Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1527551
MD5:86b442edece0f1e7d7f46682a4e6b6a6
SHA1:323c00335af743e946abd85b3b255e39cc06974d
SHA256:304be29a6ee0ea7ac9d692efc23fff85c4e5b6348790e6d30f5ef324dd36da57
Tags:exeuser-Bitsight
Infos:

Detection

Credential Flusher
Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected Credential Flusher
AI detected suspicious sample
Binary is likely a compiled AutoIt script file
Found API chain indicative of sandbox detection
Machine Learning detection for sample
Contains functionality for read data from the clipboard
Contains functionality to block mouse and keyboard input (often used to hinder debugging)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to execute programs as a different user
Contains functionality to launch a process as a different user
Contains functionality to launch a program with higher privileges
Contains functionality to modify clipboard data
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality to simulate keystroke presses
Contains functionality to simulate mouse events
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
OS version to string mapping found (often used in BOTs)
Potential key logger detected (key state polling based)
Sample execution stops while process was sleeping (likely an evasion)
Sleep loop found (likely to delay execution)
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses taskkill to terminate processes

Classification

  • System is w10x64
  • file.exe (PID: 6740 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 86B442EDECE0F1E7D7F46682A4E6B6A6)
    • taskkill.exe (PID: 6840 cmdline: taskkill /F /IM chrome.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 6864 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskkill.exe (PID: 7052 cmdline: taskkill /F /IM msedge.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 7056 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskkill.exe (PID: 4600 cmdline: taskkill /F /IM firefox.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 4944 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskkill.exe (PID: 4960 cmdline: taskkill /F /IM opera.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 5016 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • taskkill.exe (PID: 5728 cmdline: taskkill /F /IM brave.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
      • conhost.exe (PID: 2764 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • chrome.exe (PID: 4308 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobars MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 796 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 7856 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5448 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 7864 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5484 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Process Memory Space: file.exe PID: 6740JoeSecurity_CredentialFlusherYara detected Credential FlusherJoe Security
    No Sigma rule has matched
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: file.exeReversingLabs: Detection: 23%
    Source: file.exeVirustotal: Detection: 26%Perma Link
    Source: Submited SampleIntegrated Neural Analysis Model: Matched 96.9% probability
    Source: file.exeJoe Sandbox ML: detected
    Source: file.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
    Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.4:49768 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:49784 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:49792 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.4:49805 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:49829 version: TLS 1.2
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AEDBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose,0_2_00AEDBBE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF68EE FindFirstFileW,FindClose,0_2_00AF68EE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime,0_2_00AF698F
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AED076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose,0_2_00AED076
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AED3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose,0_2_00AED3A9
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF9642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose,0_2_00AF9642
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose,0_2_00AF979D
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF9B2B FindFirstFileW,Sleep,FindNextFileW,FindClose,0_2_00AF9B2B
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF5C97 FindFirstFileW,FindNextFileW,FindClose,0_2_00AF5C97
    Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
    Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
    Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.45
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AFCE44 InternetReadFile,SetEvent,GetLastError,SetEvent,0_2_00AFCE44
    Source: global trafficHTTP traffic detected: GET /account?=https://accounts.google.com/v3/signin/challenge/pwd HTTP/1.1Host: youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /account?=https%3A%2F%2Faccounts.google.com%2Fv3%2Fsignin%2Fchallenge%2Fpwd HTTP/1.1Host: www.youtube.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=omnWoqYJUmg
    Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
    Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "117.0.5938.132"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-wow64: ?0sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://accounts.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=518=XqXSGk8CZxiaCMiwLFRVwsG2tQluZDiR1GeHv-GYN2qxkc4CxtV0kkehhaL_vC-lHBHOFrVZ0DtMoFE4hltcihsBAfG_XKsV1dVm4zl0OcORrh_rNX7k189D_YuqEK0zBGitfKeNj2pX7donU1Sbu2-IeLkiwASuK6ThYvdsKQE24b2aag
    Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=gs1szRCNStTUBPy&MD=nnK7C6a5 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
    Source: global trafficHTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120600v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule224902v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120402v21s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120608v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120609v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120611v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120612v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120613v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120610v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120614v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120615v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120619v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120616v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120618v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120617v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120622v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120624v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120620v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120621v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120623v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=gs1szRCNStTUBPy&MD=nnK7C6a5 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
    Source: global trafficHTTP traffic detected: GET /rules/rule120625v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120628v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120629v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120626v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120627v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120630v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120631v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120633v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120632v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120634v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120635v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120636v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120637v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120639v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120638v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120640v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120641v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120642v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120643v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120644v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120645v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120646v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120649v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120647v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120648v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120653v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120652v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120654v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120655v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120657v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120658v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120659v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120656v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120660v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120661v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120663v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120662v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120664v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120665v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120666v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120669v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120667v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120668v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120670v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120671v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120672v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120673v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120674v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120675v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120676v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120677v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120678v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120679v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120680v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120681v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120682v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120602v10s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120601v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule224901v11s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule90401v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700401v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700400v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703901v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703900v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703350v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703351v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703501v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703500v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703401v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703400v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703601v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703600v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703851v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703850v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703801v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703800v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703701v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703700v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703751v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703750v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704051v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704050v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700600v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700601v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703951v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703950v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700001v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700000v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701401v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701400v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703051v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703050v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703551v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703550v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704001v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704000v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702401v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702400v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702601v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702600v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule700650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703301v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule703300v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule702450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule701100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120128v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230104v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230157v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230158v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230162v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230164v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230165v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230166v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230167v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230168v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230169v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230170v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230171v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230172v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230173v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule230174v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule120119v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule224900v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704101v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704100v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704201v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704200v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704151v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule704150v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: global trafficHTTP traffic detected: GET /rules/rule226009v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
    Source: chromecache_76.13.drString found in binary or memory: _.iq(p)+"/familylink/privacy/notice/embedded?langCountry="+_.iq(p);break;case "PuZJUb":a+="https://www.youtube.com/t/terms?chromeless=1&hl="+_.iq(m);break;case "fxTQxb":a+="https://youtube.com/t/terms?gl="+_.iq(_.rq(c))+"&hl="+_.iq(d)+"&override_hl=1"+(f?"&linkless=1":"");break;case "prAmvd":a+="https://www.google.com/intl/"+_.iq(m)+"/chromebook/termsofservice.html?languageCode="+_.iq(d)+"&regionCode="+_.iq(c);break;case "NfnTze":a+="https://policies.google.com/privacy/google-partners"+(f?"/embedded": equals www.youtube.com (Youtube)
    Source: global trafficDNS traffic detected: DNS query: youtube.com
    Source: global trafficDNS traffic detected: DNS query: www.youtube.com
    Source: global trafficDNS traffic detected: DNS query: www.google.com
    Source: global trafficDNS traffic detected: DNS query: accounts.youtube.com
    Source: global trafficDNS traffic detected: DNS query: play.google.com
    Source: unknownHTTP traffic detected: POST /log?format=json&hasfast=true&authuser=0 HTTP/1.1Host: play.google.comConnection: keep-aliveContent-Length: 519sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"Content-Type: application/x-www-form-urlencoded;charset=UTF-8sec-ch-ua-full-version: "117.0.5938.132"sec-ch-ua-platform-version: "10.0.0"X-Goog-AuthUser: 0sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-wow64: ?0sec-ch-ua-platform: "Windows"Accept: */*Origin: https://accounts.google.comX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://accounts.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: chromecache_76.13.drString found in binary or memory: https://accounts.google.com
    Source: chromecache_76.13.drString found in binary or memory: https://accounts.google.com/TOS?loc=
    Source: chromecache_88.13.drString found in binary or memory: https://apis.google.com/js/api.js
    Source: chromecache_76.13.drString found in binary or memory: https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessage
    Source: chromecache_76.13.drString found in binary or memory: https://families.google.com/intl/
    Source: chromecache_88.13.drString found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/drive_2020q4/v10/192px.svg
    Source: chromecache_88.13.drString found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/gmail_2020q4/v10/web-48dp/logo_gmail_2020q4_color_2x_web_
    Source: chromecache_88.13.drString found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/maps/v7/192px.svg
    Source: chromecache_76.13.drString found in binary or memory: https://g.co/recover
    Source: chromecache_76.13.drString found in binary or memory: https://play.google.com/log?format=json&hasfast=true
    Source: chromecache_76.13.drString found in binary or memory: https://play.google.com/work/enroll?identifier=
    Source: chromecache_76.13.drString found in binary or memory: https://play.google/intl/
    Source: chromecache_76.13.drString found in binary or memory: https://policies.google.com/privacy
    Source: chromecache_76.13.drString found in binary or memory: https://policies.google.com/privacy/additional
    Source: chromecache_76.13.drString found in binary or memory: https://policies.google.com/privacy/google-partners
    Source: chromecache_76.13.drString found in binary or memory: https://policies.google.com/technologies/cookies
    Source: chromecache_76.13.drString found in binary or memory: https://policies.google.com/technologies/location-data
    Source: chromecache_76.13.drString found in binary or memory: https://policies.google.com/terms
    Source: chromecache_76.13.drString found in binary or memory: https://policies.google.com/terms/location
    Source: chromecache_76.13.drString found in binary or memory: https://policies.google.com/terms/service-specific
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-email-pin.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-password.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-sms-or-voice-pin.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-sms-pin.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-stop-go-landing-page_1x.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/animation/
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/ble_device.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/ble_pin.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync_1x.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync_2x.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync_darkmode_1x.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/continue_on_your_phone.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_phone_number_verification.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_prompt_silent_tap_yes_darkmode.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_prompt_tap_yes.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_prompt_tap_yes_darkmode.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kid_success.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kid_success_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_dark_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_updated.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_updated_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_not_ready.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_stick_around_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_stick_around_dark_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_account_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_account_darkmode_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_privacy_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_privacy_darkmode_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_created.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_double_device.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_double_device_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_full_house.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_link_accounts_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_link_accounts_darkmode_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_app_decision.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_app_decision_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_supervision_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_supervision_darkmode_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_respect_others_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_respect_others_darkmode_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_single_device.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_single_device_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_stop.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/personalization_reminders.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/phone_number_sign_in_2x.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/return_to_desktop.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/return_to_desktop_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_ios_center.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_laptop.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_nfc_discovered.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_nfc_discovered_darkmode.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_phone.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_googleapp_ios.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_googleapp_pulldown.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_tapyes.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/smart_lock_2x.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/usb_key.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/web_and_app_activity.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/who_will_be_using_this_device.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/embedded/you_tube_history.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/feature_not_available.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/feature_not_available_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/gmail_ios_authzen.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/paaskey.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_challenge.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_challenge_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_cross_device.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_cross_device_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_error.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_error_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_reauth.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_reauth_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_success.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_success_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkeyerror.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkeyerror_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/red_globe_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/red_globe_light.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/screenlock.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_ipad.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone_nfc.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone_usb.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_phone.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_keys.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/success_checkmark_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/marc/success_checkmark_2_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/ui/loading_spinner_gm.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/ui/progress_spinner_color_20dp_4x.gif
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/accounts/ui/success-gm-default_2x.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/apps/signup/resources/custom-email-address.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/images/hpp/shield_security_checkup_green_2x_web_96dp.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/account_setup_chapter_dark_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/account_setup_chapter_v1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/device_setup_chapter_dark_v1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/device_setup_chapter_v1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/parental_control_chapter_dark_v1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/parental_control_chapter_v1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_accountslinked.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_accountslinked_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_childneedshelp.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_childneedshelp_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_nextstepsforparents.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_nextstepsforparents_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_allset.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_allset_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_apps_devices.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_apps_devices_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_areyousurekid.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_areyousurekid_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_birthdayemail.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_birthdayemail_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_choose_apps.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_choose_apps_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_confirmation.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_exploremore.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_exploremore_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_intro.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_intro_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacy_terms_a18.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacy_terms_a18_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacyterms.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacyterms_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_review_settings.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_review_settings_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_safe_search.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_safe_search_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_success_unchanged_a18.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_success_unchanged_a18_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_success_update_a18.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_success_update_a18_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice_a18.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice_a18_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervisiongrad.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervisiongrad_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/guardianlinking/linking_complete_0.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/guardianlinking/linking_complete_dark_0.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/ads_personalization.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/ads_personalization_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/confirmation.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/confirmation_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/eligibility_error.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/eligibility_error_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/fork.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/fork_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/intro.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/intro_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/personal_results.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/personal_results_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/safe_search.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/safe_search_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/check_notifications.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/check_notifications_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_installing_family_link_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_installing_family_link_dark_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_location_sharing_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_location_sharing_dark_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_parental_controls_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_parental_controls_dark_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_school_time_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_school_time_dark_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/location_sharing_enabled_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/location_sharing_enabled_dark_3.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/parent_sign_in_prologue_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/parent_sign_in_prologue_dark_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_complete_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_complete_dark_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_contacts_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_contacts_dark_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_family_link_boy_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_family_link_boy_dark_1.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_family_link_girl_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_family_link_girl_dark_2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/ulp_continue_without_gmail_dark_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/ulp_continue_without_gmail_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/all_set.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/all_set_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/are_you_sure_parent.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/are_you_sure_parent_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/content_restriction.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/content_restriction_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/error.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/error_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/how_controls_work.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/how_controls_work_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/next_steps.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/next_steps_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/setup_controls.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/setup_controls_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_parent.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_parent_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_teen.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_teen_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teentoadultgraduation/supervision_choice.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/teentoadultgraduation/supervision_choice_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/kid_setup_parent_escalation.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/kid_setup_parent_escalation_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/send_email_confirmation.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/send_email_confirmation_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/success_sent_email.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/success_sent_email_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulpupgrade/kidprofileupgrade_all_set.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/images/ulpupgrade/kidprofileupgrade_all_set_darkmode.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/all_set.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/all_set_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/almost_done_kids_space_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/almost_done_kids_space_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_tablet_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_tablet_v2_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_v2_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/emailinstallfamilylink.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/emailinstallfamilylink_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/familylinkinstalling.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/familylinkinstalling_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/hand_over_device_dark_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/hand_over_device_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/linking_accounts_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/linking_accounts_v2_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/locationsetup.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/locationsetup_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_email.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_email_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_email_v2_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_v2_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/open_family_link_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/open_family_link_v2_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/parents_help.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/parents_help_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/set_up_kids_space.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/set_up_kids_space_dark.png
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setupcontrol.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setupcontrol_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuplocation.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuplocation_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuptimelimits.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuptimelimits_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/supervision_ready_v2.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/supervision_ready_v2_dark.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/youtubeaccess.svg
    Source: chromecache_88.13.drString found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/youtubeaccess_dark.svg
    Source: chromecache_76.13.drString found in binary or memory: https://support.google.com/accounts?hl=
    Source: chromecache_76.13.drString found in binary or memory: https://support.google.com/accounts?p=new-si-ui
    Source: chromecache_76.13.drString found in binary or memory: https://support.google.com/websearch/answer/4358949?hl=ko&ref_topic=3285072
    Source: chromecache_88.13.drString found in binary or memory: https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
    Source: chromecache_76.13.drString found in binary or memory: https://www.google.com
    Source: chromecache_76.13.drString found in binary or memory: https://www.google.com/intl/
    Source: chromecache_88.13.drString found in binary or memory: https://www.gstatic.com/accounts/speedbump/authzen_optin_illustration.gif
    Source: chromecache_88.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/chrome_48dp.png
    Source: chromecache_88.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/googleg_48dp.png
    Source: chromecache_88.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/gsa_48dp.png
    Source: chromecache_88.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/play_prism_48dp.png
    Source: chromecache_88.13.drString found in binary or memory: https://www.gstatic.com/images/branding/product/2x/youtube_48dp.png
    Source: chromecache_76.13.drString found in binary or memory: https://www.gstatic.com/images/branding/productlogos/googleg/v6/36px.svg
    Source: chromecache_76.13.drString found in binary or memory: https://www.youtube.com/t/terms?chromeless=1&hl=
    Source: file.exe, 00000000.00000003.1753689047.0000000000984000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd
    Source: file.exe, 00000000.00000002.2984741151.0000000000C38000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwdir=C:
    Source: chromecache_76.13.drString found in binary or memory: https://youtube.com/t/terms?gl=
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49986
    Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49985
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49984
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49983
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49982
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49981
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49980
    Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49990 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49979
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49978
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49977
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49976
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
    Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49975
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49974
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49973
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49972
    Source: unknownNetwork traffic detected: HTTP traffic on port 50039 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49971
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49970
    Source: unknownNetwork traffic detected: HTTP traffic on port 49967 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50004 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49943 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49969
    Source: unknownNetwork traffic detected: HTTP traffic on port 49978 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
    Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49968
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49967
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49966
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49965
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49964
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49963
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49961
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
    Source: unknownNetwork traffic detected: HTTP traffic on port 50015 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50040 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49966 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49989 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50028 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49959
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49958
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
    Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49956
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49955
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
    Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49954
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
    Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
    Source: unknownNetwork traffic detected: HTTP traffic on port 49944 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50051 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49955 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49944
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49943
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
    Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
    Source: unknownNetwork traffic detected: HTTP traffic on port 49945 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
    Source: unknownNetwork traffic detected: HTTP traffic on port 50017 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
    Source: unknownNetwork traffic detected: HTTP traffic on port 49968 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50049 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50026 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49980 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49895
    Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
    Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49911 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49957 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49991 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
    Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
    Source: unknownNetwork traffic detected: HTTP traffic on port 50038 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49882
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
    Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
    Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50050 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49956 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50005 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49979 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49999
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49998
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49997
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49996
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49995
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
    Source: unknownNetwork traffic detected: HTTP traffic on port 49923 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49994
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49993
    Source: unknownNetwork traffic detected: HTTP traffic on port 50016 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49991
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49990
    Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50027 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49989
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49988
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49987
    Source: unknownNetwork traffic detected: HTTP traffic on port 50013 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50036 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49906 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49975 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50025 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49964 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49999 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49918 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50001 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49986 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49963 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50007
    Source: unknownNetwork traffic detected: HTTP traffic on port 50037 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50006
    Source: unknownNetwork traffic detected: HTTP traffic on port 50012 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50009
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50008
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
    Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
    Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50001
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50000
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50003
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50002
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50005
    Source: unknownNetwork traffic detected: HTTP traffic on port 49895 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50004
    Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49907 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49941 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
    Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49997 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50003 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49965 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49977 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50035 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49919 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49988 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50046 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49976 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49953 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50047 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49908 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50024 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49998 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49931 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50058 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50002 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49987 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50054
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50053
    Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50056
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50055
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50058
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50057
    Source: unknownNetwork traffic detected: HTTP traffic on port 49961 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49984 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50022 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50045 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49950 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49996 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50010 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50056 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49915 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50034 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49972 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50057 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49927 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49983 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50023 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50018
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50017
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50019
    Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49974 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50032 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50010
    Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50012
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50011
    Source: unknownNetwork traffic detected: HTTP traffic on port 50055 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50014
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50013
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50016
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50015
    Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50029
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50028
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50021
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50020
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50023
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50022
    Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50025
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50024
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50027
    Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50026
    Source: unknownNetwork traffic detected: HTTP traffic on port 49985 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50000 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50021 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50030
    Source: unknownNetwork traffic detected: HTTP traffic on port 49905 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50039
    Source: unknownNetwork traffic detected: HTTP traffic on port 49995 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50011 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50032
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50031
    Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50034
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50033
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50036
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50035
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50038
    Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50037
    Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49940 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50041
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50040
    Source: unknownNetwork traffic detected: HTTP traffic on port 49973 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50033 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50043
    Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49917 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50042
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50045
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50044
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50047
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50046
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50049
    Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50050
    Source: unknownNetwork traffic detected: HTTP traffic on port 49962 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50052
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50051
    Source: unknownNetwork traffic detected: HTTP traffic on port 50044 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49970 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50042 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50007 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49912 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49935 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49958 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50018 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50053 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49981 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49924 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49947 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50031 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49992 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50043 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49969 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49994 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50020 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50054 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49913 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50006 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
    Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
    Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49941
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49940
    Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50052 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49938
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
    Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49937
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
    Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49934
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
    Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.4:49768 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:49784 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:49792 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.4:49805 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:49829 version: TLS 1.2
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AFEAFF OpenClipboard,IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetClipboardData,CloseClipboard,GlobalLock,CloseClipboard,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,DragQueryFileW,DragQueryFileW,DragQueryFileW,GlobalUnlock,CountClipboardFormats,CloseClipboard,0_2_00AFEAFF
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AFED6A OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,OpenClipboard,EmptyClipboard,SetClipboardData,CloseClipboard,0_2_00AFED6A
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AFEAFF OpenClipboard,IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetClipboardData,CloseClipboard,GlobalLock,CloseClipboard,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,DragQueryFileW,DragQueryFileW,DragQueryFileW,GlobalUnlock,CountClipboardFormats,CloseClipboard,0_2_00AFEAFF
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AEAA57 GetKeyboardState,SetKeyboardState,PostMessageW,SendInput,0_2_00AEAA57
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00B19576 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW,0_2_00B19576

    System Summary

    barindex
    Source: file.exeString found in binary or memory: This is a third-party compiled AutoIt script.
