007C9BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 007C9BB2
                                                      • GetClientRect.USER32(?,?), ref: 00849F31
                                                      • GetCursorPos.USER32(?), ref: 00849F3B
                                                      • ScreenToClient.USER32(?,?), ref: 00849F46
                                                      • DefDlgProcW.USER32(?,00000020,?,00000000,?,?,?), ref: 00849F7A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Client$CursorLongProcRectScreenWindow
                                                      • String ID:
                                                      • API String ID: 4127811313-0
                                                      • Opcode ID: 680494a3136c8c5fcfdb74acc64cad369d0280f335facc23a24a5b0c55ed1445
                                                      • Instruction ID: 5cafb044af27647778c73202dd575c9ba5e31d02f2852246e480be5465c7f854
                                                      • Opcode Fuzzy Hash: 680494a3136c8c5fcfdb74acc64cad369d0280f335facc23a24a5b0c55ed1445
                                                      • Instruction Fuzzy Hash: 9811363690111EABDB20DFA8D8499EE77BCFB46311F000455F941E3140DB34BE86CBA1
                                                      APIs
                                                      • CreateWindowExW.USER32(?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 007B604C
                                                      • GetStockObject.GDI32(00000011), ref: 007B6060
                                                      • SendMessageW.USER32(00000000,00000030,00000000), ref: 007B606A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CreateMessageObjectSendStockWindow
                                                      • String ID:
                                                      • API String ID: 3970641297-0
                                                      • Opcode ID: 045f1a72f3a26d05369785865b7cb313a5ddb26b8ebb23e05a574f5b3063e17a
                                                      • Instruction ID: 3309361e98cc23b9cd5a51cf7ca7c9fe72dea1382fae584b3c3a91f7236cf04a
                                                      • Opcode Fuzzy Hash: 045f1a72f3a26d05369785865b7cb313a5ddb26b8ebb23e05a574f5b3063e17a
                                                      • Instruction Fuzzy Hash: 6D115B72502508BFEF529FA59C44EFABBADFF197A4F040216FB1452120D73A9C60DBA0
                                                      APIs
                                                      • ___BuildCatchObject.LIBVCRUNTIME ref: 007D3B56
                                                        • Part of subcall function 007D3AA3: BuildCatchObjectHelperInternal.LIBVCRUNTIME ref: 007D3AD2
                                                        • Part of subcall function 007D3AA3: ___AdjustPointer.LIBCMT ref: 007D3AED
                                                      • _UnwindNestedFrames.LIBCMT ref: 007D3B6B
                                                      • __FrameHandler3::FrameUnwindToState.LIBVCRUNTIME ref: 007D3B7C
                                                      • CallCatchBlock.LIBVCRUNTIME ref: 007D3BA4
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Catch$BuildFrameObjectUnwind$AdjustBlockCallFramesHandler3::HelperInternalNestedPointerState
                                                      • String ID:
                                                      • API String ID: 737400349-0
                                                      • Opcode ID: 12ea49abee573113f57dbd3ec3a577afcc9c348439d29e6cbe32e78011ac24d3
                                                      • Instruction ID: cce51fc8d84b2eb94deed27e5dbd3e9b0634cff22a8469cc805a35ee2300c8b5
                                                      • Opcode Fuzzy Hash: 12ea49abee573113f57dbd3ec3a577afcc9c348439d29e6cbe32e78011ac24d3
                                                      • Instruction Fuzzy Hash: 0C012D72100148BBDF115F95CC46DEB3F7AEF48754F04401AFE4856221C73AE961DBA1
                                                      APIs
                                                      • LoadLibraryExW.KERNEL32(00000000,00000000,00000800,007B13C6,00000000,00000000,?,007E301A,007B13C6,00000000,00000000,00000000,?,007E328B,00000006,FlsSetValue), ref: 007E30A5
                                                      • GetLastError.KERNEL32(?,007E301A,007B13C6,00000000,00000000,00000000,?,007E328B,00000006,FlsSetValue,00852290,FlsSetValue,00000000,00000364,?,007E2E46), ref: 007E30B1
                                                      • LoadLibraryExW.KERNEL32(00000000,00000000,00000000,?,007E301A,007B13C6,00000000,00000000,00000000,?,007E328B,00000006,FlsSetValue,00852290,FlsSetValue,00000000), ref: 007E30BF
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: LibraryLoad$ErrorLast
                                                      • String ID:
                                                      • API String ID: 3177248105-0
                                                      • Opcode ID: 21b25d95abe8e4727473bc62f650161a6e36fb394b710fd07915f4c96f78dbe8
                                                      • Instruction ID: ffe4ef273f0a4e12a9df7f7297eb37be5b9a71668a13bdf0df0555b1d2048d34
                                                      • Opcode Fuzzy Hash: 21b25d95abe8e4727473bc62f650161a6e36fb394b710fd07915f4c96f78dbe8
                                                      • Instruction Fuzzy Hash: 1601F736303266ABCB718B7A9C4CA677B9EBF4AB61B200720F905E3140C729D901C6E0
                                                      APIs
                                                      • GetModuleFileNameW.KERNEL32(?,?,00000104,00000000), ref: 0081747F
                                                      • LoadTypeLibEx.OLEAUT32(?,00000002,?), ref: 00817497
                                                      • RegisterTypeLib.OLEAUT32(?,?,00000000), ref: 008174AC
                                                      • RegisterTypeLibForUser.OLEAUT32(?,?,00000000), ref: 008174CA
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Type$Register$FileLoadModuleNameUser
                                                      • String ID:
                                                      • API String ID: 1352324309-0
                                                      • Opcode ID: 650b28fb4d1f4606f36a3286b1f94754efeb9c36d5742fb40b42ceb42fb32aae
                                                      • Instruction ID: 075e860acb4a582f8c5229e99f74c871f2bc8db29abf888d9e46979e1510225f
                                                      • Opcode Fuzzy Hash: 650b28fb4d1f4606f36a3286b1f94754efeb9c36d5742fb40b42ceb42fb32aae
                                                      • Instruction Fuzzy Hash: 99118BB9206315ABE7208F18DD08FD27BFCFF00B04F10856EA656D6191DBB0E984DBA4
                                                      APIs
                                                      • QueryPerformanceCounter.KERNEL32(?,?,?,?,?,?,?,?,?,0081ACD3,?,00008000), ref: 0081B0C4
                                                      • Sleep.KERNEL32(00000000,?,?,?,?,?,?,?,?,0081ACD3,?,00008000), ref: 0081B0E9
                                                      • QueryPerformanceCounter.KERNEL32(?,?,?,?,?,?,?,?,?,0081ACD3,?,00008000), ref: 0081B0F3
                                                      • Sleep.KERNEL32(00000000,?,?,?,?,?,?,?,?,0081ACD3,?,00008000), ref: 0081B126
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CounterPerformanceQuerySleep
                                                      • String ID:
                                                      • API String ID: 2875609808-0
                                                      • Opcode ID: 48a2ef8fb6b148cdac123c23a5e487312f96d426a28dff42fe670c231cd38b89
                                                      • Instruction ID: da1fa793a2001e17270a5096d12a3f86bbcd1b0f2dc09c75e3182ef8c50a4a9d
                                                      • Opcode Fuzzy Hash: 48a2ef8fb6b148cdac123c23a5e487312f96d426a28dff42fe670c231cd38b89
                                                      • Instruction Fuzzy Hash: 38113931C0292DE7CF00AFE4E958AEEBB7CFF0A711F114089D955B2181DB309690CB51
                                                      APIs
                                                      • GetWindowRect.USER32(?,?), ref: 00847E33
                                                      • ScreenToClient.USER32(?,?), ref: 00847E4B
                                                      • ScreenToClient.USER32(?,?), ref: 00847E6F
                                                      • InvalidateRect.USER32(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00847E8A
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClientRectScreen$InvalidateWindow
                                                      • String ID:
                                                      • API String ID: 357397906-0
                                                      • Opcode ID: 650e60726384ca0732650777651d1df83275e1d1b7f884e1c791fbf75fad9e48
                                                      • Instruction ID: 0ddbd39e18f86e502b8d5086b5f87fbfb66fe1da482e0a9919193be094b3d241
                                                      • Opcode Fuzzy Hash: 650e60726384ca0732650777651d1df83275e1d1b7f884e1c791fbf75fad9e48
                                                      • Instruction Fuzzy Hash: 771153B9D0020AAFDB41CF98C884AEEBBF9FF19310F509166E915E3210D735AA54CF90
                                                      APIs
                                                      • SendMessageTimeoutW.USER32(?,00000000,00000000,00000000,00000002,00001388,?), ref: 00812DC5
                                                      • GetWindowThreadProcessId.USER32(?,00000000), ref: 00812DD6
                                                      • GetCurrentThreadId.KERNEL32 ref: 00812DDD
                                                      • AttachThreadInput.USER32(00000000,?,00000000,00000000), ref: 00812DE4
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Thread$AttachCurrentInputMessageProcessSendTimeoutWindow
                                                      • String ID:
                                                      • API String ID: 2710830443-0
                                                      • Opcode ID: ee6c6068d4d00478175ac7889816a09b3f5d876ebf92eab2c29cb7e5b680033f
                                                      • Instruction ID: 47df54622771c2c631a9e814110f028368c56dbe4443fc2fb7b64ba95f0b0cba
                                                      • Opcode Fuzzy Hash: ee6c6068d4d00478175ac7889816a09b3f5d876ebf92eab2c29cb7e5b680033f
                                                      • Instruction Fuzzy Hash: 35E0EDB56022287AD7601BA2EC0DEEB7E6CFF57BA1F414119B506D10909AA58981C6B1
                                                      APIs
                                                        • Part of subcall function 007C9639: ExtCreatePen.GDI32(?,?,00000000,00000000,00000000,?,00000000), ref: 007C9693
                                                        • Part of subcall function 007C9639: SelectObject.GDI32(?,00000000), ref: 007C96A2
                                                        • Part of subcall function 007C9639: BeginPath.GDI32(?), ref: 007C96B9