    Source: file.exe, 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: This is a third-party compiled AutoIt script.memstr_4a556535-e
    Source: file.exe, 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: AnyArabicArmenianAvestanBalineseBamumBassa_VahBatakBengaliBopomofoBrahmiBrailleBugineseBuhidCCanadian_AboriginalCarianCaucasian_AlbanianCcCfChakmaChamCherokeeCnCoCommonCopticCsCuneiformCypriotCyrillicDeseretDevanagariDuployanEgyptian_HieroglyphsElbasanEthiopicGeorgianGlagoliticGothicGranthaGreekGujaratiGurmukhiHanHangulHanunooHebrewHiraganaImperial_AramaicInheritedInscriptional_PahlaviInscriptional_ParthianJavaneseKaithiKannadaKatakanaKayah_LiKharoshthiKhmerKhojkiKhudawadiLL&LaoLatinLepchaLimbuLinear_ALinear_BLisuLlLmLoLtLuLycianLydianMMahajaniMalayalamMandaicManichaeanMcMeMeetei_MayekMende_KikakuiMeroitic_CursiveMeroitic_HieroglyphsMiaoMnModiMongolianMroMyanmarNNabataeanNdNew_Tai_LueNkoNlNoOghamOl_ChikiOld_ItalicOld_North_ArabianOld_PermicOld_PersianOld_South_ArabianOld_TurkicOriyaOsmanyaPPahawh_HmongPalmyrenePau_Cin_HauPcPdPePfPhags_PaPhoenicianPiPoPsPsalter_PahlaviRejangRunicSSamaritanSaurashtraScSharadaShavianSiddhamSinhalaSkSmSoSora_SompengSundaneseSyloti_NagriSyriacTagalogTagbanwaTai_LeTai_ThamTai_VietTakriTamilTeluguThaanaThaiTibetanTifinaghTirhutaUgariticVaiWarang_CitiXanXpsXspXucXwdYiZZlZpZsSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBoxSHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainermemstr_9d980d94-7
    Source: file.exeString found in binary or memory: This is a third-party compiled AutoIt script.memstr_5478b6a0-5
    Source: file.exeString found in binary or memory: AnyArabicArmenianAvestanBalineseBamumBassa_VahBatakBengaliBopomofoBrahmiBrailleBugineseBuhidCCanadian_AboriginalCarianCaucasian_AlbanianCcCfChakmaChamCherokeeCnCoCommonCopticCsCuneiformCypriotCyrillicDeseretDevanagariDuployanEgyptian_HieroglyphsElbasanEthiopicGeorgianGlagoliticGothicGranthaGreekGujaratiGurmukhiHanHangulHanunooHebrewHiraganaImperial_AramaicInheritedInscriptional_PahlaviInscriptional_ParthianJavaneseKaithiKannadaKatakanaKayah_LiKharoshthiKhmerKhojkiKhudawadiLL&LaoLatinLepchaLimbuLinear_ALinear_BLisuLlLmLoLtLuLycianLydianMMahajaniMalayalamMandaicManichaeanMcMeMeetei_MayekMende_KikakuiMeroitic_CursiveMeroitic_HieroglyphsMiaoMnModiMongolianMroMyanmarNNabataeanNdNew_Tai_LueNkoNlNoOghamOl_ChikiOld_ItalicOld_North_ArabianOld_PermicOld_PersianOld_South_ArabianOld_TurkicOriyaOsmanyaPPahawh_HmongPalmyrenePau_Cin_HauPcPdPePfPhags_PaPhoenicianPiPoPsPsalter_PahlaviRejangRunicSSamaritanSaurashtraScSharadaShavianSiddhamSinhalaSkSmSoSora_SompengSundaneseSyloti_NagriSyriacTagalogTagbanwaTai_LeTai_ThamTai_VietTakriTamilTeluguThaanaThaiTibetanTifinaghTirhutaUgariticVaiWarang_CitiXanXpsXspXucXwdYiZZlZpZsSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBoxSHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainermemstr_b173dcd2-c
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AED5EB: CreateFileW,DeviceIoControl,CloseHandle,0_2_00AED5EB
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AE1201 LogonUserW,DuplicateTokenEx,CloseHandle,OpenWindowStationW,GetProcessWindowStation,SetProcessWindowStation,OpenDesktopW,_wcslen,LoadUserProfileW,CreateEnvironmentBlock,CreateProcessAsUserW,UnloadUserProfile,GetProcessHeap,HeapFree,CloseWindowStation,CloseDesktop,SetProcessWindowStation,CloseHandle,DestroyEnvironmentBlock,0_2_00AE1201
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AEE8F6 ExitWindowsEx,InitiateSystemShutdownExW,SetSystemPowerState,0_2_00AEE8F6
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A880600_2_00A88060
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF20460_2_00AF2046
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AE82980_2_00AE8298
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00ABE4FF0_2_00ABE4FF
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AB676B0_2_00AB676B
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00B148730_2_00B14873
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AACAA00_2_00AACAA0
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A8CAF00_2_00A8CAF0
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A9CC390_2_00A9CC39
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AB6DD90_2_00AB6DD9
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A9D0630_2_00A9D063
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A891C00_2_00A891C0
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A9B1190_2_00A9B119
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA13940_2_00AA1394
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA17060_2_00AA1706
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA781B0_2_00AA781B
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA19B00_2_00AA19B0
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A879200_2_00A87920
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A9997D0_2_00A9997D
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA7A4A0_2_00AA7A4A
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA7CA70_2_00AA7CA7
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA1C770_2_00AA1C77
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AB9EEE0_2_00AB9EEE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00B0BE440_2_00B0BE44
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA1F320_2_00AA1F32
    Source: C:\Users\user\Desktop\file.exeCode function: String function: 00A9F9F2 appears 31 times
    Source: C:\Users\user\Desktop\file.exeCode function: String function: 00AA0A30 appears 46 times
    Source: file.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
    Source: classification engineClassification label: mal72.troj.evad.winEXE@46/30@12/6
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF37B5 GetLastError,FormatMessageW,0_2_00AF37B5
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AE10BF AdjustTokenPrivileges,CloseHandle,0_2_00AE10BF
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AE16C3 LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,0_2_00AE16C3
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF51CD SetErrorMode,GetDiskFreeSpaceExW,SetErrorMode,0_2_00AF51CD
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00B0A67C CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,0_2_00B0A67C
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF648E _wcslen,CoInitialize,CoCreateInstance,CoUninitialize,0_2_00AF648E
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A842A2 CreateStreamOnHGlobal,FindResourceExW,LoadResource,SizeofResource,LockResource,0_2_00A842A2
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2764:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5016:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7056:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4944:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6864:120:WilError_03
    Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
    Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: file.exeReversingLabs: Detection: 23%
    Source: file.exeVirustotal: Detection: 26%
    Source: unknownProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /T
    Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobars
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5448 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5484 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobarsJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5448 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5484 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: wsock32.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: version.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: winmm.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
    Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
    Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A842DE GetVersionExW,GetCurrentProcess,IsWow64Process,LoadLibraryA,GetProcAddress,GetNativeSystemInfo,FreeLibrary,GetSystemInfo,GetSystemInfo,0_2_00A842DE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA0A76 push ecx; ret 0_2_00AA0A89
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A9F98E GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,0_2_00A9F98E
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00B11C41 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed,0_2_00B11C41
    Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

    Malware Analysis System Evasion

    barindex
    Source: C:\Users\user\Desktop\file.exeSandbox detection routine: GetForegroundWindow, DecisionNode, Sleepgraph_0-96264
    Source: C:\Users\user\Desktop\file.exeWindow / User API: threadDelayed 7218Jump to behavior
    Source: C:\Users\user\Desktop\file.exeWindow / User API: foregroundWindowGot 1775Jump to behavior
    Source: C:\Users\user\Desktop\file.exeAPI coverage: 3.7 %
    Source: C:\Users\user\Desktop\file.exe TID: 6764Thread sleep time: -72180s >= -30000sJump to behavior
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Users\user\Desktop\file.exeThread sleep count: Count: 7218 delay: -10Jump to behavior
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AEDBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose,0_2_00AEDBBE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF68EE FindFirstFileW,FindClose,0_2_00AF68EE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime,0_2_00AF698F
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AED076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose,0_2_00AED076
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AED3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose,0_2_00AED3A9
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF9642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose,0_2_00AF9642
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose,0_2_00AF979D
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF9B2B FindFirstFileW,Sleep,FindNextFileW,FindClose,0_2_00AF9B2B
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF5C97 FindFirstFileW,FindNextFileW,FindClose,0_2_00AF5C97
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A842DE GetVersionExW,GetCurrentProcess,IsWow64Process,LoadLibraryA,GetProcAddress,GetNativeSystemInfo,FreeLibrary,GetSystemInfo,GetSystemInfo,0_2_00A842DE
    Source: C:\Users\user\Desktop\file.exeProcess information queried: ProcessInformationJump to behavior
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AFEAA2 BlockInput,0_2_00AFEAA2
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AB2622 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00AB2622
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A842DE GetVersionExW,GetCurrentProcess,IsWow64Process,LoadLibraryA,GetProcAddress,GetNativeSystemInfo,FreeLibrary,GetSystemInfo,GetSystemInfo,0_2_00A842DE
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA4CE8 mov eax, dword ptr fs:[00000030h]0_2_00AA4CE8
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AE0B62 GetSecurityDescriptorDacl,GetAclInformation,GetLengthSid,GetLengthSid,GetAce,AddAce,GetLengthSid,GetProcessHeap,HeapAlloc,GetLengthSid,CopySid,AddAce,SetSecurityDescriptorDacl,SetUserObjectSecurity,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,0_2_00AE0B62
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AB2622 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00AB2622
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA083F IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00AA083F
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA09D5 SetUnhandledExceptionFilter,0_2_00AA09D5
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA0C21 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00AA0C21
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AE1201 LogonUserW,DuplicateTokenEx,CloseHandle,OpenWindowStationW,GetProcessWindowStation,SetProcessWindowStation,OpenDesktopW,_wcslen,LoadUserProfileW,CreateEnvironmentBlock,CreateProcessAsUserW,UnloadUserProfile,GetProcessHeap,HeapFree,CloseWindowStation,CloseDesktop,SetProcessWindowStation,CloseHandle,DestroyEnvironmentBlock,0_2_00AE1201
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AC2BA5 KiUserCallbackDispatcher,SetCurrentDirectoryW,GetForegroundWindow,ShellExecuteW,0_2_00AC2BA5
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AEB226 SendInput,keybd_event,0_2_00AEB226
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00B022DA GetForegroundWindow,GetDesktopWindow,GetWindowRect,mouse_event,GetCursorPos,mouse_event,0_2_00B022DA
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM chrome.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM msedge.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM firefox.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM opera.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\taskkill.exe taskkill /F /IM brave.exe /TJump to behavior
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AE0B62 GetSecurityDescriptorDacl,GetAclInformation,GetLengthSid,GetLengthSid,GetAce,AddAce,GetLengthSid,GetProcessHeap,HeapAlloc,GetLengthSid,CopySid,AddAce,SetSecurityDescriptorDacl,SetUserObjectSecurity,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,0_2_00AE0B62
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AE1663 AllocateAndInitializeSid,CheckTokenMembership,FreeSid,0_2_00AE1663
    Source: file.exeBinary or memory string: Run Script:AutoIt script files (*.au3, *.a3x)*.au3;*.a3xAll files (*.*)*.*au3#include depth exceeded. Make sure there are no recursive includesError opening the file>>>AUTOIT SCRIPT<<<Bad directive syntax errorUnterminated stringCannot parse #includeUnterminated group of commentsONOFF0%d%dShell_TrayWndREMOVEKEYSEXISTSAPPENDblankinfoquestionstopwarning
    Source: file.exeBinary or memory string: Shell_TrayWnd
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AA0698 cpuid 0_2_00AA0698
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00AF8195 GetLocalTime,SystemTimeToFileTime,LocalFileTimeToFileTime,GetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,0_2_00AF8195
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00ADD27A GetUserNameW,0_2_00ADD27A
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00ABBB6F _free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,0_2_00ABBB6F
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00A842DE GetVersionExW,GetCurrentProcess,IsWow64Process,LoadLibraryA,GetProcAddress,GetNativeSystemInfo,FreeLibrary,GetSystemInfo,GetSystemInfo,0_2_00A842DE

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: Process Memory Space: file.exe PID: 6740, type: MEMORYSTR
    Source: file.exeBinary or memory string: WIN_81
    Source: file.exeBinary or memory string: WIN_XP
    Source: file.exeBinary or memory string: %.3d%S%M%H%m%Y%jX86IA64X64WIN32_NTWIN_11WIN_10WIN_2022WIN_2019WIN_2016WIN_81WIN_2012R2WIN_2012WIN_8WIN_2008R2WIN_7WIN_2008WIN_VISTAWIN_2003WIN_XPeWIN_XPInstallLanguageSYSTEM\CurrentControlSet\Control\Nls\LanguageSchemeLangIDControl Panel\AppearanceUSERPROFILEUSERDOMAINUSERDNSDOMAINGetSystemWow64DirectoryWSeDebugPrivilege:winapistdcallubyte64HKEY_LOCAL_MACHINEHKLMHKEY_CLASSES_ROOTHKCRHKEY_CURRENT_CONFIGHKCCHKEY_CURRENT_USERHKCUHKEY_USERSHKUREG_EXPAND_SZREG_SZREG_MULTI_SZREG_DWORDREG_QWORDREG_BINARYRegDeleteKeyExWadvapi32.dll+.-.\\[\\nrt]|%%|%[-+ 0#]?([0-9]*|\*)?(\.[0-9]*|\.\*)?[hlL]?[diouxXeEfgGs](*UCP)\XISVISIBLEISENABLEDTABLEFTTABRIGHTCURRENTTABSHOWDROPDOWNHIDEDROPDOWNADDSTRINGDELSTRINGFINDSTRINGGETCOUNTSETCURRENTSELECTIONGETCURRENTSELECTIONSELECTSTRINGISCHECKEDCHECKUNCHECKGETSELECTEDGETLINECOUNTGETCURRENTLINEGETCURRENTCOLEDITPASTEGETLINESENDCOMMANDIDGETITEMCOUNTGETSUBITEMCOUNTGETTEXTGETSELECTEDCOUNTISSELECTEDSELECTALLSELECTCLEARSELECTINVERTDESELECTFINDITEMVIEWCHANGEGETTOTALCOUNTCOLLAPSEEXPANDmsctls_statusbar321tooltips_class32%d/%02d/%02dbuttonComboboxListboxSysDateTimePick32SysMonthCal32.icl.exe.dllMsctls_Progress32msctls_trackbar32SysAnimate32msctls_updown32SysTabControl32SysTreeView32SysListView32-----@GUI_DRAGID@GUI_DROPID@GUI_DRAGFILEError text not found (please report)Q\EDEFINEUTF16)UTF)UCP)NO_AUTO_POSSESS)NO_START_OPT)LIMIT_MATCH=LIMIT_RECURSION=CR)LF)CRLF)ANY)ANYCRLF)BSR_ANYCRLF)BSR_UNICODE)argument is not a compiled regular expressionargument not compiled in 16 bit modeinternal error: opcode not recognizedinternal error: missing capturing bracketfailed to get memory