                                                        • Part of subcall function 007C9639: SelectObject.GDI32(?,00000000), ref: 007C96E2
                                                      • MoveToEx.GDI32(?,00000000,00000000,00000000), ref: 00848887
                                                      • LineTo.GDI32(?,?,?), ref: 00848894
                                                      • EndPath.GDI32(?), ref: 008488A4
                                                      • StrokePath.GDI32(?), ref: 008488B2
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Path$ObjectSelect$BeginCreateLineMoveStroke
                                                      • String ID:
                                                      • API String ID: 1539411459-0
                                                      • Opcode ID: 1d02b8c2d0304f3b9224204003e37026857f277bb04c0cdb940d10920d9ff681
                                                      • Instruction ID: 20a38d9ed3dd85ae02279bfa6b9c1a4f6ad8188e8f8fe8181ec2984ddeb694ae
                                                      • Opcode Fuzzy Hash: 1d02b8c2d0304f3b9224204003e37026857f277bb04c0cdb940d10920d9ff681
                                                      • Instruction Fuzzy Hash: FFF03A3A042658FADB125F94AC0DFCE3F5DBF16310F448100FA11650E2CB795511CBA9
                                                      APIs
                                                      • GetSysColor.USER32(00000008), ref: 007C98CC
                                                      • SetTextColor.GDI32(?,?), ref: 007C98D6
                                                      • SetBkMode.GDI32(?,00000001), ref: 007C98E9
                                                      • GetStockObject.GDI32(00000005), ref: 007C98F1
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Color$ModeObjectStockText
                                                      • String ID:
                                                      • API String ID: 4037423528-0
                                                      • Opcode ID: bb042d19db3b5bb4f6906f3dc882655ad4791df2d0d743e664fc3f8eb4fca947
                                                      • Instruction ID: 87c73e50b79ce0d56a9dc8e4514ff6f1d15e70f6bbe25832d6a4961b6a7a5c5d
                                                      • Opcode Fuzzy Hash: bb042d19db3b5bb4f6906f3dc882655ad4791df2d0d743e664fc3f8eb4fca947
                                                      • Instruction Fuzzy Hash: 10E06D35645680AAEBA15B74AC09BE83F24FB16336F04821AF7FA980E1C7715640DB10
                                                      APIs
                                                      • GetCurrentThread.KERNEL32 ref: 00811634
                                                      • OpenThreadToken.ADVAPI32(00000000,?,?,?,008111D9), ref: 0081163B
                                                      • GetCurrentProcess.KERNEL32(00000028,?,?,?,?,008111D9), ref: 00811648
                                                      • OpenProcessToken.ADVAPI32(00000000,?,?,?,008111D9), ref: 0081164F
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CurrentOpenProcessThreadToken
                                                      • String ID:
                                                      • API String ID: 3974789173-0
                                                      • Opcode ID: a078a80f433d401bac9efca365a8b1257342b8008e380df04017da6c866e0e6d
                                                      • Instruction ID: e64f9d6bbc5286c102c18ad84a9b7e0be76c1581370867597684db660c95620a
                                                      • Opcode Fuzzy Hash: a078a80f433d401bac9efca365a8b1257342b8008e380df04017da6c866e0e6d
                                                      • Instruction Fuzzy Hash: AEE04F356022119BDBA01FA19D0DB867B6CFF56791F144809F246C9090D6644480CB50
                                                      APIs
                                                      • GetDesktopWindow.USER32 ref: 0080D858
                                                      • GetDC.USER32(00000000), ref: 0080D862
                                                      • GetDeviceCaps.GDI32(00000000,0000000C), ref: 0080D882
                                                      • ReleaseDC.USER32(?), ref: 0080D8A3
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CapsDesktopDeviceReleaseWindow
                                                      • String ID:
                                                      • API String ID: 2889604237-0
                                                      • Opcode ID: 71af866e893cf2f108df2042461eec6fefa9a422a0a2af59f33a3eb0dc9d6d73
                                                      • Instruction ID: 13321e3ed673f8acc9d190eacb0a759ad6745cbe7fdaf895e1cfbf6239a866b8
                                                      • Opcode Fuzzy Hash: 71af866e893cf2f108df2042461eec6fefa9a422a0a2af59f33a3eb0dc9d6d73
                                                      • Instruction Fuzzy Hash: 1AE01AB9801204DFCB919FA0D80CA6DBBB9FB19310F15D45DF806E7260C7388941EF40
                                                      APIs
                                                      • GetDesktopWindow.USER32 ref: 0080D86C
                                                      • GetDC.USER32(00000000), ref: 0080D876
                                                      • GetDeviceCaps.GDI32(00000000,0000000C), ref: 0080D882
                                                      • ReleaseDC.USER32(?), ref: 0080D8A3
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CapsDesktopDeviceReleaseWindow
                                                      • String ID:
                                                      • API String ID: 2889604237-0
                                                      • Opcode ID: 92930487ac24d5aeb003586e5637af17dc9f4d468713c256e5f06a10f4043d81
                                                      • Instruction ID: fb8f7df383d276537f4b873886af573eceff8f8f58ac5c3633cf56e53c440740
                                                      • Opcode Fuzzy Hash: 92930487ac24d5aeb003586e5637af17dc9f4d468713c256e5f06a10f4043d81
                                                      • Instruction Fuzzy Hash: 03E012B9801200EFCB91AFA0D80CA6DBBB9BB18310B15904DF80AE7260CB385901EF40
                                                      APIs
                                                        • Part of subcall function 007B7620: _wcslen.LIBCMT ref: 007B7625
                                                      • WNetUseConnectionW.MPR(00000000,?,0000002A,00000000,?,?,0000002A,?), ref: 00824ED4
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Connection_wcslen
                                                      • String ID: *$LPT
                                                      • API String ID: 1725874428-3443410124
                                                      • Opcode ID: 4486a246dbeed911b2aa277a325ae5d32884325d52cca0758779172d297efda7
                                                      • Instruction ID: e455c64542f3f60f92b3bc824cbfb99804a26d372fdb64951ebe8365511e19c9
                                                      • Opcode Fuzzy Hash: 4486a246dbeed911b2aa277a325ae5d32884325d52cca0758779172d297efda7
                                                      • Instruction Fuzzy Hash: 90915D75A00214DFDB14DF54D584EA9BBF1FF84308F199099E80A9B3A2CB35ED85CBA1
                                                      APIs
                                                      • __startOneArgErrorHandling.LIBCMT ref: 007DE30D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ErrorHandling__start
                                                      • String ID: pow
                                                      • API String ID: 3213639722-2276729525
                                                      • Opcode ID: c24ba329d51ee94fb4fec6408fa400269111273a5592d596e66f879c91bccf1c
                                                      • Instruction ID: d1aca00e533d87af2d3d85465686fa6d49425c17236073528bbe33e1683875b8
                                                      • Opcode Fuzzy Hash: c24ba329d51ee94fb4fec6408fa400269111273a5592d596e66f879c91bccf1c
                                                      • Instruction Fuzzy Hash: 55517D61A0D24296CB1BB715CD453793BB8FB44741F34899AF0D54A3E9EF3C8C81DA46
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: #
                                                      • API String ID: 0-1885708031
                                                      • Opcode ID: 731caa0cacfd3f05764a35a1f52625675a7d55b90583395a9d3c5173bf92b4da
                                                      • Instruction ID: a0e0574afa566caabd0df11704e73db328291abee784368646056cd2d93df8d9
                                                      • Opcode Fuzzy Hash: 731caa0cacfd3f05764a35a1f52625675a7d55b90583395a9d3c5173bf92b4da
                                                      • Instruction Fuzzy Hash: 4A513335601246DFDB25DF28C885BFA7BA8FF55310F24845DE891DB2C0DA389D42CBA0
                                                      APIs
                                                      • Sleep.KERNEL32(00000000), ref: 007CF2A2
                                                      • GlobalMemoryStatusEx.KERNEL32(?), ref: 007CF2BB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: GlobalMemorySleepStatus
                                                      • String ID: @
                                                      • API String ID: 2783356886-2766056989
                                                      • Opcode ID: 4231ab75b2eb5cab69395742c67e2dbbb786614f2f3ecc27fb58f946dee20a4e
                                                      • Instruction ID: 3bde580d16c01c80ca60aa0703b44a4a87176a18361d47c7f36ffcf31841fa65
                                                      • Opcode Fuzzy Hash: 4231ab75b2eb5cab69395742c67e2dbbb786614f2f3ecc27fb58f946dee20a4e
                                                      • Instruction Fuzzy Hash: 26512472418744DBD320AF10D88ABABBBF8FB84300F85885DF199811A5EB748529CB67
                                                      APIs
                                                      • CharUpperBuffW.USER32(?,?,?,00000003,?,?), ref: 008357E0
                                                      • _wcslen.LIBCMT ref: 008357EC
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: BuffCharUpper_wcslen
                                                      • String ID: CALLARGARRAY
                                                      • API String ID: 157775604-1150593374
                                                      • Opcode ID: 2a8cbcd6c6a20a1b1ad6bedc6c3ee26c616fc7a4865f1bb77bcf05fc963859a6
                                                      • Instruction ID: 9b4aa4ad0486f56b69684687b479536400e46f84f8c4f47c98e3771e86572609
                                                      • Opcode Fuzzy Hash: 2a8cbcd6c6a20a1b1ad6bedc6c3ee26c616fc7a4865f1bb77bcf05fc963859a6
                                                      • Instruction Fuzzy Hash: CE417B71A00209DFCB14EFA9C8869AEBBB5FF99724F14406DE505E7291E7349D81CBA0
                                                      APIs
                                                      • _wcslen.LIBCMT ref: 0082D130
                                                      • InternetCrackUrlW.WININET(?,00000000,00000000,0000007C), ref: 0082D13A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CrackInternet_wcslen
                                                      • String ID: |
                                                      • API String ID: 596671847-2343686810
                                                      • Opcode ID: e6bdfb16a3302687b4c644f36a6cbc6ef092c59fb416fecf6aec27b1ca3c13bc
                                                      • Instruction ID: 90cb027f29bb1966fd41cade51f9b97d776b7f7d4da69dfbe65080a66a028a56
                                                      • Opcode Fuzzy Hash: e6bdfb16a3302687b4c644f36a6cbc6ef092c59fb416fecf6aec27b1ca3c13bc
                                                      • Instruction Fuzzy Hash: DA313D71D00219EBCF15EFA4DC89AEEBFB9FF04304F100019F915A61A2E735AA56CB50
                                                      APIs
                                                      • DestroyWindow.USER32(?,?,?,?), ref: 00843621
                                                      • MoveWindow.USER32(?,?,?,?,?,00000001,?,?,?), ref: 0084365C
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$DestroyMove
                                                      • String ID: static
                                                      • API String ID: 2139405536-2160076837
                                                      • Opcode ID: cde8ff80f452406edd14703b4eca76a618658a3134d7b99c46acd22e846fe70e
                                                      • Instruction ID: b38273474efd00566f789cc8dc224cdf0dea4106e98ef89d1b150c0d8388403b
                                                      • Opcode Fuzzy Hash: cde8ff80f452406edd14703b4eca76a618658a3134d7b99c46acd22e846fe70e
                                                      • Instruction Fuzzy Hash: 2E318B71100208AEDB109F28DC81FFB73A9FF98724F01961DF9A5D7280DA34AD91D760
                                                      APIs
                                                      • SendMessageW.USER32(00000027,00001132,00000000,?), ref: 0084461F
                                                      • SendMessageW.USER32(?,00001105,00000000,00000000), ref: 00844634
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend
                                                      • String ID: '
                                                      • API String ID: 3850602802-1997036262
                                                      • Opcode ID: ddc320d0b2ac1850c42bd35a704b1aa1591d15bcea3de07d3f71126650ad9518
                                                      • Instruction ID: c4464c42456f18ed92abcffdef0fb7452e3bce76c10ba5e013144f27457a82e5
                                                      • Opcode Fuzzy Hash: ddc320d0b2ac1850c42bd35a704b1aa1591d15bcea3de07d3f71126650ad9518
                                                      • Instruction Fuzzy Hash: C1311674A0120A9FEF14CFA9C981BDABBB5FB09304F11516AE904EB341E770A941CF90
                                                      APIs
                                                      • SendMessageW.USER32(00000000,00000143,00000000,?), ref: 0084327C
                                                      • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 00843287
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: MessageSend
                                                      • String ID: Combobox
                                                      • API String ID: 3850602802-2096851135
                                                      • Opcode ID: 0f3fc38bb4fa408a60f52cc42f8321a926c22700b88828db42fa5a3438f93434
                                                      • Instruction ID: 56c278f566167a7f9c7c240396078fed9a4896da22fac78da8aee52565d0a99f
                                                      • Opcode Fuzzy Hash: 0f3fc38bb4fa408a60f52cc42f8321a926c22700b88828db42fa5a3438f93434
                                                      • Instruction Fuzzy Hash: C811E27130021CBFFF219E54DC84EBB376AFB94365F104129F918E7290D6B19D518760
                                                      APIs
                                                        • Part of subcall function 007B600E: CreateWindowExW.USER32(?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 007B604C
                                                        • Part of subcall function 007B600E: GetStockObject.GDI32(00000011), ref: 007B6060
                                                        • Part of subcall function 007B600E: SendMessageW.USER32(00000000,00000030,00000000), ref: 007B606A
                                                      • GetWindowRect.USER32(00000000,?), ref: 0084377A
                                                      • GetSysColor.USER32(00000012), ref: 00843794
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Window$ColorCreateMessageObjectRectSendStock
                                                      • String ID: static
                                                      • API String ID: 1983116058-2160076837
                                                      • Opcode ID: 98fb6cb6d2af43dfd6a7543cab4fda905cac549e0ee2f579513fbce18c972d3e
                                                      • Instruction ID: bdebe9097ade9d6eb677833f92052c27917069f6c898326c9138d3eaf3068594
                                                      • Opcode Fuzzy Hash: 98fb6cb6d2af43dfd6a7543cab4fda905cac549e0ee2f579513fbce18c972d3e
                                                      • Instruction Fuzzy Hash: 1A1114B2610209AFDB00DFA8CC46AEA7BB8FB19314F014925F995E2250EB35E8519B60
                                                      APIs