    Source: file.exeBinary or memory string: WIN_XPe
    Source: file.exeBinary or memory string: WIN_VISTA
    Source: file.exeBinary or memory string: WIN_7
    Source: file.exeBinary or memory string: WIN_8

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: Process Memory Space: file.exe PID: 6740, type: MEMORYSTR
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00B01204 socket,WSAGetLastError,bind,WSAGetLastError,closesocket,listen,WSAGetLastError,closesocket,0_2_00B01204
    Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00B01806 socket,WSAGetLastError,bind,WSAGetLastError,closesocket,0_2_00B01806
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire Infrastructure2
    Valid Accounts
    1
    Windows Management Instrumentation
    1
    DLL Side-Loading
    1
    Exploitation for Privilege Escalation
    2
    Disable or Modify Tools
    21
    Input Capture
    2
    System Time Discovery
    Remote Services1
    Archive Collected Data
    2
    Ingress Tool Transfer
    Exfiltration Over Other Network Medium1
    System Shutdown/Reboot
    CredentialsDomainsDefault Accounts1
    Native API
    2
    Valid Accounts
    1
    DLL Side-Loading
    1
    Deobfuscate/Decode Files or Information
    LSASS Memory1
    Account Discovery
    Remote Desktop Protocol21
    Input Capture
    11
    Encrypted Channel
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)2
    Valid Accounts
    2
    Obfuscated Files or Information
    Security Account Manager1
    File and Directory Discovery
    SMB/Windows Admin Shares3
    Clipboard Data
    3
    Non-Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook21
    Access Token Manipulation
    1
    DLL Side-Loading
    NTDS16
    System Information Discovery
    Distributed Component Object ModelInput Capture4
    Application Layer Protocol
    Traffic DuplicationData Destruction
    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script2
    Process Injection
    2
    Valid Accounts
    LSA Secrets12
    Security Software Discovery
    SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts12
    Virtualization/Sandbox Evasion
    Cached Domain Credentials12
    Virtualization/Sandbox Evasion
    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
    DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items21
    Access Token Manipulation
    DCSync3
    Process Discovery
    Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
    Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job2
    Process Injection
    Proc Filesystem11
    Application Window Discovery
    Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
    Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
    System Owner/User Discovery
    Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet
    behaviorgraph top1 signatures2 2 Behavior Graph ID: 1527551 Sample: file.exe Startdate: 07/10/2024 Architecture: WINDOWS Score: 72 46 Multi AV Scanner detection for submitted file 2->46 48 Yara detected Credential Flusher 2->48 50 Binary is likely a compiled AutoIt script file 2->50 52 2 other signatures 2->52 7 file.exe 2->7         started        process3 signatures4 54 Binary is likely a compiled AutoIt script file 7->54 56 Found API chain indicative of sandbox detection 7->56 10 chrome.exe 1 7->10         started        13 taskkill.exe 1 7->13         started        15 taskkill.exe 1 7->15         started        17 3 other processes 7->17 process5 dnsIp6 42 192.168.2.4, 138, 443, 49282 unknown unknown 10->42 44 239.255.255.250 unknown Reserved 10->44 19 chrome.exe 10->19         started        22 chrome.exe 10->22         started        24 chrome.exe 6 10->24         started        26 conhost.exe 13->26         started        28 conhost.exe 15->28         started        30 conhost.exe 17->30         started        32 conhost.exe 17->32         started        34 conhost.exe 17->34         started        process7 dnsIp8 36 play.google.com 142.250.181.238, 443, 49761, 49762 GOOGLEUS United States 19->36 38 www.google.com 142.250.184.228, 443, 49740, 49887 GOOGLEUS United States 19->38 40 5 other IPs or domains 19->40

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    file.exe24%ReversingLabsWin32.Trojan.Generic
    file.exe26%VirustotalBrowse
    file.exe100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    youtube-ui.l.google.com0%VirustotalBrowse
    www3.l.google.com0%VirustotalBrowse
    youtube.com0%VirustotalBrowse
    accounts.youtube.com0%VirustotalBrowse
    www.google.com0%VirustotalBrowse
    www.youtube.com0%VirustotalBrowse
    play.google.com0%VirustotalBrowse
    SourceDetectionScannerLabelLink
    https://play.google/intl/0%URL Reputationsafe
    https://families.google.com/intl/0%URL Reputationsafe
    https://policies.google.com/technologies/location-data0%URL Reputationsafe
    https://apis.google.com/js/api.js0%URL Reputationsafe
    https://policies.google.com/privacy/google-partners0%URL Reputationsafe
    https://policies.google.com/terms/service-specific0%URL Reputationsafe
    https://g.co/recover0%URL Reputationsafe
    https://policies.google.com/privacy/additional0%URL Reputationsafe
    https://support.google.com/websearch/answer/4358949?hl=ko&ref_topic=32850720%URL Reputationsafe
    https://policies.google.com/technologies/cookies0%URL Reputationsafe
    https://policies.google.com/terms0%URL Reputationsafe
    https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=0%URL Reputationsafe
    https://support.google.com/accounts?hl=0%URL Reputationsafe
    https://policies.google.com/terms/location0%URL Reputationsafe
    https://policies.google.com/privacy0%URL Reputationsafe
    https://support.google.com/accounts?p=new-si-ui0%URL Reputationsafe
    https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessage0%URL Reputationsafe
    https://youtube.com/t/terms?gl=0%VirustotalBrowse
    https://play.google.com/log?format=json&hasfast=true&authuser=00%VirustotalBrowse
    https://www.google.com/intl/1%VirustotalBrowse
    https://www.google.com/favicon.ico0%VirustotalBrowse
    https://play.google.com/work/enroll?identifier=0%VirustotalBrowse
    https://play.google.com/log?hasfast=true&authuser=0&format=json0%VirustotalBrowse
    https://play.google.com/log?format=json&hasfast=true0%VirustotalBrowse
    https://www.google.com0%VirustotalBrowse
    https://www.youtube.com/t/terms?chromeless=1&hl=0%VirustotalBrowse
    NameIPActiveMaliciousAntivirus DetectionReputation
    youtube-ui.l.google.com
    142.250.185.238
    truefalseunknown
    www3.l.google.com
    142.250.186.46
    truefalseunknown
    play.google.com
    142.250.181.238
    truefalseunknown
    www.google.com
    142.250.184.228
    truefalseunknown
    youtube.com
    142.250.186.78
    truefalseunknown
    accounts.youtube.com
    unknown
    unknownfalseunknown
    www.youtube.com
    unknown
    unknownfalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://play.google.com/log?format=json&hasfast=true&authuser=0falseunknown
    https://www.google.com/favicon.icofalseunknown
    https://play.google.com/log?hasfast=true&authuser=0&format=jsonfalseunknown
    NameSourceMaliciousAntivirus DetectionReputation
    https://play.google/intl/chromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://families.google.com/intl/chromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://youtube.com/t/terms?gl=chromecache_76.13.drfalseunknown
    https://policies.google.com/technologies/location-datachromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://www.google.com/intl/chromecache_76.13.drfalseunknown
    https://apis.google.com/js/api.jschromecache_88.13.drfalse
    • URL Reputation: safe
    unknown
    https://policies.google.com/privacy/google-partnerschromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://play.google.com/work/enroll?identifier=chromecache_76.13.drfalseunknown
    https://policies.google.com/terms/service-specificchromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://g.co/recoverchromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://policies.google.com/privacy/additionalchromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://support.google.com/websearch/answer/4358949?hl=ko&ref_topic=3285072chromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://policies.google.com/technologies/cookieschromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://policies.google.com/termschromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=chromecache_88.13.drfalse
    • URL Reputation: safe
    unknown
    https://www.google.comchromecache_76.13.drfalseunknown
    https://play.google.com/log?format=json&hasfast=truechromecache_76.13.drfalseunknown
    https://www.youtube.com/t/terms?chromeless=1&hl=chromecache_76.13.drfalseunknown
    https://support.google.com/accounts?hl=chromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://policies.google.com/terms/locationchromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://policies.google.com/privacychromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://support.google.com/accounts?p=new-si-uichromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessagechromecache_76.13.drfalse
    • URL Reputation: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    142.250.186.78
    youtube.comUnited States
    15169GOOGLEUSfalse
    142.250.185.238
    youtube-ui.l.google.comUnited States
    15169GOOGLEUSfalse
    142.250.181.238
    play.google.comUnited States
    15169GOOGLEUSfalse
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    142.250.184.228
    www.google.comUnited States
    15169GOOGLEUSfalse
    IP
    192.168.2.4
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1527551
    Start date and time:2024-10-07 02:50:08 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 5m 13s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:20
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:file.exe
    Detection:MAL
    Classification:mal72.troj.evad.winEXE@46/30@12/6
    EGA Information:
    • Successful, ratio: 100%
    HCA Information:
    • Successful, ratio: 95%
    • Number of executed functions: 41
    • Number of non-executed functions: 310
    Cookbook Comments:
    • Found application associated with file extension: .exe
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 172.217.16.195, 142.250.185.142, 74.125.71.84, 34.104.35.123, 142.250.186.163, 142.250.184.227, 172.217.16.138, 142.250.184.202, 142.250.184.234, 142.250.185.234, 172.217.18.10, 142.250.186.106, 172.217.18.106, 142.250.186.42, 216.58.206.42, 142.250.185.170, 142.250.186.138, 142.250.186.170, 142.250.181.234, 142.250.186.74, 142.250.185.202, 172.217.16.202, 142.250.74.202, 93.184.221.240, 192.229.221.95, 216.58.206.35, 74.125.206.84, 142.250.186.46
    • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, otelrules.azureedge.net, fonts.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, update.googleapis.com, clients.l.google.com, www.gstatic.com, optimizationguide-pa.googleapis.com
    • HTTPS sessions have been limited to 150. Please view the PCAPs for the complete data.
    • Not all processes where analyzed, report is missing behavior information
    • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
    No simulations
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    239.255.255.250Camtech_Korea_Invoice_2024.htmlGet hashmaliciousHTMLPhisherBrowse
      http://chiso.dev/Get hashmaliciousUnknownBrowse
        http://buddycities.com/Get hashmaliciousUnknownBrowse
          http://buckboosters.com/Get hashmaliciousUnknownBrowse
            https://wchckwl.org/Get hashmaliciousUnknownBrowse
              http://www.ngdhqw.blogspot.de/Get hashmaliciousGRQ ScamBrowse
                https://event.stibee.com/v2/click/NDA4MDIvMjQzMzA0Ny80OTAyMzcv/aHR0cHM6Ly91cHBpdHkuY28ua3IvJWVhJWI3JWI4JWViJTgyJWEwLTUlZWIlYTclOGMtJWVjJTliJTkwJWViJThjJTgwLSVlYyU4MiViYyVlYyVhMCU4NCVlYyU5ZCU4NC0lZWIlYjQlYTQlZWMlOTYlYjQlZWMlOWElOTQtMi8Get hashmaliciousUnknownBrowse
                  http://vpnpanda.org/Get hashmaliciousUnknownBrowse
                    https://ln.run/qHANsGet hashmaliciousUnknownBrowse
                      http://revexhibition.pages.dev/Get hashmaliciousHTMLPhisherBrowse
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        www3.l.google.comhttp://ak437453-76542337354.com/Get hashmaliciousUnknownBrowse
                        • 216.58.206.46
                        https://securepage.cloud/4766af00c255f04f85v8a0cf334e017e26f2.htmlGet hashmaliciousUnknownBrowse
                        • 142.250.184.206
                        http://afcudigital.biz/ebill/Get hashmaliciousHTMLPhisherBrowse
                        • 142.250.184.206
                        http://ofreverence.neocities.org/Get hashmaliciousUnknownBrowse
                        • 172.217.18.14
                        file.exeGet hashmaliciousCredential FlusherBrowse
                        • 216.58.206.46
                        file.exeGet hashmaliciousCredential FlusherBrowse
                        • 142.250.185.238
                        file.exeGet hashmaliciousCredential FlusherBrowse
                        • 142.250.74.206
                        file.exeGet hashmaliciousCredential FlusherBrowse
                        • 142.250.184.206
                        file.exeGet hashmaliciousCredential FlusherBrowse
                        • 142.250.184.206
                        file.exeGet hashmaliciousCredential FlusherBrowse
                        • 142.250.181.238
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        28a2c9bd18a11de089ef85a160da29e4SecuriteInfo.com.Trojan.DownLoader47.42925.26493.18247.exeGet hashmaliciousAmadeyBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        Camtech_Korea_Invoice_2024.htmlGet hashmaliciousHTMLPhisherBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        zncaKWwEdq.exeGet hashmaliciousVidarBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        http://chiso.dev/Get hashmaliciousUnknownBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        http://buddycities.com/Get hashmaliciousUnknownBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        http://buckboosters.com/Get hashmaliciousUnknownBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        https://wchckwl.org/Get hashmaliciousUnknownBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        http://www.ngdhqw.blogspot.de/Get hashmaliciousGRQ ScamBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        https://event.stibee.com/v2/click/NDA4MDIvMjQzMzA0Ny80OTAyMzcv/aHR0cHM6Ly91cHBpdHkuY28ua3IvJWVhJWI3JWI4JWViJTgyJWEwLTUlZWIlYTclOGMtJWVjJTliJTkwJWViJThjJTgwLSVlYyU4MiViYyVlYyVhMCU4NCVlYyU5ZCU4NC0lZWIlYjQlYTQlZWMlOTYlYjQlZWMlOWElOTQtMi8Get hashmaliciousUnknownBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        http://vpnpanda.org/Get hashmaliciousUnknownBrowse
                        • 4.175.87.197
                        • 184.28.90.27
                        • 13.107.246.45
                        No context
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (522)
                        Category:downloaded
                        Size (bytes):5050
                        Entropy (8bit):5.30005628600801
                        Encrypted:false
                        SSDEEP:96:o75BuBxJfma7bGZABddEgf8nI4zLm4KGo8Vh1EabPVTq8fv/xRw:WHMmaX9r8Igp7nBlHo
                        MD5:D9F15F1AEAF15673336FAA3507D1A2A7
                        SHA1:FC79D00AF2E2D44FEBA701F12ECD4AFCA327F464
                        SHA-256:AA3574ADCF3826390918BC2D5DCD88D7BC63238A6022DEF3487A67A731C30E7A
                        SHA-512:D756961B6BFC478274E390B94D613BD837DA011D680FC6D67779A8E12C7F082EF977FC15D02C076F92BC1D2CE7EFDE48F82B4EC1BD12CF38AEDDAB1917E36041
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,iAskyc,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziXSP,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=wg1P6b"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.oNa=_.z("wg1P6b",[_.XA,_.Fn,_.Nn]);._.k("wg1P6b");.var f6a;f6a=_.mh(["aria-"]);._.yJ=function(a){_.X.call(this,a.Fa);this.Ka=this.xa=this.aa=this.viewportElement=this.Na=null;this.Jc=a.Ea.ef;this.ab=a.Ea.focus;this.Fc=a.Ea.Fc;this.ea=this.Qi();a=-1*parseInt(_.Fo(this.Qi().el(),"marginTop")||"0",10);var b=parseInt(_.Fo(this.Qi().el(),"marginBottom")||"0",10);this.Ta={top:a,right:0,bottom:b,left:0};a=_.cf(this.getData("isMenuDynamic"),!1);b=_.cf(this.getData("isMenuHoisted"),!1);this.Ga=a?1:b?2:0;this.ka=!1;this.Ca=1;this.Ga!==1&&(this.aa=this.Sa("U0exHf").children().Wc(0),_.ku(this,.g6a(this,this.aa.el())));_.oF(this.oa())&&(a=this.oa().el(),b=this.we.bind(this),a.__soy_skip_handler=b)};_.J(_.yJ,_.X);_.yJ.Ba=function(){return{Ea:{ef:_.cF,focus:_.OE,Fc:_.uu}}};_.yJ.prototype.IF=function(a){var b=a.source;this.Na=b;var c;((c=a.data)==null?0:c.qz)?(a=a.data.qz,this.Ca=a==="MOUS
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (5693)
                        Category:downloaded
                        Size (bytes):698852
                        Entropy (8bit):5.594980353163612
                        Encrypted:false
                        SSDEEP:6144:TN3KfgnkxgOYoRvEoQvSXwojVlmGa/ZLJiH7ZkvgTa5PB1+UO5Hx+B8U2+:TUMkxgOENagFxJiyU+
                        MD5:AA9FDCBE29C6D043DC83A7DAD848CCC3
                        SHA1:E3F0A387A0A4B060620C975E1C70AA20294F3F22
                        SHA-256:1A624C24D6D712C633F0B034606610DAD6B5AD7890FBFA3A9B204BD33207D60E
                        SHA-512:C93878CE1281349204ABDB4444B18A12C03A010D1A252827EBFE45523E834988CE95D6E625FF82A60934D7A275AD8DAAC689E4412C5719ACCA8C9E1D4365B4D3
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=LEikZe,_b,_tp,byfTOb,lsjVmc/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=n73qwf,SCuOPb,IZT63,vfuNJf,UUJqVe,ws9Tlc,siKnQd,XVq9Qb,STuCOe,njlZCf,m9oV,vjKJJ,y5vRwf,iyZMqd,NTMZac,mzzZzc,rCcCxc,vvMGie,K1ZKnb,ziZ8Mc,b3kMqb,mvkUhe,CMcBD,Fndnac,t2srLd,EN3i8d,z0u0L,xiZRqc,NOeYWe,O6y8ed,L9OGUe,PrPYRd,MpJwZc,qPfo0c,cYShmd,hc6Ubd,Rkm0ef,KUM7Z,oLggrd,inNHtf,L1AAkb,WpP9Yc,lwddkf,gJzDyc,SpsfSb,aC1iue,tUnxGc,aW3pY,ZakeSe,EFQ78c,xQtZb,I6YDgd,zbML3c,zr1jrb,vHEMJe,YHI3We,YTxL4,bSspM,Uas9Hd,zy0vNb,K0PMbc,AvtSve,qmdT9,MY7mZe,xBaz7b,GwYlN,eVCnO,EIOG1e,LDQI"
                        Preview:"use strict";_F_installCss(".r4WGQb{position:relative}.Dl08I>:first-child{margin-top:0}.Dl08I>:last-child{margin-bottom:0}.IzwVE{color:#1f1f1f;color:var(--gm3-sys-color-on-surface,#1f1f1f);font-family:\"Google Sans\",roboto,\"Noto Sans Myanmar UI\",arial,sans-serif;font-size:1.25rem;font-weight:400;letter-spacing:0rem;line-height:1.2}.l5PPKe{color:#1f1f1f;color:var(--gm3-sys-color-on-surface,#1f1f1f);font-size:1rem}.l5PPKe .dMNVAe{margin:0;padding:0}.l5PPKe>:first-child{margin-top:0;padding-top:0}.l5PPKe>:last-child{margin-bottom:0;padding-bottom:0}.Dl08I{margin:0;padding:0;position:relative}.Dl08I>.SmR8:only-child{padding-top:1px}.Dl08I>.SmR8:only-child::before{top:0}.Dl08I>.SmR8:not(first-child){padding-bottom:1px}.Dl08I>.SmR8::after{bottom:0}.Dl08I>.SmR8:only-child::before,.Dl08I>.SmR8::after{border-bottom:1px solid #c4c7c5;border-bottom:1px solid var(--gm3-sys-color-outline-variant,#c4c7c5);content:\"\";height:0;left:0;position:absolute;width:100%}.aZvCDf{margin-top:8px;margin-left
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (570)
                        Category:downloaded
                        Size (bytes):3467
                        Entropy (8bit):5.508385764606741
                        Encrypted:false
                        SSDEEP:96:ogbsxK3SrI2Jrutmxy9FALtcP+EGYkxhclzV9xCw:Psc3OIpDj2ZYkxhATxX
                        MD5:231ABD6E6C360E709640B399EDF85476
                        SHA1:6CB98F38D9B6FDCF2E7D7C7682A219082F2E1E75
                        SHA-256:44B5D535663C65CD2E6228EF1F0C3DBA9C89EAE5C1BF079A6C4C64972DEE989D
                        SHA-512:D45455810B34493A05BA2DD7ADF24C0C009F4CF0898AE9C57978D38C8F2654CEEFC11D1C151BA72B902E0FA87537D43C37957DCAEC1792B5277B54C8E7BCCA3C
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,iAskyc,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,wg1P6b,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziXSP,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=Wt6vjf,hhhU8,FCpbqb,WhJNk"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("Wt6vjf");.var fya=function(){var a=_.He();return _.Nj(a,1)},au=function(a){this.Da=_.t(a,0,au.messageId)};_.J(au,_.v);au.prototype.Ha=function(){return _.Fj(this,1)};au.prototype.Ua=function(a){return _.Xj(this,1,a)};au.messageId="f.bo";var bu=function(){_.km.call(this)};_.J(bu,_.km);bu.prototype.xd=function(){this.NT=!1;gya(this);_.km.prototype.xd.call(this)};bu.prototype.aa=function(){hya(this);if(this.JC)return iya(this),!1;if(!this.UV)return cu(this),!0;this.dispatchEvent("p");if(!this.HP)return cu(this),!0;this.NM?(this.dispatchEvent("r"),cu(this)):iya(this);return!1};.var jya=function(a){var b=new _.gp(a.b5);a.vQ!=null&&_.Mn(b,"authuser",a.vQ);return b},iya=function(a){a.JC=!0;var b=jya(a),c="rt=r&f_uid="+_.rk(a.HP);_.fn(b,(0,_.bg)(a.ea,a),"POST",c)};.bu.prototype.ea=function(a){a=a.target;hya(this);if(_.jn(a)){this.iK=0;if(this.NM)this.JC=!1,this.dispatchEvent("r"
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (533)
                        Category:downloaded
                        Size (bytes):9210
                        Entropy (8bit):5.393248075042016
                        Encrypted:false
                        SSDEEP:192:t7mFYxV97I4Ia0U44rS3mt8IV7ydti6M5/1JlNg:t7vB7Il2t+dEF1JlNg
                        MD5:2ED5BC88509286438B682EFF23518005
                        SHA1:D5C8FD77BA3ED7F977A4AD0C85CF026D0F74F3E2
                        SHA-256:F878D44B5CAC6BC95D638C13D0814C10E7D6CC145351ABA7945F53D8CB167979
                        SHA-512:12F5415A482286C53631D09B5F50BA4AAA0957DB61904430E5B728777A15DC62428ED560847AB1DFEC459E302FB4D009D32CC1770EAD5425023CA48DF4640AA4
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PrPYRd,Rkm0ef,SCuOPb,STuCOe,SpsfSb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,byfTOb,cYShmd,eVCnO,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,qPfo0c,qmdT9,rCcCxc,siKnQd,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=ltDFwf,SD8Jgb,rmumx,E87wgc,qPYxq,Tbb4sb,pxq3x,f8Gu1e,soHxf,YgOFye,yRXbo,bTi8wc,ywOR5c,PHUIyb"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.vNa=_.z("SD8Jgb",[]);._.GX=function(a,b){if(typeof b==="string")a.Nc(b);else if(b instanceof _.Ip&&b.ia&&b.ia===_.A)b=_.Za(b.Ku()),a.empty().append(b);else if(b instanceof _.Ua)b=_.Za(b),a.empty().append(b);else if(b instanceof Node)a.empty().append(b);else throw Error("Wf");};_.HX=function(a){var b=_.Lo(a,"[jsslot]");if(b.size()>0)return b;b=new _.Jo([_.Qk("span")]);_.Mo(b,"jsslot","");a.empty().append(b);return b};_.bMb=function(a){return a===null||typeof a==="string"&&_.Ji(a)};._.k("SD8Jgb");._.MX=function(a){_.X.call(this,a.Fa);this.Va=a.controller.Va;this.od=a.controllers.od[0]||null;this.header=a.controller.header;this.nav=a.controller.nav;var b;(b=this.oa().find("button:not([type])").el())==null||b.setAttribute("type","button")};_.J(_.MX,_.X);_.MX.Ba=function(){return{controller:{Va:{jsname:"n7vHCb",ctor:_.pv},header:{jsname:"tJHJj",ctor:_.pv},nav:{jsname:"DH6Rkf",ct
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (468)
                        Category:downloaded
                        Size (bytes):1858
                        Entropy (8bit):5.297658905867848
                        Encrypted:false
                        SSDEEP:48:o7vjoGL3AeFkphnpiu7cOyBfO/3d/rYrv3Zrw:ofrLxFuLdyp2AVw
                        MD5:B42DB3D22B12B8E3BE1B82961FE2870E
                        SHA1:D9CFD11C1C2DE17A7E9301F11AD875B610B96576
                        SHA-256:75DC40A81CEACB57940F84D2B29E021974C3004B245CC7198362CA944E9C4058
                        SHA-512:EC0708797586F8F85EC8A0BBECA707D73778D93C12986B92965D1828B254D39485926354AEC4D73474BC5755E392B813D8045B19369FAE23B30BBD12E17F7053
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=iAskyc,ziXSP"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("iAskyc");._.QZ=function(a){_.W.call(this,a.Fa);this.window=a.Ea.window.get();this.Mc=a.Ea.Mc};_.J(_.QZ,_.W);_.QZ.Ba=function(){return{Ea:{window:_.tu,Mc:_.HE}}};_.QZ.prototype.Po=function(){};_.QZ.prototype.addEncryptionRecoveryMethod=function(){};_.RZ=function(a){return(a==null?void 0:a.Jo)||function(){}};_.SZ=function(a){return(a==null?void 0:a.r3)||function(){}};_.VPb=function(a){return(a==null?void 0:a.Qp)||function(){}};._.WPb=function(a){return new Map(Array.from(a,function(b){var c=_.n(b);b=c.next().value;c=c.next().value;return[b,c.map(function(d){return{epoch:d.epoch,key:new Uint8Array(d.key)}})]}))};_.XPb=function(a){setTimeout(function(){throw a;},0)};_.QZ.prototype.qO=function(){return!0};_.qu(_.Dn,_.QZ);._.l();._.k("ziXSP");.var j_=function(a){_.QZ.call(this,a.Fa)};_.J(j_,_.QZ);j_.Ba=_.QZ.Ba;j_.prototype.Po=function(a,b,c){var d;if((d=this.window.chrome)==nu
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
                        Category:downloaded
                        Size (bytes):5430
                        Entropy (8bit):3.6534652184263736
                        Encrypted:false
                        SSDEEP:48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B
                        MD5:F3418A443E7D841097C714D69EC4BCB8
                        SHA1:49263695F6B0CDD72F45CF1B775E660FDC36C606
                        SHA-256:6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770
                        SHA-512:82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563
                        Malicious:false
                        URL:https://www.google.com/favicon.ico
                        Preview:............ .h...&... .... .........(....... ..... ............................................0...................................................................................................................................v.].X.:.X.:.r.Y........................................q.X.S.4.S.4.S.4.S.4.S.4.S.4...X....................0........q.W.S.4.X.:.................J...A...g.........................K.H.V.8..........................F..B.....................,.......................................B..............................................B..B..B..B..B...u..........................................B..B..B..B..B...{.................5.......k...........................................................7R..8F.................................................2........Vb..5C..;I..................R^.....................0................Xc..5C..5C..5C..5C..5C..5C..lv..........................................]i..<J..:G..Zf....................................................
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (1694)
                        Category:downloaded
                        Size (bytes):32500
                        Entropy (8bit):5.378121087555083
                        Encrypted:false
                        SSDEEP:768:OnTTScxIXeijt4aRZf4AEqTzQh2HIVVcYTVf79pew6cVEkAXtuWsmsL:iA4w4A4h2HIVVcMVf72QA9jOL
                        MD5:57D7B0A2CE36496F05AFA27B39C1F219
                        SHA1:418AD03C2E75AEAF188E2A00123B70E09D541656
                        SHA-256:E247A1F5E564A248C92E39C040A06B9B3BEA50A130CC98F2787FB5E2441E0707
                        SHA-512:78B135A69424F951AC7E3CCBDC4F496BCA0BE6A2312DC90DFA29032C7DB19455B7E35FEE57F470729EC5E86D52DC19037BB6404C27DF614A548DE409527866C2
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=_b,_tp/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=byfTOb,lsjVmc,LEikZe"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{.var Cua=function(a,b){this.da=a;this.ea=b;if(!c){var c=new _.gp("//www.google.com/images/cleardot.gif");_.rp(c)}this.ka=c};_.h=Cua.prototype;_.h.Zc=null;_.h.rZ=1E4;_.h.jA=!1;_.h.sQ=0;_.h.JJ=null;_.h.gV=null;_.h.setTimeout=function(a){this.rZ=a};_.h.start=function(){if(this.jA)throw Error("dc");this.jA=!0;this.sQ=0;Dua(this)};_.h.stop=function(){Eua(this);this.jA=!1};.var Dua=function(a){a.sQ++;navigator!==null&&"onLine"in navigator&&!navigator.onLine?_.om((0,_.bg)(a.hH,a,!1),0):(a.aa=new Image,a.aa.onload=(0,_.bg)(a.Kja,a),a.aa.onerror=(0,_.bg)(a.Jja,a),a.aa.onabort=(0,_.bg)(a.Ija,a),a.JJ=_.om(a.Lja,a.rZ,a),a.aa.src=String(a.ka))};_.h=Cua.prototype;_.h.Kja=function(){this.hH(!0)};_.h.Jja=function(){this.hH(!1)};_.h.Ija=function(){this.hH(!1)};_.h.Lja=function(){this.hH(!1)};._.h.hH=function(a){Eua(this);a?(this.jA=!1,this.da.call(this.ea,!0)):this.sQ<=0?Dua(this):(this.jA=!1,
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:Web Open Font Format (Version 2), TrueType, length 52280, version 1.0
                        Category:downloaded
                        Size (bytes):52280
                        Entropy (8bit):7.995413196679271
                        Encrypted:true
                        SSDEEP:1536:1rvqtK8DZilXxwJ8mMwAZy7phqsFLdG3B4d:xytBZits8bw4wzbFxG3B4d
                        MD5:F61F0D4D0F968D5BBA39A84C76277E1A
                        SHA1:AA3693EA140ECA418B4B2A30F6A68F6F43B4BEB2
                        SHA-256:57147F08949ABABE7DEEF611435AE418475A693E3823769A25C2A39B6EAD9CCC
                        SHA-512:6C3BD90F709BCF9151C9ED9FFEA55C4F6883E7FDA2A4E26BF018C83FE1CFBE4F4AA0DB080D6D024070D53B2257472C399C8AC44EEFD38B9445640EFA85D5C487
                        Malicious:false
                        URL:https://fonts.gstatic.com/s/googlesans/v58/4UaRrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_Iq2vgCI.woff2
                        Preview:wOF2.......8.....................................^...$..4?HVAR..?MVAR9.`?STAT.*',..J/.......`..(..Z.0..R.6.$.... .....K..[..q..c..T.....>.P.j.`.w..#...%......N.".....$..3.0.6......... .L.rX/r[j.y.|*(.4.%#.....2.v.m..-..%.....;-.Y.{..&..O=#l@...k..7g..ZI...#.Z./+T..r7...M..3).Z%.x....s..sL..[A!.5*1w'/.8V..2Z..%.X.h.o.).]..9..Q`.$.....7..kZ.~O........d..g.n.d.Rw+&....Cz..uy#..fz,(.J....v.%..`..9.....h...?O..:...c%.....6s....xl..#...5..._......1.>.)"U.4 W....?%......6//!$...!.n9C@n...........!""^.....W..Z<.7.x.."UT.T....E.."R>.R..t.....H d..e_.K../.+8.Q.P.ZQ....;...U....]......._.e*......71.?.7.ORv.?...l...G|.P...|:...I.X..2.,.L........d.g.]}W#uW]QnuP-s.;.-Y.....].......C..j_.M0...y.......J..........NY..@A...,....-.F......'..w./j5g.vUS...U..0.&...y7.LP.....%.....Y......Y..D. e.A..G.?.$.......6...eaK.n5.m...N...,...+BCl..L> .E9~.b[.w.x....6<...}.e...%V....O.......*.?...a..#[eE.4..p..$...].....%......o._......N.._~..El....b..A.0.r8.....|..D.d..