                                                      • InternetOpenW.WININET(?,00000000,00000000,00000000,00000000), ref: 0082CD7D
                                                      • InternetSetOptionW.WININET(00000000,00000032,?,00000008), ref: 0082CDA6
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Internet$OpenOption
                                                      • String ID: <local>
                                                      • API String ID: 942729171-4266983199
                                                      • Opcode ID: 7546942a85d1c6e1dbfb562718d782b7ccfa52b5ba45c7ef3892fb5f4ae9eb21
                                                      • Instruction ID: 866c55de97b99e9a797e4d49d9dd54627f7970ff85f50d424ab671f10b64b5c5
                                                      • Opcode Fuzzy Hash: 7546942a85d1c6e1dbfb562718d782b7ccfa52b5ba45c7ef3892fb5f4ae9eb21
                                                      • Instruction Fuzzy Hash: CF11C675205635BAE7744B669C45EFBBE6CFF127A8F004226B109C3180D7749885D6F0
                                                      APIs
                                                      • GetWindowTextLengthW.USER32(00000000), ref: 008434AB
                                                      • SendMessageW.USER32(?,000000B1,00000000,00000000), ref: 008434BA
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: LengthMessageSendTextWindow
                                                      • String ID: edit
                                                      • API String ID: 2978978980-2167791130
                                                      • Opcode ID: 0b05aa99c5084f3edc06199eae86ab3daaf553215719654eefe4616b8dbdac49
                                                      • Instruction ID: 5ffc070907786c82c05a7ef23b8bbafb895468806aa7979e660796b310a58703
                                                      • Opcode Fuzzy Hash: 0b05aa99c5084f3edc06199eae86ab3daaf553215719654eefe4616b8dbdac49
                                                      • Instruction Fuzzy Hash: 1E118C7120020CABEB129E68DC44AEB3B6EFB25378F504324FA65D31E0C775DD519B68
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                      • CharUpperBuffW.USER32(?,?,?), ref: 00816CB6
                                                      • _wcslen.LIBCMT ref: 00816CC2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen$BuffCharUpper
                                                      • String ID: STOP
                                                      • API String ID: 1256254125-2411985666
                                                      • Opcode ID: 0de969964638197b9059f1a4e327ba514083c316271e4de17f6dedfea8ee5a6e
                                                      • Instruction ID: fe1d592cee2147167a732a5a081b95cd2af626aef173e5642108d64bb8716bb8
                                                      • Opcode Fuzzy Hash: 0de969964638197b9059f1a4e327ba514083c316271e4de17f6dedfea8ee5a6e
                                                      • Instruction Fuzzy Hash: 2001C832A005268BCB209FBDDC859FF77B9FF617147500524E9A2D6194FB35D990C690
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 00813CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00813CCA
                                                      • SendMessageW.USER32(?,000001A2,000000FF,?), ref: 00811D4C
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClassMessageNameSend_wcslen
                                                      • String ID: ComboBox$ListBox
                                                      • API String ID: 624084870-1403004172
                                                      • Opcode ID: 44c664b64b4fc40eae469592dcfb40b3089f4f476fe2ffc8a953e8b8bd079b3f
                                                      • Instruction ID: 355a8ff5885acc09cf363920a7c1f8545435a2eda2ff57a6f7f2e6c743d8a9b7
                                                      • Opcode Fuzzy Hash: 44c664b64b4fc40eae469592dcfb40b3089f4f476fe2ffc8a953e8b8bd079b3f
                                                      • Instruction Fuzzy Hash: 3E01D875601218AB8F04EBA4DC59DFE776CFF56350B140519FA36A73C1EA345948C660
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 00813CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00813CCA
                                                      • SendMessageW.USER32(?,00000180,00000000,?), ref: 00811C46
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClassMessageNameSend_wcslen
                                                      • String ID: ComboBox$ListBox
                                                      • API String ID: 624084870-1403004172
                                                      • Opcode ID: afcc4f6516009f8c547af5e5925e11f1a9e452c6337d5b4a97c9769845ccd119
                                                      • Instruction ID: 3dbd65f795c5e87bdaf3cc0415f2a458daab8c1434daee9773a16fab64a6404e
                                                      • Opcode Fuzzy Hash: afcc4f6516009f8c547af5e5925e11f1a9e452c6337d5b4a97c9769845ccd119
                                                      • Instruction Fuzzy Hash: 24016775781108A7CF14EBA4C959AFFB7ACFF15340F140019BA27B7281EA649E48D6F1
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 00813CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00813CCA
                                                      • SendMessageW.USER32(?,00000182,?,00000000), ref: 00811CC8
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClassMessageNameSend_wcslen
                                                      • String ID: ComboBox$ListBox
                                                      • API String ID: 624084870-1403004172