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (755)
                        Category:downloaded
                        Size (bytes):1460
                        Entropy (8bit):5.274624539239422
                        Encrypted:false
                        SSDEEP:24:kMYD7DUuXIqMSsN7UYgtx/mQ7hz1BU6TZ6BdXDMvUKGbWxlGb+jSFFV87Ofk8tp8:o7DhXI6PoXwsKGb2lGb+jS9Mwrw
                        MD5:481C149C4D3EE4A53C3E7CBA067371DF
                        SHA1:E0FED275636D3492C922C44F010157FAF0936733
                        SHA-256:9327A53F577C5FCEFDB162E02D8646CE5B70DF2201F4B3289384657B32BACE70
                        SHA-512:EC5C5A03ED4E1A27BEE7E1C488A238D79A9787D944E364CCE516FB28C22256919E49C99BFCFEA0F7815AB4232A350914E26D33D20F5A81ED19A39DFD40E30C79
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=P6sQOc"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("lOO0Vd");._.b_a=new _.pf(_.Dm);._.l();._.k("P6sQOc");.var g_a=!!(_.Mh[1]&16);var i_a=function(a,b,c,d,e){this.ea=a;this.xa=b;this.ka=c;this.Ca=d;this.Ga=e;this.aa=0;this.da=h_a(this)},j_a=function(a){var b={};_.Ma(a.HS(),function(e){b[e]=!0});var c=a.uS(),d=a.yS();return new i_a(a.wP(),c.aa()*1E3,a.bS(),d.aa()*1E3,b)},h_a=function(a){return Math.random()*Math.min(a.xa*Math.pow(a.ka,a.aa),a.Ca)},SG=function(a,b){return a.aa>=a.ea?!1:b!=null?!!a.Ga[b]:!0};var TG=function(a){_.W.call(this,a.Fa);this.da=a.Ea.JV;this.ea=a.Ea.metadata;a=a.Ea.cha;this.fetch=a.fetch.bind(a)};_.J(TG,_.W);TG.Ba=function(){return{Ea:{JV:_.e_a,metadata:_.b_a,cha:_.VZa}}};TG.prototype.aa=function(a,b){if(this.ea.getType(a.Od())!==1)return _.Vm(a);var c=this.da.jV;return(c=c?j_a(c):null)&&SG(c)?_.zya(a,k_a(this,a,b,c)):_.Vm(a)};.var k_a=function(a,b,c,d){return c.then(function(e){return e},function(e)
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (2907)
                        Category:downloaded
                        Size (bytes):23298
                        Entropy (8bit):5.429186219736739
                        Encrypted:false
                        SSDEEP:384:+BitNeB9HVPQmqySWyvbbb/XEm6k1JTM2qzhOF0bCjOgiQBH2f+wl9nyf0zHwx:+BiHeB9Hecebbb/PONOFnjOgPBHgSywx
                        MD5:A5C41D7BA22E9CF451810802AE5AC2E8
                        SHA1:858F35134A0BD7BAECB1B1A30EC3645642214554
                        SHA-256:D29364A1E9EDE91152F2CB84962B73644741817C9C6A615C1FB70A885DD1CB8D
                        SHA-512:DEA28AD362B51832D33CD9E936C0A255FA32C20DFFC6E806DA7AAF657D3490AF079C40FE21E10B2FDC971EB066E51ABDA182DEDC156759CCE06440E456FEB316
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,Rkm0ef,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=RqjULd"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.xu.prototype.da=_.ca(40,function(){return _.tj(this,3)});_.cz=function(a,b){this.key=a;this.defaultValue=!1;this.flagName=b};_.cz.prototype.ctor=function(a){return typeof a==="boolean"?a:this.defaultValue};_.dz=function(){this.ka=!0;var a=_.xj(_.fk(_.Be("TSDtV",window),_.Cya),_.xu,1,_.sj())[0];if(a){var b={};for(var c=_.n(_.xj(a,_.Dya,2,_.sj())),d=c.next();!d.done;d=c.next()){d=d.value;var e=_.Lj(d,1).toString();switch(_.vj(d,_.yu)){case 3:b[e]=_.Jj(d,_.nj(d,_.yu,3));break;case 2:b[e]=_.Lj(d,_.nj(d,_.yu,2));break;case 4:b[e]=_.Mj(d,_.nj(d,_.yu,4));break;case 5:b[e]=_.Nj(d,_.nj(d,_.yu,5));break;case 6:b[e]=_.Rj(d,_.ff,6,_.yu);break;default:throw Error("jd`"+_.vj(d,_.yu));}}}else b={};this.ea=b;this.token=.a?a.da():null};_.dz.prototype.aa=function(a){if(!this.ka||a.key in this.ea)a=a.ctor(this.ea[a.key]);else if(_.Be("nQyAE",window)){var b=_.Fya(a.flagName);if(b===null)a=a.de
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (683)
                        Category:downloaded
                        Size (bytes):3131
                        Entropy (8bit):5.352056237104327
                        Encrypted:false
                        SSDEEP:48:o7hHD75byh9xqKP5jNQ8js63rAwrMNhYfmdpwoKLEy5aQW5Tx5v3MmFopMGIWO4x:oFD+95jOQr3AT7wRLDGD5flBb4Ew
                        MD5:ADEF03127F74F5E6742B8CFA7B863F28
                        SHA1:58D7C635582AF10E91EC047FD315FAF758AF51DA
                        SHA-256:5FDD639E222F58AEB6178EB02583086BCC50ED219DEAA953D0E7984DD0E1FEDC
                        SHA-512:3AC26E9569EE83298F386D551774F378D3E433A2C80C1D4BC7481C544605A2FA4943F6CBC8E97FBF8FE3C32C1EFB2A1CCAA01403819482FC7429538FDF2CA758
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=ZwDk9d,RMhBfe"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("ZwDk9d");.var kA=function(a){_.W.call(this,a.Fa)};_.J(kA,_.W);kA.Ba=_.W.Ba;kA.prototype.jS=function(a){return _.Ye(this,{Xa:{lT:_.ol}}).then(function(b){var c=window._wjdd,d=window._wjdc;return!c&&d?new _.ni(function(e){window._wjdc=function(f){d(f);e(dKa(f,b,a))}}):dKa(c,b,a)})};var dKa=function(a,b,c){return(a=a&&a[c])?a:b.Xa.lT.jS(c)};.kA.prototype.aa=function(a,b){var c=_.Dra(b).Tj;if(c.startsWith("$")){var d=_.jm.get(a);_.xq[b]&&(d||(d={},_.jm.set(a,d)),d[c]=_.xq[b],delete _.xq[b],_.yq--);if(d)if(a=d[c])b=_.af(a);else throw Error("Jb`"+b);else b=null}else b=null;return b};_.qu(_.Lfa,kA);._.l();._.k("SNUn3");._.cKa=new _.pf(_.wg);._.l();._.k("RMhBfe");.var eKa=function(a){var b=_.wq(a);return b?new _.ni(function(c,d){var e=function(){b=_.wq(a);var f=_.Sfa(a,b);f?c(f.getAttribute("jsdata")):window.document.readyState=="complete"?(f=["Unable to find deferred jsdata wit
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (395)
                        Category:downloaded
                        Size (bytes):1608
                        Entropy (8bit):5.271783084011668
                        Encrypted:false
                        SSDEEP:48:o726BiFP89yAxKz1TtMxII+eXww7D2bc+rw:oyMyAAz1WNd8vw
                        MD5:45EA91A811A594F81B7F760DD14BE237
                        SHA1:2C97782C6D5D0BCFB3676FF24AA1008251090DAE
                        SHA-256:7488FF4710E7592F66BE1FAC090F73CB8F1D2D0794B57DEAC1798C5B309EE76F
                        SHA-512:4F79A36857D5A8AF1E2F938EF92EA75C384DE4789972B068BE82EADAA442C538A65035CCE8665A7283137E2075B8FE4C1C9E7B2A36585491683B4869005B772A
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=w9hDv,ZDZcre,A7fCU"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("w9hDv");._.vg(_.Ila);_.iA=function(a){_.W.call(this,a.Fa);this.aa=a.Xa.cache};_.J(_.iA,_.W);_.iA.Ba=function(){return{Xa:{cache:_.gt}}};_.iA.prototype.execute=function(a){_.Bb(a,function(b){var c;_.$e(b)&&(c=b.eb.kc(b.kb));c&&this.aa.LG(c)},this);return{}};_.qu(_.Ola,_.iA);._.l();._.k("ZDZcre");.var jH=function(a){_.W.call(this,a.Fa);this.Xl=a.Ea.Xl;this.j4=a.Ea.metadata;this.aa=a.Ea.wt};_.J(jH,_.W);jH.Ba=function(){return{Ea:{Xl:_.OG,metadata:_.b_a,wt:_.LG}}};jH.prototype.execute=function(a){var b=this;a=this.aa.create(a);return _.Bb(a,function(c){var d=b.j4.getType(c.Od())===2?b.Xl.Rb(c):b.Xl.fetch(c);return _.Bl(c,_.PG)?d.then(function(e){return _.Dd(e)}):d},this)};_.qu(_.Tla,jH);._.l();._.k("K5nYTd");._.a_a=new _.pf(_.Pla);._.l();._.k("sP4Vbe");.._.l();._.k("kMFpHd");.._.l();._.k("A7fCU");.var RG=function(a){_.W.call(this,a.Fa);this.aa=a.Ea.yQ};_.J(RG,_.W);RG.Ba=func
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with no line terminators
                        Category:downloaded
                        Size (bytes):84
                        Entropy (8bit):4.875266466142591
                        Encrypted:false
                        SSDEEP:3:DZFJu0+WVTBCq2Bjdw2KsJJuYHSKnZ:lFJuuVTBudw29nu4SKZ
                        MD5:87B6333E98B7620EA1FF98D1A837A39E
                        SHA1:105DE6815B0885357DE1414BFC0D77FCC9E924EF
                        SHA-256:DCD3C133C5C40BECD4100BBE6EDAE84C9735E778E4234A5E8395C56FF8A733BA
                        SHA-512:867D7943D813685FAA76394E53199750C55817E836FD19C933F74D11E9657CE66719A6D6B2E39EE1DE62358BCE364E38A55F4E138DF92337DE6985DDCD5D0994
                        Malicious:false
                        URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISHgmA6QC9dWevzxIFDRkBE_oSBQ3oIX6GEgUN05ioBw==?alt=proto
                        Preview:Cj0KBw0ZARP6GgAKKQ3oIX6GGgQISxgCKhwIClIYCg5AIS4jJF8qLSY/Ky8lLBABGP////8PCgcN05ioBxoA
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (553)
                        Category:downloaded
                        Size (bytes):744742
                        Entropy (8bit):5.792853825531523
                        Encrypted:false
                        SSDEEP:6144:x5bdWK/20rOQKKQtvqUGSGDdPSxdZqmguPH:pOeKGSpgu/
                        MD5:D6A4595EF381156A4C38FC1268C40783
                        SHA1:75B2E4139EE5014416D280B02E1F57724B0A4240
                        SHA-256:9E6266EF7F49A5256F373AB78F9D0AE688CA964F542892F5FF0563F05AC6C676
                        SHA-512:ACC3385A52ABFA53EE68286C86F2266C2BE7D12350F31AEFD91052616CF417207E5F27A31FEC5FB4B5DDA705C599DD0B724ACA88E9FF682289C3B473902CD79C
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/excm=_b,_tp,identifierview/ed=1/dg=0/wt=2/ujg=1/rs=AOaEmlEEvjRYpfMDihaNwG0swUsVgVpBIg/m=_b,_tp"
                        Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([0x2860c1c4, 0x2046d860, 0x39e1fc40, 0x14501e80, 0xe420, 0x0, 0x1a000000, 0x1d000003, 0xc, ]);./*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/./*.. Copyright Google LLC. SPDX-License-Identifier: Apache-2.0.*/./*.. Copyright 2024 Google, Inc. SPDX-License-Identifier: MIT.*/./*. SPDX-License-Identifier: Apache-2.0.*/./*. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var baa,daa,Na,Ta,gaa,iaa,jb,qaa,waa,Caa,Haa,Kaa,Jb,Laa,Ob,Qb,Rb,Maa,Naa,Sb,Oaa,Paa,Qaa,Yb,Vaa,Xaa,ec,fc,gc,bba,cba,gba,jba,lba,mba,qba,tba,nba,sba,rba,pba,oba,uba,yba,Cba,Dba,Aba,Hc,Ic,Gba,Iba,Mba,Nba,Oba,Pba,Lba,Qba,Sba,dd,Uba,Vba,Xba,Zba,Yba,aca,bca,cca,dca,fca,eca,hca,ica,jca,kca,nca,
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text, with very long lines (681)
                        Category:downloaded
                        Size (bytes):4067
                        Entropy (8bit):5.3700036060139436
                        Encrypted:false
                        SSDEEP:96:G6mTOIiY1medWRQrf7VF6vtDgXJyA7oxcoTiw:3mTOImedWOVF6vtUJyA8xJ3
                        MD5:FA701F5D7BEF5AF6B676F099A00A1140
                        SHA1:4CA8594D1E845605E7F1242AD8E10FD3A41FA3BE
                        SHA-256:F1F311E29B597B507EE761AE40185A9BE194BA6498F91DD2A69610EF765B554A
                        SHA-512:D53CAD789CED1F1D05546CD9DDA662FF47DF4A9FE382F4936EB1579175B06A95770426E5A83C24EACE04014956F1971A6432D1FCB26F2A9E4B922D8A34FC9875
                        Malicious:false
                        URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.PqO-Y4U4tl0.es5.O/ck=boq-identity.AccountsSignInUi.nq70RHujW6U.L.B1.O/am=xMFgKBi2EQjEH54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlGiXTMuN04FgQ4LzahFtNqboYL9eA/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=sOXFj,q0xTif,ZZ4WUe"
                        Preview:"use strict";_F_installCss(".N7rBcd{overflow-x:auto}sentinel{}");.this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.vg(_.bqa);._.k("sOXFj");.var wu=function(a){_.W.call(this,a.Fa)};_.J(wu,_.W);wu.Ba=_.W.Ba;wu.prototype.aa=function(a){return a()};_.qu(_.aqa,wu);._.l();._.k("oGtAuc");._.Bya=new _.pf(_.bqa);._.l();._.k("q0xTif");.var vza=function(a){var b=function(d){_.Zn(d)&&(_.Zn(d).Lc=null,_.Gu(d,null));d.XyHi9&&(d.XyHi9=null)};b(a);a=a.querySelectorAll("[c-wiz]");for(var c=0;c<a.length;c++)b(a[c])},Su=function(a){_.nt.call(this,a.Fa);this.Qa=this.dom=null;if(this.rl()){var b=_.Cm(this.Wg(),[_.Hm,_.Gm]);b=_.pi([b[_.Hm],b[_.Gm]]).then(function(c){this.Qa=c[0];this.dom=c[1]},null,this);_.ku(this,b)}this.Ra=a.lm.Dea};_.J(Su,_.nt);Su.Ba=function(){return{lm:{Dea:function(a){return _.Ue(a)}}}};Su.prototype.Bp=function(a){return this.Ra.Bp(a)};.Su.prototype.getData=function(a){return this.Ra.getData(a)};Su.prototype.uo=function(){_.Nt(this.d
                        File type:PE32 executable (GUI) Intel 80386, for MS Windows
                        Entropy (8bit):6.583819527071619
                        TrID:
                        • Win32 Executable (generic) a (10002005/4) 99.96%
                        • Generic Win/DOS Executable (2004/3) 0.02%
                        • DOS Executable Generic (2002/1) 0.02%
                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                        File name:file.exe
                        File size:919'040 bytes
                        MD5:86b442edece0f1e7d7f46682a4e6b6a6
                        SHA1:323c00335af743e946abd85b3b255e39cc06974d
                        SHA256:304be29a6ee0ea7ac9d692efc23fff85c4e5b6348790e6d30f5ef324dd36da57
                        SHA512:8dfa5438ff3006b6c63842a17b2b1729b121ddef9bd4660737b6eef98437bc44b197fc4e44b7f38fafd2dfa29e72c22fc26faf33731182400e8bb18b48ccce7d
                        SSDEEP:24576:/qDEvCTbMWu7rQYlBQcBiT6rprG8a4kK:/TvC/MTQYxsWR7a4
                        TLSH:D0159E0273D1C062FFAB92334B5AF6515BBC69260123E61F13981DB9BE701B1563E7A3
                        File Content Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......................j:......j:..C...j:......@.*...............................n.......~.............{.......{.......{.........z....