                                                      • Opcode ID: c929876f72f8c983fd04f0f3843675249c88346ce7b9cad841efd8ec880a2e34
                                                      • Instruction ID: af2df4fd33fa047b78ba71b34cd1b64b27c7ef02900a72a847b160a2c4dac923
                                                      • Opcode Fuzzy Hash: c929876f72f8c983fd04f0f3843675249c88346ce7b9cad841efd8ec880a2e34
                                                      • Instruction Fuzzy Hash: 16016775641118A7CF14E7A4CA59AFE77ACFF11340B540015BA16F3281EA659F48C6F1
                                                      APIs
                                                        • Part of subcall function 007B9CB3: _wcslen.LIBCMT ref: 007B9CBD
                                                        • Part of subcall function 00813CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00813CCA
                                                      • SendMessageW.USER32(?,0000018B,00000000,00000000), ref: 00811DD3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ClassMessageNameSend_wcslen
                                                      • String ID: ComboBox$ListBox
                                                      • API String ID: 624084870-1403004172
                                                      • Opcode ID: b9cad59d8d61aa57293a647d1a203afce2228bac2b7668dd5f16f7051381456e
                                                      • Instruction ID: 8ed1e5e2453ce5bfbb9405e2f0c8d69b5130a39d5efa73596a3fa99c785b1b4a
                                                      • Opcode Fuzzy Hash: b9cad59d8d61aa57293a647d1a203afce2228bac2b7668dd5f16f7051381456e
                                                      • Instruction Fuzzy Hash: C7F0A471A41218A7DF04E7A4DC9ABFE776CFF02354F140919BA36E32C1EA64994882A1
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: _wcslen
                                                      • String ID: 3, 3, 16, 1
                                                      • API String ID: 176396367-3042988571
                                                      • Opcode ID: 9f12e271cb67e940d73a0713f41820832bd969109cbe90b71bf67f98d2b41939
                                                      • Instruction ID: dc864e4d952e30fa594f8c27769b698985bfc8a4d0c7135bbed5b46ae303ab39
                                                      • Opcode Fuzzy Hash: 9f12e271cb67e940d73a0713f41820832bd969109cbe90b71bf67f98d2b41939
                                                      • Instruction Fuzzy Hash: 91E06182305320719331137BDCC597F5699EFC9750B10182BF9C5C236AFAA8ED9193E5
                                                      APIs
                                                      • MessageBoxW.USER32(00000000,Error allocating memory.,AutoIt,00000010), ref: 00810B23
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Message
                                                      • String ID: AutoIt$Error allocating memory.
                                                      • API String ID: 2030045667-4017498283
                                                      • Opcode ID: caba219e3b5da8fe3256ef994c4a29f64d80ae7bb8af87367a6028fbb9836473
                                                      • Instruction ID: a4b8b483dcb5d5ef85070187c6243648818fb49017b1517cb1003bd9dc536497
                                                      • Opcode Fuzzy Hash: caba219e3b5da8fe3256ef994c4a29f64d80ae7bb8af87367a6028fbb9836473
                                                      • Instruction Fuzzy Hash: C9E0923128931876D2102694BC07F897B88EF05B20F10442AF798955C38AE9649046E9
                                                      APIs
                                                        • Part of subcall function 007CF7C9: InitializeCriticalSectionAndSpinCount.KERNEL32(?,00000000,?,007D0D71,?,?,?,007B100A), ref: 007CF7CE
                                                      • IsDebuggerPresent.KERNEL32(?,?,?,007B100A), ref: 007D0D75
                                                      • OutputDebugStringW.KERNEL32(ERROR : Unable to initialize critical section in CAtlBaseModule,?,?,?,007B100A), ref: 007D0D84
                                                      Strings
                                                      • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 007D0D7F
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: CountCriticalDebugDebuggerInitializeOutputPresentSectionSpinString
                                                      • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
                                                      • API String ID: 55579361-631824599
                                                      • Opcode ID: e547f1605994cf4680165de67cd9b24f8a37a5bb0e7f236ba47e2b23c8bf0abc
                                                      • Instruction ID: a4fdf2cc0019c5a3ee43742a9bfa33ad10526c74e515400b607aa2db2b9dba03
                                                      • Opcode Fuzzy Hash: e547f1605994cf4680165de67cd9b24f8a37a5bb0e7f236ba47e2b23c8bf0abc
                                                      • Instruction Fuzzy Hash: E7E06D742003118BD3609FB8E4087427BF5BB04741F00492EE482C6752DBF8E444CBE1
                                                      APIs
                                                      • GetTempPathW.KERNEL32(00000104,?,00000001), ref: 0082302F
                                                      • GetTempFileNameW.KERNEL32(?,aut,00000000,?), ref: 00823044
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: Temp$FileNamePath
                                                      • String ID: aut
                                                      • API String ID: 3285503233-3010740371