                        Icon Hash:aaf3e3e3938382a0
                        Entrypoint:0x420577
                        Entrypoint Section:.text
                        Digitally signed:false
                        Imagebase:0x400000
                        Subsystem:windows gui
                        Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
                        DLL Characteristics:DYNAMIC_BASE, TERMINAL_SERVER_AWARE
                        Time Stamp:0x670323B0 [Sun Oct 6 23:56:32 2024 UTC]
                        TLS Callbacks:
                        CLR (.Net) Version:
                        OS Version Major:5
                        OS Version Minor:1
                        File Version Major:5
                        File Version Minor:1
                        Subsystem Version Major:5
                        Subsystem Version Minor:1
                        Import Hash:948cc502fe9226992dce9417f952fce3
                        Instruction
                        call 00007FB2293B2503h
                        jmp 00007FB2293B1E0Fh
                        push ebp
                        mov ebp, esp
                        push esi
                        push dword ptr [ebp+08h]
                        mov esi, ecx
                        call 00007FB2293B1FEDh
                        mov dword ptr [esi], 0049FDF0h
                        mov eax, esi
                        pop esi
                        pop ebp
                        retn 0004h
                        and dword ptr [ecx+04h], 00000000h
                        mov eax, ecx
                        and dword ptr [ecx+08h], 00000000h
                        mov dword ptr [ecx+04h], 0049FDF8h
                        mov dword ptr [ecx], 0049FDF0h
                        ret
                        push ebp
                        mov ebp, esp
                        push esi
                        push dword ptr [ebp+08h]
                        mov esi, ecx
                        call 00007FB2293B1FBAh
                        mov dword ptr [esi], 0049FE0Ch
                        mov eax, esi
                        pop esi
                        pop ebp
                        retn 0004h
                        and dword ptr [ecx+04h], 00000000h
                        mov eax, ecx
                        and dword ptr [ecx+08h], 00000000h
                        mov dword ptr [ecx+04h], 0049FE14h
                        mov dword ptr [ecx], 0049FE0Ch
                        ret
                        push ebp
                        mov ebp, esp
                        push esi
                        mov esi, ecx
                        lea eax, dword ptr [esi+04h]
                        mov dword ptr [esi], 0049FDD0h
                        and dword ptr [eax], 00000000h
                        and dword ptr [eax+04h], 00000000h
                        push eax
                        mov eax, dword ptr [ebp+08h]
                        add eax, 04h
                        push eax
                        call 00007FB2293B4BADh
                        pop ecx
                        pop ecx
                        mov eax, esi
                        pop esi
                        pop ebp
                        retn 0004h
                        lea eax, dword ptr [ecx+04h]
                        mov dword ptr [ecx], 0049FDD0h
                        push eax
                        call 00007FB2293B4BF8h
                        pop ecx
                        ret
                        push ebp
                        mov ebp, esp
                        push esi
                        mov esi, ecx
                        lea eax, dword ptr [esi+04h]
                        mov dword ptr [esi], 0049FDD0h
                        push eax
                        call 00007FB2293B4BE1h
                        test byte ptr [ebp+08h], 00000001h
                        pop ecx
                        Programming Language:
                        • [ C ] VS2008 SP1 build 30729
                        • [IMP] VS2008 SP1 build 30729
                        NameVirtual AddressVirtual Size Is in Section
                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IMPORT0xc8e640x17c.rdata
                        IMAGE_DIRECTORY_ENTRY_RESOURCE0xd40000x9bb8.rsrc
                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                        IMAGE_DIRECTORY_ENTRY_BASERELOC0xde0000x7594.reloc
                        IMAGE_DIRECTORY_ENTRY_DEBUG0xb0ff00x1c.rdata
                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                        IMAGE_DIRECTORY_ENTRY_TLS0xc34000x18.rdata
                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xb10100x40.rdata
                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IAT0x9c0000x894.rdata
                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                        .text0x10000x9ab1d0x9ac000a1473f3064dcbc32ef93c5c8a90f3a6False0.565500681542811data6.668273581389308IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                        .rdata0x9c0000x2fb820x2fc00c9cf2468b60bf4f80f136ed54b3989fbFalse0.35289185209424084data5.691811547483722IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        .data0xcc0000x706c0x480053b9025d545d65e23295e30afdbd16d9False0.04356553819444445DOS executable (block device driver @\273\)0.5846666986982398IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                        .rsrc0xd40000x9bb80x9c006bf3112804e1367cce425f5d3b868124False0.3167317708333333data5.332685302889328IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        .reloc0xde0000x75940x7600c68ee8931a32d45eb82dc450ee40efc3False0.7628111758474576data6.7972128181359786IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                        NameRVASizeTypeLanguageCountryZLIB Complexity
                        RT_ICON0xd45a80x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishGreat Britain0.7466216216216216
                        RT_ICON0xd46d00x128Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colorsEnglishGreat Britain0.3277027027027027
                        RT_ICON0xd47f80x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishGreat Britain0.3885135135135135
                        RT_ICON0xd49200x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 0EnglishGreat Britain0.3333333333333333
                        RT_ICON0xd4c080x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishGreat Britain0.5
                        RT_ICON0xd4d300xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0EnglishGreat Britain0.2835820895522388
                        RT_ICON0xd5bd80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0EnglishGreat Britain0.37906137184115524
                        RT_ICON0xd64800x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishGreat Britain0.23699421965317918
                        RT_ICON0xd69e80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishGreat Britain0.13858921161825727
                        RT_ICON0xd8f900x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishGreat Britain0.25070356472795496
                        RT_ICON0xda0380x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishGreat Britain0.3173758865248227
                        RT_MENU0xda4a00x50dataEnglishGreat Britain0.9
                        RT_STRING0xda4f00x594dataEnglishGreat Britain0.3333333333333333
                        RT_STRING0xdaa840x68adataEnglishGreat Britain0.2735961768219833
                        RT_STRING0xdb1100x490dataEnglishGreat Britain0.3715753424657534
                        RT_STRING0xdb5a00x5fcdataEnglishGreat Britain0.3087467362924282
                        RT_STRING0xdbb9c0x65cdataEnglishGreat Britain0.34336609336609336
                        RT_STRING0xdc1f80x466dataEnglishGreat Britain0.3605683836589698
                        RT_STRING0xdc6600x158Matlab v4 mat-file (little endian) n, numeric, rows 0, columns 0EnglishGreat Britain0.502906976744186
                        RT_RCDATA0xdc7b80xe7edata1.002964959568733
                        RT_GROUP_ICON0xdd6380x76dataEnglishGreat Britain0.6610169491525424
                        RT_GROUP_ICON0xdd6b00x14dataEnglishGreat Britain1.25
                        RT_GROUP_ICON0xdd6c40x14dataEnglishGreat Britain1.15
                        RT_GROUP_ICON0xdd6d80x14dataEnglishGreat Britain1.25
                        RT_VERSION0xdd6ec0xdcdataEnglishGreat Britain0.6181818181818182
                        RT_MANIFEST0xdd7c80x3efASCII text, with CRLF line terminatorsEnglishGreat Britain0.5074478649453823
                        DLLImport
                        WSOCK32.dllgethostbyname, recv, send, socket, inet_ntoa, setsockopt, ntohs, WSACleanup, WSAStartup, sendto, htons, __WSAFDIsSet, select, accept, listen, bind, inet_addr, ioctlsocket, recvfrom, WSAGetLastError, closesocket, gethostname, connect
                        VERSION.dllGetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
                        WINMM.dlltimeGetTime, waveOutSetVolume, mciSendStringW
                        COMCTL32.dllImageList_ReplaceIcon, ImageList_Destroy, ImageList_Remove, ImageList_SetDragCursorImage, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_EndDrag, ImageList_DragMove, InitCommonControlsEx, ImageList_Create
                        MPR.dllWNetGetConnectionW, WNetCancelConnection2W, WNetUseConnectionW, WNetAddConnection2W
                        WININET.dllHttpOpenRequestW, InternetCloseHandle, InternetOpenW, InternetSetOptionW, InternetCrackUrlW, HttpQueryInfoW, InternetQueryOptionW, InternetConnectW, HttpSendRequestW, FtpOpenFileW, FtpGetFileSize, InternetOpenUrlW, InternetReadFile, InternetQueryDataAvailable
                        PSAPI.DLLGetProcessMemoryInfo
                        IPHLPAPI.DLLIcmpSendEcho, IcmpCloseHandle, IcmpCreateFile
                        USERENV.dllDestroyEnvironmentBlock, LoadUserProfileW, CreateEnvironmentBlock, UnloadUserProfile
                        UxTheme.dllIsThemeActive
                        KERNEL32.dllDuplicateHandle, CreateThread, WaitForSingleObject, HeapAlloc, GetProcessHeap, HeapFree, Sleep, GetCurrentThreadId, MultiByteToWideChar, MulDiv, GetVersionExW, IsWow64Process, GetSystemInfo, FreeLibrary, LoadLibraryA, GetProcAddress, SetErrorMode, GetModuleFileNameW, WideCharToMultiByte, lstrcpyW, lstrlenW, GetModuleHandleW, QueryPerformanceCounter, VirtualFreeEx, OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateFileW, SetFilePointerEx, SetEndOfFile, ReadFile, WriteFile, FlushFileBuffers, TerminateProcess, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetFileTime, GetFileAttributesW, FindFirstFileW, FindClose, GetLongPathNameW, GetShortPathNameW, DeleteFileW, IsDebuggerPresent, CopyFileExW, MoveFileW, CreateDirectoryW, RemoveDirectoryW, SetSystemPowerState, QueryPerformanceFrequency, LoadResource, LockResource, SizeofResource, OutputDebugStringW, GetTempPathW, GetTempFileNameW, DeviceIoControl, LoadLibraryW, GetLocalTime, CompareStringW, GetCurrentThread, EnterCriticalSection, LeaveCriticalSection, GetStdHandle, CreatePipe, InterlockedExchange, TerminateThread, LoadLibraryExW, FindResourceExW, CopyFileW, VirtualFree, FormatMessageW, GetExitCodeProcess, GetPrivateProfileStringW, WritePrivateProfileStringW, GetPrivateProfileSectionW, WritePrivateProfileSectionW, GetPrivateProfileSectionNamesW, FileTimeToLocalFileTime, FileTimeToSystemTime, SystemTimeToFileTime, LocalFileTimeToFileTime, GetDriveTypeW, GetDiskFreeSpaceExW, GetDiskFreeSpaceW, GetVolumeInformationW, SetVolumeLabelW, CreateHardLinkW, SetFileAttributesW, CreateEventW, SetEvent, GetEnvironmentVariableW, SetEnvironmentVariableW, GlobalLock, GlobalUnlock, GlobalAlloc, GetFileSize, GlobalFree, GlobalMemoryStatusEx, Beep, GetSystemDirectoryW, HeapReAlloc, HeapSize, GetComputerNameW, GetWindowsDirectoryW, GetCurrentProcessId, GetProcessIoCounters, CreateProcessW, GetProcessId, SetPriorityClass, VirtualAlloc, GetCurrentDirectoryW, lstrcmpiW, DecodePointer, GetLastError, RaiseException, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, InterlockedDecrement, InterlockedIncrement, ResetEvent, WaitForSingleObjectEx, IsProcessorFeaturePresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, CloseHandle, GetFullPathNameW, GetStartupInfoW, GetSystemTimeAsFileTime, InitializeSListHead, RtlUnwind, SetLastError, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, ExitProcess, GetModuleHandleExW, ExitThread, ResumeThread, FreeLibraryAndExitThread, GetACP, GetDateFormatW, GetTimeFormatW, LCMapStringW, GetStringTypeW, GetFileType, SetStdHandle, GetConsoleCP, GetConsoleMode, ReadConsoleW, GetTimeZoneInformation, FindFirstFileExW, IsValidCodePage, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableA, SetCurrentDirectoryW, FindNextFileW, WriteConsoleW
                        USER32.dllGetKeyboardLayoutNameW, IsCharAlphaW, IsCharAlphaNumericW, IsCharLowerW, IsCharUpperW, GetMenuStringW, GetSubMenu, GetCaretPos, IsZoomed, GetMonitorInfoW, SetWindowLongW, SetLayeredWindowAttributes, FlashWindow, GetClassLongW, TranslateAcceleratorW, IsDialogMessageW, GetSysColor, InflateRect, DrawFocusRect, DrawTextW, FrameRect, DrawFrameControl, FillRect, PtInRect, DestroyAcceleratorTable, CreateAcceleratorTableW, SetCursor, GetWindowDC, GetSystemMetrics, GetActiveWindow, CharNextW, wsprintfW, RedrawWindow, DrawMenuBar, DestroyMenu, SetMenu, GetWindowTextLengthW, CreateMenu, IsDlgButtonChecked, DefDlgProcW, CallWindowProcW, ReleaseCapture, SetCapture, PeekMessageW, GetInputState, UnregisterHotKey, CharLowerBuffW, MonitorFromPoint, MonitorFromRect, LoadImageW, mouse_event, ExitWindowsEx, SetActiveWindow, FindWindowExW, EnumThreadWindows, SetMenuDefaultItem, InsertMenuItemW, IsMenu, ClientToScreen, GetCursorPos, DeleteMenu, CheckMenuRadioItem, GetMenuItemID, GetMenuItemCount, SetMenuItemInfoW, GetMenuItemInfoW, SetForegroundWindow, IsIconic, FindWindowW, SystemParametersInfoW, LockWindowUpdate, SendInput, GetAsyncKeyState, SetKeyboardState, GetKeyboardState, GetKeyState, VkKeyScanW, LoadStringW, DialogBoxParamW, MessageBeep, EndDialog, SendDlgItemMessageW, GetDlgItem, SetWindowTextW, CopyRect, ReleaseDC, GetDC, EndPaint, BeginPaint, GetClientRect, GetMenu, DestroyWindow, EnumWindows, GetDesktopWindow, IsWindow, IsWindowEnabled, IsWindowVisible, EnableWindow, InvalidateRect, GetWindowLongW, GetWindowThreadProcessId, AttachThreadInput, GetFocus, GetWindowTextW, SendMessageTimeoutW, EnumChildWindows, CharUpperBuffW, GetClassNameW, GetParent, GetDlgCtrlID, SendMessageW, MapVirtualKeyW, PostMessageW, GetWindowRect, SetUserObjectSecurity, CloseDesktop, CloseWindowStation, OpenDesktopW, RegisterHotKey, GetCursorInfo, SetWindowPos, CopyImage, AdjustWindowRectEx, SetRect, SetClipboardData, EmptyClipboard, CountClipboardFormats, CloseClipboard, GetClipboardData, IsClipboardFormatAvailable, OpenClipboard, BlockInput, TrackPopupMenuEx, GetMessageW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, GetUserObjectSecurity, MessageBoxW, DefWindowProcW, MoveWindow, SetFocus, PostQuitMessage, KillTimer, CreatePopupMenu, RegisterWindowMessageW, SetTimer, ShowWindow, CreateWindowExW, RegisterClassExW, LoadIconW, LoadCursorW, GetSysColorBrush, GetForegroundWindow, MessageBoxA, DestroyIcon, DispatchMessageW, keybd_event, TranslateMessage, ScreenToClient
                        GDI32.dllEndPath, DeleteObject, GetTextExtentPoint32W, ExtCreatePen, StrokeAndFillPath, GetDeviceCaps, SetPixel, CloseFigure, LineTo, AngleArc, MoveToEx, Ellipse, CreateCompatibleBitmap, CreateCompatibleDC, PolyDraw, BeginPath, Rectangle, SetViewportOrgEx, GetObjectW, SetBkMode, RoundRect, SetBkColor, CreatePen, SelectObject, StretchBlt, CreateSolidBrush, SetTextColor, CreateFontW, GetTextFaceW, GetStockObject, CreateDCW, GetPixel, DeleteDC, GetDIBits, StrokePath
                        COMDLG32.dllGetSaveFileNameW, GetOpenFileNameW
                        ADVAPI32.dllGetAce, RegEnumValueW, RegDeleteValueW, RegDeleteKeyW, RegEnumKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegQueryValueExW, RegConnectRegistryW, InitializeSecurityDescriptor, InitializeAcl, AdjustTokenPrivileges, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, CreateProcessAsUserW, CreateProcessWithLogonW, GetLengthSid, CopySid, LogonUserW, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, GetTokenInformation, RegCreateKeyExW, GetSecurityDescriptorDacl, GetAclInformation, GetUserNameW, AddAce, SetSecurityDescriptorDacl, InitiateSystemShutdownExW
                        SHELL32.dllDragFinish, DragQueryPoint, ShellExecuteExW, DragQueryFileW, SHEmptyRecycleBinW, SHGetPathFromIDListW, SHBrowseForFolderW, SHCreateShellItem, SHGetDesktopFolder, SHGetSpecialFolderLocation, SHGetFolderPathW, SHFileOperationW, ExtractIconExW, Shell_NotifyIconW, ShellExecuteW
                        ole32.dllCoTaskMemAlloc, CoTaskMemFree, CLSIDFromString, ProgIDFromCLSID, CLSIDFromProgID, OleSetMenuDescriptor, MkParseDisplayName, OleSetContainedObject, CoCreateInstance, IIDFromString, StringFromGUID2, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoInitialize, CoUninitialize, GetRunningObjectTable, CoGetInstanceFromFile, CoGetObject, CoInitializeSecurity, CoCreateInstanceEx, CoSetProxyBlanket
                        OLEAUT32.dllCreateStdDispatch, CreateDispTypeInfo, UnRegisterTypeLib, UnRegisterTypeLibForUser, RegisterTypeLibForUser, RegisterTypeLib, LoadTypeLibEx, VariantCopyInd, SysReAllocString, SysFreeString, VariantChangeType, SafeArrayDestroyData, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayAllocData, SafeArrayAllocDescriptorEx, SafeArrayCreateVector, SysStringLen, QueryPathOfRegTypeLib, SysAllocString, VariantInit, VariantClear, DispCallFunc, VariantTimeToSystemTime, VarR8FromDec, SafeArrayGetVartype, SafeArrayDestroyDescriptor, VariantCopy, OleLoadPicture
                        Language of compilation systemCountry where language is spokenMap
                        EnglishGreat Britain
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 7, 2024 02:51:08.571592093 CEST49675443192.168.2.4173.222.162.32
                        Oct 7, 2024 02:51:09.996483088 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:09.996531963 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:09.996999979 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:09.998559952 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:09.998574972 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.642353058 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.642550945 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.642564058 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.643317938 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.643382072 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.644751072 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.644799948 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.645735025 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.645817041 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.645896912 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.687402010 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.701308966 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.701322079 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.763806105 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.920799017 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.920864105 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.920887947 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.920996904 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.921056032 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.925278902 CEST49733443192.168.2.4142.250.186.78
                        Oct 7, 2024 02:51:10.925309896 CEST44349733142.250.186.78192.168.2.4
                        Oct 7, 2024 02:51:10.945611954 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:10.945652962 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:10.945718050 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:10.946269035 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:10.946299076 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.634720087 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.635080099 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.635109901 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.635698080 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.635776997 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.636712074 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.636779070 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.638022900 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.638108969 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.638251066 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.638266087 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.685687065 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.929136992 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.929182053 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.929338932 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:11.929373026 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.929420948 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.933242083 CEST49736443192.168.2.4142.250.185.238
                        Oct 7, 2024 02:51:11.933281898 CEST44349736142.250.185.238192.168.2.4
                        Oct 7, 2024 02:51:14.514964104 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:14.515059948 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:14.515150070 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:14.515341997 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:14.515381098 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:14.754251003 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:14.754333973 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:14.754467964 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:14.756179094 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:14.756253958 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.167756081 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:15.168112040 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:15.168181896 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:15.169680119 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:15.169866085 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:15.170789957 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:15.170890093 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:15.216269016 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:15.216329098 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:15.263004065 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:15.396032095 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.396261930 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.403639078 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.403693914 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.404071093 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.453774929 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.455163956 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.499475956 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.663203955 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.663263083 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.663459063 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.673985004 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.673985004 CEST49742443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.674052000 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.674086094 CEST44349742184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.726142883 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.726241112 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:15.726346970 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.726656914 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:15.726696968 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:16.390698910 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:16.390801907 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:16.393105030 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:16.393126965 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:16.393465042 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:16.394658089 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:16.435401917 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:16.672137022 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:16.672199011 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:16.672267914 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:16.673145056 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:16.673173904 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:16.673192978 CEST49744443192.168.2.4184.28.90.27
                        Oct 7, 2024 02:51:16.673202038 CEST44349744184.28.90.27192.168.2.4
                        Oct 7, 2024 02:51:21.080343008 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.080456972 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.080533981 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.081248045 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.081284046 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.128595114 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.128632069 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.128716946 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.129208088 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.129232883 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.715935946 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.716149092 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.716183901 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.716691971 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.716763020 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.717689991 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.717752934 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.719635963 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.719721079 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.720104933 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.720122099 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.764946938 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.773262024 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.773497105 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.773511887 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.774532080 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.774591923 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.775557995 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.775619030 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.775723934 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.775805950 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.776094913 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:21.776108027 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:21.826411963 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.129525900 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.129555941 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.129657030 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.129936934 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.129937887 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.129996061 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.130383015 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.130419970 CEST44349762142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.130444050 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.130470037 CEST49762443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.130878925 CEST49761443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.130894899 CEST44349761142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.132062912 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.132124901 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.132277012 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.133308887 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.133338928 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.133462906 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.134062052 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.134098053 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.134406090 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.134417057 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.215502024 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:22.215545893 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:22.215619087 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:22.216869116 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:22.216900110 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:22.767545938 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.767891884 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.767925978 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.768508911 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.768582106 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.769512892 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.769573927 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.769723892 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.769818068 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.769867897 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.769896030 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.769912004 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.790524960 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.790841103 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.790853977 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.791357040 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.791413069 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.792366028 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.792418003 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.792519093 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.792602062 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.792633057 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.792633057 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.792670965 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.810844898 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.842035055 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.842045069 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.891686916 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.983361006 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.984189987 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:22.984601021 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.985560894 CEST49764443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:22.985600948 CEST44349764142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:23.012343884 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:23.013185978 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:23.013272047 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:23.014579058 CEST49765443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:23.014595985 CEST44349765142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:23.021631002 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:23.021708012 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:23.027051926 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:23.027070999 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:23.027426958 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:23.067229986 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:23.121344090 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:23.163436890 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:23.390234947 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:23.390340090 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:23.390465021 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:23.390499115 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:23.390530109 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:23.390559912 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:23.390746117 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:23.391693115 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:23.451916933 CEST49740443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:51:23.451946974 CEST44349740142.250.184.228192.168.2.4
                        Oct 7, 2024 02:51:24.131939888 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:24.140178919 CEST4972380192.168.2.4199.232.210.172
                        Oct 7, 2024 02:51:24.145643950 CEST8049723199.232.210.172192.168.2.4
                        Oct 7, 2024 02:51:24.145776033 CEST4972380192.168.2.4199.232.210.172
                        Oct 7, 2024 02:51:24.179404020 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392435074 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392467976 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392482042 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392498970 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392525911 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:24.392541885 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392595053 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392627954 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:24.392628908 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:24.392631054 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392652035 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:24.392664909 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392690897 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:24.392709017 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:24.392721891 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392743111 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:24.392815113 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:25.054670095 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:25.054711103 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:25.054738045 CEST49768443192.168.2.44.175.87.197
                        Oct 7, 2024 02:51:25.054770947 CEST443497684.175.87.197192.168.2.4
                        Oct 7, 2024 02:51:28.719268084 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:28.719327927 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:28.719427109 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:28.719727039 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:28.719755888 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:29.344686031 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:29.344957113 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:29.344986916 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:29.345354080 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:29.345849037 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:29.345917940 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:29.346285105 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:29.346328974 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:29.346340895 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:29.674789906 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:29.675848961 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:29.675916910 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:29.676992893 CEST49780443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:29.677020073 CEST44349780142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:52.167268038 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:52.167357922 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:52.167467117 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:52.167886019 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:52.167926073 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:52.802532911 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:52.802964926 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:52.803025961 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:52.804708958 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:52.805064917 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:52.805228949 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:52.805228949 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:52.805247068 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:52.805293083 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:52.857670069 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.102816105 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.103411913 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.103568077 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.103614092 CEST49781443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.103635073 CEST44349781142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.143841982 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.143887043 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.144157887 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.144239902 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.144256115 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.777478933 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.777762890 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.777825117 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.779088020 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.780678034 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.780841112 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.780841112 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:53.780865908 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.780976057 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:53.827315092 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:54.077534914 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:54.077830076 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:54.078006983 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:54.078387976 CEST49782443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:54.078449965 CEST44349782142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.235479116 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:55.235582113 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.236125946 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:55.236237049 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:55.236268997 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.902275085 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.902614117 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:55.902683020 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.904014111 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.904315948 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:55.904464006 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:55.904484034 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.904508114 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:55.904524088 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.947427988 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:55.951436996 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:56.204869032 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:56.205250978 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:56.205322027 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:56.205415964 CEST49783443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:51:56.205456972 CEST44349783142.250.181.238192.168.2.4
                        Oct 7, 2024 02:51:58.161860943 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:58.161919117 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.162009954 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:58.162350893 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:58.162383080 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.811069965 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.811458111 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:58.814809084 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:58.814845085 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.815351009 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.823916912 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:58.871434927 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.926023960 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.926090002 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.926239967 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.926271915 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:58.926338911 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:58.926374912 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:58.926399946 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.011723042 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.011780977 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.011857986 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.011878014 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.011905909 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.011926889 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.014147997 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.014189959 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.014225960 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.014236927 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.014264107 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.014281988 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.098108053 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.098157883 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.098390102 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.098426104 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.098479986 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.099236012 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.099275112 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.099318981 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.099332094 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.099378109 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.099378109 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.100358009 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.100405931 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.100430965 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.100442886 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.100488901 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.100509882 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.101408005 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.101459026 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.101485014 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.101495981 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.101521015 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.101541996 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.184843063 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.184885025 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.184922934 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.184942961 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.184969902 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.184989929 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.185219049 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.185259104 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.185297966 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.185307980 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.185333014 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.185352087 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.186029911 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.186068058 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.186105013 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.186114073 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.186141014 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.186160088 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.186597109 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.186640024 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.186670065 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.186682940 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.186708927 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.186726093 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.187093973 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.187134981 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.187163115 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.187174082 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.187201023 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.187218904 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.187357903 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.187531948 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.187582016 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.190078020 CEST49784443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.190113068 CEST4434978413.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.376271963 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.376271963 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.376368046 CEST4434978613.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.376409054 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.376476049 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.376543999 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.381460905 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.381460905 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.381546974 CEST4434978613.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.381591082 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.382409096 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.382477999 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.382548094 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.382687092 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.382704973 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.383590937 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.383691072 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.383759975 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.384392023 CEST49789443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.384424925 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.384483099 CEST49789443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.384577990 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.384613991 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:51:59.384641886 CEST49789443192.168.2.413.107.246.45
                        Oct 7, 2024 02:51:59.384661913 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.021639109 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.022175074 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.022250891 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.022667885 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.022684097 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.022732973 CEST4434978613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.023181915 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.023267984 CEST4434978613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.023479939 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.023497105 CEST4434978613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.024710894 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.024987936 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.025018930 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.025295973 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.025307894 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.036118984 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.036731005 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.036787987 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.037197113 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.037209034 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.082536936 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.082937956 CEST49789443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.082973003 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.083355904 CEST49789443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.083363056 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.120301008 CEST4434978613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.120440960 CEST4434978613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.120621920 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.120623112 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.120623112 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.122723103 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.122741938 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.122805119 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.122838020 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.122859955 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.122894049 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.122921944 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.123018980 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.123051882 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.123076916 CEST49787443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.123090982 CEST4434978713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.123801947 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.123842955 CEST4434979013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.123914957 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.124053001 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.124067068 CEST4434979013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.125312090 CEST49791443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.125384092 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.125451088 CEST49791443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.125549078 CEST49791443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.125556946 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.125576973 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.125629902 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.125705004 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.125766039 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.125811100 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.125829935 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.125859976 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.125921011 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.125921011 CEST49785443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.125955105 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.125977993 CEST4434978513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.127705097 CEST49792443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.127806902 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.127880096 CEST49792443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.127989054 CEST49792443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.128012896 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.140857935 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.140908003 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.141020060 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.141046047 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.141083002 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.141247988 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.141278028 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.141304016 CEST49788443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.141318083 CEST4434978813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.143415928 CEST49793443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.143497944 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.143590927 CEST49793443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.143872023 CEST49793443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.143953085 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.187881947 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.188013077 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.188097954 CEST49789443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.188138962 CEST49789443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.188138962 CEST49789443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.188158989 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.188173056 CEST4434978913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.190414906 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.190498114 CEST4434979413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.190588951 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.190762043 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.190798998 CEST4434979413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.420367956 CEST49786443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.420432091 CEST4434978613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.800617933 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.801446915 CEST49791443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.801505089 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.801893950 CEST49791443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.801907063 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.815825939 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.816123962 CEST49792443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.816169977 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.816423893 CEST49792443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.816437006 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.823502064 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.823842049 CEST49793443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.823900938 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.824018002 CEST49793443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.824032068 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.826864958 CEST4434979013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.827214956 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.827260971 CEST4434979013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.827382088 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.827400923 CEST4434979013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.835447073 CEST4434979413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.835679054 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.835758924 CEST4434979413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.836096048 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.836179018 CEST4434979413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.908484936 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.908548117 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.908618927 CEST49791443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.908838987 CEST49791443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.908839941 CEST49791443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.908879995 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.908904076 CEST4434979113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.911531925 CEST49795443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.911597013 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.911684036 CEST49795443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.911823034 CEST49795443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.911839008 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.922025919 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.922208071 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.922267914 CEST49792443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.922316074 CEST49792443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.922341108 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.922368050 CEST49792443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.922379971 CEST4434979213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.923234940 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.923374891 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.923456907 CEST49793443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.923531055 CEST49793443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.923531055 CEST49793443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.923572063 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.923607111 CEST4434979313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.924877882 CEST49796443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.924910069 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.924989939 CEST49796443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.925098896 CEST49796443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.925107956 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.925456047 CEST49797443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.925539017 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.925616026 CEST49797443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.925750971 CEST49797443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.925785065 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.932723045 CEST4434979013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.932869911 CEST4434979013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.933016062 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.933016062 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.933016062 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.934211016 CEST4434979413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.934349060 CEST4434979413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.934541941 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.934541941 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.934541941 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.934931993 CEST49798443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.935014963 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.935087919 CEST49798443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.935204983 CEST49798443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.935228109 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.936532021 CEST49799443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.936541080 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:00.936599016 CEST49799443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.936701059 CEST49799443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:00.936709881 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.232682943 CEST49794443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.232762098 CEST4434979413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.248231888 CEST49790443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.248254061 CEST4434979013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.666764021 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.674763918 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.674788952 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.676248074 CEST49795443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.676328897 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.676651955 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.676656008 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.682674885 CEST49795443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.682693005 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.685794115 CEST49799443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.685815096 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.689383984 CEST49799443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.689389944 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.692749977 CEST49796443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.692754984 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.705954075 CEST49796443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.705957890 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.713021994 CEST49798443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.713104963 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.717057943 CEST49798443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.717057943 CEST49797443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.717113972 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.717190981 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.720638037 CEST49797443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.720693111 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.779588938 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.779679060 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.779743910 CEST49795443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.786705017 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.786860943 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.787066936 CEST49799443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.802359104 CEST49795443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.802406073 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.802433968 CEST49795443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.802453041 CEST4434979513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.803400993 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.803561926 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.803612947 CEST49796443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.803836107 CEST49799443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.803860903 CEST49799443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.803872108 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.803888083 CEST4434979913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.805782080 CEST49796443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.805787086 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.805797100 CEST49796443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.805799961 CEST4434979613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.812602997 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.812746048 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.812910080 CEST49798443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.815923929 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.816067934 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.816257954 CEST49797443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.820290089 CEST49800443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.820333004 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.820396900 CEST49800443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.822475910 CEST49798443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.822475910 CEST49798443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.822540045 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.822568893 CEST4434979813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.822766066 CEST49801443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.822834015 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.822895050 CEST49801443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.824011087 CEST49797443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.824011087 CEST49797443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.824017048 CEST49802443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.824028015 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.824035883 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.824050903 CEST4434979713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.824106932 CEST49802443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.824223995 CEST49800443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.824244976 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.824357986 CEST49801443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.824388027 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.825959921 CEST49802443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.825995922 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.826612949 CEST49803443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.826625109 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.826790094 CEST49803443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.826941013 CEST49803443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.826956034 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.827186108 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.827270031 CEST4434980413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:01.827351093 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.827502966 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:01.827543020 CEST4434980413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.107228041 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:02.107311010 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:02.107460022 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:02.108556986 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:02.108639956 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:02.470587015 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.472800016 CEST49801443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.472882032 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.473220110 CEST49801443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.473232985 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.479127884 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.479453087 CEST49803443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.479485035 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.479813099 CEST49803443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.479820967 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.488923073 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.489240885 CEST49802443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.489281893 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.489608049 CEST49802443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.489618063 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.492502928 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.492770910 CEST49800443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.492808104 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.493100882 CEST49800443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.493108034 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.508141994 CEST4434980413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.508630037 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.508718967 CEST4434980413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.508836985 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.508855104 CEST4434980413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.570070982 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.570204020 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.570276022 CEST49801443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.570349932 CEST49801443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.570349932 CEST49801443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.570390940 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.570415974 CEST4434980113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.573147058 CEST49806443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.573250055 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.573317051 CEST49806443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.573431969 CEST49806443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.573452950 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.579790115 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.579929113 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.579978943 CEST49803443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.580147028 CEST49803443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.580163956 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.580176115 CEST49803443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.580183029 CEST4434980313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.583736897 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.583779097 CEST4434980713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.583960056 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.584017038 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.584045887 CEST4434980713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.591844082 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.591912985 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.591967106 CEST49802443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.593586922 CEST49802443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.593588114 CEST49802443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.593610048 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.593633890 CEST4434980213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.595371008 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.595546961 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.595597029 CEST49800443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.595788956 CEST49800443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.595797062 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.595808029 CEST49800443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.595813036 CEST4434980013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.597743034 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.597825050 CEST4434980813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.597908020 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.598654032 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.598737001 CEST4434980813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.599641085 CEST49809443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.599669933 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.599728107 CEST49809443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.599838018 CEST49809443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.599847078 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.612812996 CEST4434980413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.612941980 CEST4434980413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.613106012 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.613106012 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.613106012 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.614864111 CEST49810443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.614875078 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.614938021 CEST49810443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.615046024 CEST49810443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.615053892 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.919960976 CEST49804443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:02.920022964 CEST4434980413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:02.926393986 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:02.926640987 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:02.928103924 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:02.928157091 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:02.928575993 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:02.939145088 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:02.979474068 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.227282047 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.230663061 CEST49806443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.230731964 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.231632948 CEST49806443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.231647968 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.249197006 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.249557972 CEST49809443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.249573946 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.249917030 CEST49809443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.249921083 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.254962921 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.255204916 CEST49810443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.255215883 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.255494118 CEST49810443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.255497932 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.263138056 CEST4434980713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.263499022 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.263581038 CEST4434980713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.263832092 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.263860941 CEST4434980713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.266841888 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.266910076 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.267030001 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.267105103 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:03.267106056 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:03.267169952 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.267239094 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:03.267824888 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.268013954 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.268013954 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:03.268093109 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:03.268348932 CEST4434980813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.268781900 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.268867016 CEST4434980813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.269150019 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.269201994 CEST4434980813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.271810055 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:03.271847963 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.271877050 CEST49805443192.168.2.44.175.87.197
                        Oct 7, 2024 02:52:03.271892071 CEST443498054.175.87.197192.168.2.4
                        Oct 7, 2024 02:52:03.329771042 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.329905987 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.330004930 CEST49806443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.330156088 CEST49806443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.330156088 CEST49806443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.330195904 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.330220938 CEST4434980613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.334001064 CEST49811443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.334084988 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.334191084 CEST49811443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.334359884 CEST49811443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.334388971 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.350672007 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.350735903 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.350797892 CEST49809443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.350989103 CEST49809443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.351003885 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.351032019 CEST49809443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.351037979 CEST4434980913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.353092909 CEST49812443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.353174925 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.353602886 CEST49812443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.353602886 CEST49812443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.353735924 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.354410887 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.354557991 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.354633093 CEST49810443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.354711056 CEST49810443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.354716063 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.354741096 CEST49810443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.354744911 CEST4434981013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.356911898 CEST49813443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.356997967 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.357393026 CEST49813443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.357600927 CEST49813443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.357636929 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.367216110 CEST4434980713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.367362976 CEST4434980713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.367748022 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.367748976 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.367748976 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.369467974 CEST49814443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.369492054 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.369568110 CEST49814443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.369683981 CEST49814443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.369709015 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.370317936 CEST4434980813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.370449066 CEST4434980813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.370654106 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.370654106 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.370655060 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.372788906 CEST49815443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.372872114 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.373445034 CEST49815443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.373445034 CEST49815443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.373574018 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.672271967 CEST49807443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.672333956 CEST4434980713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.672347069 CEST49808443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.672406912 CEST4434980813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.973741055 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.976250887 CEST49811443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.976337910 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.976711988 CEST49811443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.976767063 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.991714954 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.996004105 CEST49812443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.996038914 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:03.996431112 CEST49812443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:03.996438026 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.018119097 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.019965887 CEST49814443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.020020008 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.020404100 CEST49814443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.020416021 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.025098085 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.033051968 CEST49813443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.033082962 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.033478022 CEST49813443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.033488035 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.039616108 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.072882891 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.073031902 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.073162079 CEST49811443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.074990034 CEST49815443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.075050116 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.075427055 CEST49815443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.075479031 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.075968981 CEST49811443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.075969934 CEST49811443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.076035023 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.076071024 CEST4434981113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.078588963 CEST49816443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.078680992 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.078764915 CEST49816443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.078881025 CEST49816443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.078911066 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.097454071 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.097613096 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.097812891 CEST49812443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.100925922 CEST49812443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.100925922 CEST49812443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.100991011 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.101033926 CEST4434981213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.116637945 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.116785049 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.116872072 CEST49814443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.122677088 CEST49814443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.122692108 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.122704029 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.122751951 CEST49814443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.122769117 CEST4434981413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.122778893 CEST4434981713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.122894049 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.132069111 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.132152081 CEST4434981713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.136287928 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.136584997 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.136679888 CEST49813443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.138289928 CEST49813443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.138307095 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.138350964 CEST49813443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.138361931 CEST4434981313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.142163038 CEST49818443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.142246962 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.142780066 CEST49818443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.148559093 CEST49818443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.148641109 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.174824953 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.174958944 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.175112009 CEST49819443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.175192118 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.175199032 CEST49815443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.175268888 CEST49819443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.178992987 CEST49815443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.178992987 CEST49815443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.179039001 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.179068089 CEST4434981513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.199179888 CEST49819443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.199218035 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.219316006 CEST49820443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.219409943 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.219552040 CEST49820443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.219860077 CEST49820443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.219891071 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.724750042 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.725316048 CEST49816443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.725377083 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.725765944 CEST49816443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.725781918 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.772488117 CEST4434981713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.773083925 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.773144007 CEST4434981713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.773350954 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.773365021 CEST4434981713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.799329996 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.799849033 CEST49818443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.799907923 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.799973011 CEST49818443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.799988031 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.811844110 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.812150955 CEST49820443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.812201977 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.812536955 CEST49820443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.812551022 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.850697994 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.850837946 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.850918055 CEST49816443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.850996017 CEST49816443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.850996017 CEST49816443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.851038933 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.851069927 CEST4434981613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.853483915 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.853914976 CEST49819443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.853952885 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.854211092 CEST49821443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.854237080 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.854406118 CEST49821443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.854444027 CEST49821443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.854454041 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.854547024 CEST49819443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.854574919 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.870934963 CEST4434981713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.871073961 CEST4434981713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.871277094 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.871277094 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.871277094 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.873713970 CEST49822443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.873740911 CEST4434982213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.873847008 CEST49822443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.873951912 CEST49822443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.873965979 CEST4434982213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.899549007 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.899698973 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.899789095 CEST49818443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.899929047 CEST49818443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.899974108 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.900003910 CEST49818443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.900018930 CEST4434981813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.902766943 CEST49823443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.902849913 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.902964115 CEST49823443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.903058052 CEST49823443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.903078079 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.914865017 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.915010929 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.915080070 CEST49820443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.915232897 CEST49820443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.915232897 CEST49820443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.915256977 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.915278912 CEST4434982013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.917232037 CEST49824443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.917254925 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.917340040 CEST49824443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.917527914 CEST49824443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.917550087 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.953713894 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.953845978 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.953922033 CEST49819443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.954032898 CEST49819443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.954032898 CEST49819443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.954061031 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.954083920 CEST4434981913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.956747055 CEST49825443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.956768990 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:04.956842899 CEST49825443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.956980944 CEST49825443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:04.956994057 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.091944933 CEST49817443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.092006922 CEST4434981713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.494640112 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.495177031 CEST49821443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.495206118 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.495862007 CEST49821443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.495867014 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.518490076 CEST4434982213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.518930912 CEST49822443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.518960953 CEST4434982213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.519423962 CEST49822443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.519443035 CEST4434982213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.545782089 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.552386999 CEST49823443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.552428007 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.552910089 CEST49823443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.552922964 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.591767073 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.592468023 CEST49824443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.592499018 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.592535973 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.592663050 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.592725992 CEST49821443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.593101978 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.593372107 CEST49824443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.593393087 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.593564987 CEST49821443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.593575001 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.593584061 CEST49821443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.593588114 CEST4434982113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.593770981 