                                                      • Opcode ID: 33406ae8aef0cf0af239201b697ae239ba2021ab5c21085c1b2a3ce0146b08ef
                                                      • Instruction ID: e81a3babe13f0b0b7251f081ce54f30b2f972fbd36cee2666586f44e4729a2d9
                                                      • Opcode Fuzzy Hash: 33406ae8aef0cf0af239201b697ae239ba2021ab5c21085c1b2a3ce0146b08ef
                                                      • Instruction Fuzzy Hash: 98D05E7650133867DA60A7A4AC4EFCB7B6CEB05750F0002A1B655E2091EAF4D984CAD4
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: LocalTime
                                                      • String ID: %.3d$X64
                                                      • API String ID: 481472006-1077770165
                                                      • Opcode ID: 7110b61ffbe97b82b312c7f374fa5a5703d167400860c87300c3b0d261b88ea1
                                                      • Instruction ID: df0cb18d1ddec9aa742374055d307fbc4bcf8584641ed9bd7d9ab1f796f90e1b
                                                      • Opcode Fuzzy Hash: 7110b61ffbe97b82b312c7f374fa5a5703d167400860c87300c3b0d261b88ea1
                                                      • Instruction Fuzzy Hash: 5BD012A180931CEACBD096E0CC49DB9B37CFB18305F508466F80AD1080D768E948AB61
                                                      APIs
                                                      • FindWindowW.USER32(Shell_TrayWnd,00000000), ref: 0084232C
                                                      • PostMessageW.USER32(00000000,00000111,00000197,00000000), ref: 0084233F
                                                        • Part of subcall function 0081E97B: Sleep.KERNEL32 ref: 0081E9F3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FindMessagePostSleepWindow
                                                      • String ID: Shell_TrayWnd
                                                      • API String ID: 529655941-2988720461
                                                      • Opcode ID: c8576065b501445a9aae6b6921dc2c580df56daef686a73fc5c60daae4d3c665
                                                      • Instruction ID: 936b23977f1e719fe3cf86902c85832c08ded0b433b843a78ac64a7cf2d884d5
                                                      • Opcode Fuzzy Hash: c8576065b501445a9aae6b6921dc2c580df56daef686a73fc5c60daae4d3c665
                                                      • Instruction Fuzzy Hash: 20D0A93A381300B6E2E8A7309C0FFCA6A18BB00B00F018A06770AEA1D0C8A4A801CA00
                                                      APIs
                                                      • FindWindowW.USER32(Shell_TrayWnd,00000000), ref: 0084236C
                                                      • PostMessageW.USER32(00000000), ref: 00842373
                                                        • Part of subcall function 0081E97B: Sleep.KERNEL32 ref: 0081E9F3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: FindMessagePostSleepWindow
                                                      • String ID: Shell_TrayWnd
                                                      • API String ID: 529655941-2988720461
                                                      • Opcode ID: 4e1c624e1da4bd6ac43389eddc581ab89d77dc7f6dae138402ec877548a2774a
                                                      • Instruction ID: 2d36e448977bbaa1e62ed39db9f3ddd06f4e3404d43831596448da2c508375ae
                                                      • Opcode Fuzzy Hash: 4e1c624e1da4bd6ac43389eddc581ab89d77dc7f6dae138402ec877548a2774a
                                                      • Instruction Fuzzy Hash: A6D0A9363823007AE2E8A7309C0FFCA6A18BB01B00F018A06770AEA1D0C8A4A801CA04
                                                      APIs
                                                      • MultiByteToWideChar.KERNEL32(?,00000009,?,00000000,00000000,?,?,?,00000000,?,?,?,?,?,00000000,?), ref: 007EBE93
                                                      • GetLastError.KERNEL32 ref: 007EBEA1
                                                      • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 007EBEFC
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.2995331170.00000000007B1000.00000020.00000001.01000000.00000003.sdmp, Offset: 007B0000, based on PE: true
                                                      • Associated: 00000000.00000002.2995309572.00000000007B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.000000000084C000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995392271.0000000000872000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995446263.000000000087C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                      • Associated: 00000000.00000002.2995464370.0000000000884000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_7b0000_file.jbxd
                                                      Similarity
                                                      • API ID: ByteCharMultiWide$ErrorLast
                                                      • String ID:
                                                      • API String ID: 1717984340-0
                                                      • Opcode ID: 7b6ada164a8ca295b88806f991881dc366a0924043faf2c6e5892e392aa0dff9
                                                      • Instruction ID: 6ab9e0bb520bff7adada0835ff20473fbf7aa37c125d7e425345c7e21e527321
                                                      • Opcode Fuzzy Hash: 7b6ada164a8ca295b88806f991881dc366a0924043faf2c6e5892e392aa0dff9
                                                      • Instruction Fuzzy Hash: 5341D735602286EFCF218FA6CC84ABB7FA5AF49310F144169F959972A1DB349D01DB60