CEST49825443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.593785048 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.594418049 CEST49825443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.594422102 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.597789049 CEST49826443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.597801924 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.597870111 CEST49826443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.597981930 CEST49826443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.597986937 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.617010117 CEST4434982213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.617141962 CEST4434982213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.617204905 CEST49822443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.617216110 CEST49822443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.617219925 CEST4434982213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.620016098 CEST49827443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.620084047 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.620177984 CEST49827443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.620526075 CEST49827443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.620553970 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.673160076 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.673296928 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.673361063 CEST49823443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.673428059 CEST49823443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.673455954 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.673481941 CEST49823443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.673497915 CEST4434982313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.675645113 CEST49828443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.675733089 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.675832033 CEST49828443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.675940990 CEST49828443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.675961971 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.690874100 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.691006899 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.691075087 CEST49825443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.691143990 CEST49825443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.691155910 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.691164970 CEST49825443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.691169977 CEST4434982513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.693056107 CEST49829443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.693140030 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.693233013 CEST49829443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.693325996 CEST49829443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.693351984 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.697951078 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.698005915 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.698163033 CEST49824443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.698328972 CEST49824443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.698328972 CEST49824443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.698357105 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.698380947 CEST4434982413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.700303078 CEST49830443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.700330973 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:05.700427055 CEST49830443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.700520039 CEST49830443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:05.700546980 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.278760910 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.283696890 CEST49826443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.283718109 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.284543991 CEST49826443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.284550905 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.357211113 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.357661009 CEST49827443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.357728004 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.358093977 CEST49827443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.358107090 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.358710051 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.358952045 CEST49830443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.359030008 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.359231949 CEST49830443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.359246969 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.363162041 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.363377094 CEST49828443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.363461018 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.363672018 CEST49828443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.363688946 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.368200064 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.368520975 CEST49829443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.368555069 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.368870020 CEST49829443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.368880987 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.381819010 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.381887913 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.381948948 CEST49826443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.382045031 CEST49826443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.382057905 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.382069111 CEST49826443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.382074118 CEST4434982613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.384486914 CEST49831443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.384567976 CEST4434983113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.384660006 CEST49831443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.384778976 CEST49831443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.384793997 CEST4434983113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.458173037 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.458235979 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.458309889 CEST49830443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.458550930 CEST49830443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.458569050 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.458587885 CEST49830443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.458595037 CEST4434983013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.461687088 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.461743116 CEST49832443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.461827040 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.461833954 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.461895943 CEST49828443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.461930037 CEST49832443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.462157011 CEST49832443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.462194920 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.462202072 CEST49828443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.462232113 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.462260008 CEST49828443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.462275982 CEST4434982813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.464709997 CEST49833443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.464802980 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.464896917 CEST49833443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.465050936 CEST49833443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.465085983 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.468729019 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.468854904 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.468911886 CEST49829443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.468974113 CEST49829443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.468981028 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.468998909 CEST49829443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.469003916 CEST4434982913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.471381903 CEST49834443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.471422911 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.471506119 CEST49834443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.471678019 CEST49834443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.471702099 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.491924047 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.492058039 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.492146015 CEST49827443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.492234945 CEST49827443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.492270947 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.492299080 CEST49827443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.492314100 CEST4434982713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.494693995 CEST49835443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.494776011 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:06.494862080 CEST49835443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.495042086 CEST49835443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:06.495078087 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.104672909 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.105521917 CEST49832443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.105581045 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.106134892 CEST49832443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.106188059 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.112871885 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.113318920 CEST49834443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.113377094 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.113523960 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.113933086 CEST49834443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.113934040 CEST49833443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.113951921 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.114027977 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.114346981 CEST49833443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.114357948 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.114500999 CEST4434983113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.114876986 CEST49831443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.114934921 CEST4434983113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.115427017 CEST49831443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.115439892 CEST4434983113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.131690979 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.132247925 CEST49835443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.132308006 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.132790089 CEST49835443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.132843018 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.203324080 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.203372002 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.203505993 CEST49832443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.203710079 CEST49832443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.203751087 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.203809977 CEST49832443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.203825951 CEST4434983213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.206856966 CEST49836443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.206940889 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.207037926 CEST49836443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.207195044 CEST49836443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.207232952 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.211359978 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.211427927 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.211496115 CEST49834443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.211590052 CEST49834443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.211590052 CEST49834443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.211632967 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.211674929 CEST4434983413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.213947058 CEST49837443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.213983059 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.214056015 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.214068890 CEST49837443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.214122057 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.214183092 CEST49833443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.214287043 CEST49837443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.214302063 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.214360952 CEST49833443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.214378119 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.214401007 CEST49833443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.214413881 CEST4434983313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.214509964 CEST4434983113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.214668989 CEST4434983113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.214749098 CEST49831443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.214749098 CEST49831443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.214821100 CEST49831443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.214859009 CEST4434983113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.216861963 CEST49838443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.216871977 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.216895103 CEST49839443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.216943026 CEST49838443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.216978073 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.217037916 CEST49838443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.217047930 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.217058897 CEST49839443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.217264891 CEST49839443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.217294931 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.231008053 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.231200933 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.231292009 CEST49835443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.231379032 CEST49835443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.231379032 CEST49835443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.231446028 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.231476068 CEST4434983513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.233561039 CEST49840443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.233644009 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.233750105 CEST49840443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.233917952 CEST49840443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.233953953 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.851438999 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.852404118 CEST49836443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.852463007 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.852946997 CEST49836443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.852962017 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.860862017 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.861408949 CEST49839443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.861443996 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.861709118 CEST49839443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.861720085 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.869209051 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.869498014 CEST49838443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.869534969 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.869792938 CEST49838443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.869800091 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.884469032 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.887990952 CEST49840443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.888048887 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.888803005 CEST49840443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.888818026 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.904510975 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.907975912 CEST49837443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.907985926 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.908543110 CEST49837443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.908546925 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.952299118 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.952438116 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.952528000 CEST49836443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.953115940 CEST49836443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.953115940 CEST49836443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.953157902 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.953183889 CEST4434983613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.957576036 CEST49841443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.957664013 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.957757950 CEST49841443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.957952976 CEST49841443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.958004951 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.959769011 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.959912062 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.960032940 CEST49839443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.960223913 CEST49839443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.960242033 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.960263968 CEST49839443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.960275888 CEST4434983913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.962759972 CEST49842443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.962781906 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.963690996 CEST49842443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.963830948 CEST49842443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.963855982 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.969449997 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.969508886 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.969723940 CEST49838443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.969759941 CEST49838443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.969759941 CEST49838443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.969779015 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.969793081 CEST4434983813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.986232042 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.986365080 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.986483097 CEST49840443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.994287968 CEST49840443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.994332075 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.994359970 CEST49840443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.994375944 CEST4434984013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.997268915 CEST49843443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.997308969 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.997419119 CEST49843443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.997771025 CEST49843443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.997802973 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.999026060 CEST49844443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.999053955 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:07.999665022 CEST49844443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.999759912 CEST49844443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:07.999773026 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.009448051 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.009510040 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.009594917 CEST49837443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.009732962 CEST49837443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.009747028 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.009757996 CEST49837443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.009766102 CEST4434983713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.012120008 CEST49845443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.012150049 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.012214899 CEST49845443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.012366056 CEST49845443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.012372971 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.597745895 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.598340988 CEST49841443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.598417997 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.598799944 CEST49841443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.598814964 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.614579916 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.614970922 CEST49842443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.614986897 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.615565062 CEST49842443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.615575075 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.638590097 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.642004967 CEST49844443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.642025948 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.642821074 CEST49844443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.642826080 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.648789883 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.649197102 CEST49843443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.649255991 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.649770021 CEST49843443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.649784088 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.671895027 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.682063103 CEST49845443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.682084084 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.682584047 CEST49845443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.682590008 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.700613976 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.700977087 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.701041937 CEST49841443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.705770016 CEST49841443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.705812931 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.705841064 CEST49841443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.705857038 CEST4434984113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.709465027 CEST49846443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.709497929 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.709575891 CEST49846443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.709893942 CEST49846443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.709904909 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.715012074 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.715168953 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.715224981 CEST49842443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.715277910 CEST49842443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.715308905 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.715339899 CEST49842443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.715349913 CEST4434984213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.717983961 CEST49847443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.718008041 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.718074083 CEST49847443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.718189955 CEST49847443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.718204021 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.738409042 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.738543034 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.738604069 CEST49844443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.738667965 CEST49844443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.738677979 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.738688946 CEST49844443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.738692999 CEST4434984413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.740820885 CEST49848443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.740858078 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.741009951 CEST49848443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.741131067 CEST49848443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.741154909 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.756195068 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.756321907 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.756402969 CEST49843443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.756587982 CEST49843443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.756587982 CEST49843443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.756630898 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.756659985 CEST4434984313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.759022951 CEST49849443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.759108067 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.759188890 CEST49849443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.759373903 CEST49849443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.759423018 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.783442974 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.783488035 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.783544064 CEST49845443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.783710957 CEST49845443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.783724070 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.783734083 CEST49845443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.783737898 CEST4434984513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.785989046 CEST49850443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.786014080 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:08.786112070 CEST49850443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.786201000 CEST49850443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:08.786226034 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.363368988 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.373969078 CEST49846443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.374032974 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.374389887 CEST49846443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.374403000 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.374536991 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.374882936 CEST49847443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.374917030 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.375093937 CEST49847443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.375101089 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.424340010 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.424793959 CEST49850443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.424873114 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.425364971 CEST49850443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.425385952 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.432353973 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.432712078 CEST49848443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.432735920 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.433252096 CEST49848443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.433258057 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.452348948 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.452775955 CEST49849443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.452826023 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.453324080 CEST49849443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.453347921 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.472059011 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.472407103 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.472487926 CEST49846443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.472557068 CEST49846443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.472557068 CEST49846443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.472595930 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.472624063 CEST4434984613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.474967003 CEST49851443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.474998951 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.475097895 CEST49851443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.475198030 CEST49851443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.475203991 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.475281000 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.475347996 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.475402117 CEST49847443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.475428104 CEST49847443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.475438118 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.475465059 CEST49847443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.475471020 CEST4434984713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.477127075 CEST49852443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.477210999 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.477292061 CEST49852443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.477384090 CEST49852443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.477408886 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.523508072 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.523652077 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.523735046 CEST49850443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.523824930 CEST49850443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.523858070 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.523883104 CEST49850443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.523897886 CEST4434985013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.526190996 CEST49853443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.526273012 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.526376009 CEST49853443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.526563883 CEST49853443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.526601076 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.536473989 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.536627054 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.536691904 CEST49848443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.536724091 CEST49848443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.536746025 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.536757946 CEST49848443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.536763906 CEST4434984813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.539004087 CEST49854443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.539036989 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.539189100 CEST49854443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.539381027 CEST49854443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.539419889 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.559212923 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.559350967 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.559425116 CEST49849443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.559537888 CEST49849443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.559557915 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.559581041 CEST49849443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.559591055 CEST4434984913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.561851025 CEST49855443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.561908007 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:09.561996937 CEST49855443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.562103987 CEST49855443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:09.562124014 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.122411013 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.123056889 CEST49851443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.123074055 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.123622894 CEST49851443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.123629093 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.126440048 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.126754045 CEST49852443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.126804113 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.127091885 CEST49852443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.127104044 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.172497034 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.172939062 CEST49853443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.173012018 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.173280954 CEST49853443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.173294067 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.173969030 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.174217939 CEST49854443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.174232006 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.174531937 CEST49854443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.174542904 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.196048021 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.196507931 CEST49855443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.196566105 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.196772099 CEST49855443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.196784973 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.224544048 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.224694967 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.224791050 CEST49851443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.224957943 CEST49851443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.224976063 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.225008965 CEST49851443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.225014925 CEST4434985113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.227650881 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.227794886 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.227819920 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.227876902 CEST49852443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.227888107 CEST4434985713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.227962017 CEST49852443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.227962017 CEST49852443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.227965117 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.228008032 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.228037119 CEST4434985213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.228099108 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.228118896 CEST4434985713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.229979038 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.230000973 CEST4434985813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.230077982 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.230192900 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.230216026 CEST4434985813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.271738052 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.271878004 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.271987915 CEST49853443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.272142887 CEST49853443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.272142887 CEST49853443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.272186995 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.272212982 CEST4434985313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.272790909 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.272861004 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.272912025 CEST49854443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.272986889 CEST49854443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.273000956 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.273041964 CEST49854443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.273055077 CEST4434985413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.274159908 CEST49859443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.274194002 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.274257898 CEST49859443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.274370909 CEST49859443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.274390936 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.274727106 CEST49860443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.274811983 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.274890900 CEST49860443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.275002003 CEST49860443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.275029898 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.297190905 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.297342062 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.297406912 CEST49855443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.297451973 CEST49855443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.297452927 CEST49855443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.297475100 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.297497034 CEST4434985513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.299201012 CEST49861443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.299283028 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.299360991 CEST49861443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.299479008 CEST49861443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.299499989 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.576431990 CEST4972480192.168.2.4199.232.210.172
                        Oct 7, 2024 02:52:10.581929922 CEST8049724199.232.210.172192.168.2.4
                        Oct 7, 2024 02:52:10.582011938 CEST4972480192.168.2.4199.232.210.172
                        Oct 7, 2024 02:52:10.883055925 CEST4434985713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.883630037 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.883688927 CEST4434985713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.884084940 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.884099960 CEST4434985713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.899446964 CEST4434985813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.900111914 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.900172949 CEST4434985813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.900325060 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.900341988 CEST4434985813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.940876961 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.941422939 CEST49859443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.941433907 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.941643000 CEST49859443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.941648006 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.954632998 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.954943895 CEST49860443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.955018044 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.955236912 CEST49860443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.955250978 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.977386951 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.977896929 CEST49861443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.977957010 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.978101969 CEST49861443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.978116989 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.983490944 CEST4434985713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.983632088 CEST4434985713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.983901024 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.983901024 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.983901024 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.986342907 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.986428022 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:10.986524105 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.986685038 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:10.986711025 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.001188993 CEST4434985813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.001759052 CEST4434985813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.002120018 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.002120972 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.002120972 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.004084110 CEST49863443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.004167080 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.004259109 CEST49863443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.004390001 CEST49863443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.004424095 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.043657064 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.043796062 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.043906927 CEST49859443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.043921947 CEST49859443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.043932915 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.043940067 CEST49859443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.043945074 CEST4434985913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.045727015 CEST49864443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.045809984 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.045887947 CEST49864443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.045989990 CEST49864443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.046009064 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.058435917 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.058588028 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.058799982 CEST49860443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.058885098 CEST49860443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.058885098 CEST49860443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.058928013 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.058974028 CEST4434986013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.060954094 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.061034918 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.061117887 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.061244965 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.061281919 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.081618071 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.081784010 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.081844091 CEST49861443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.083885908 CEST49861443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.083885908 CEST49861443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.083934069 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.083961964 CEST4434986113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.086188078 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.086225033 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.086464882 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.086466074 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.086524010 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.201813936 CEST49857443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.201884985 CEST4434985713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.311626911 CEST49858443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.311674118 CEST4434985813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.632913113 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.644184113 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.678735971 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.683238983 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.683290958 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.684034109 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.684048891 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.684329987 CEST49863443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.684395075 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.684688091 CEST49863443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.684700966 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.700464964 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.701926947 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.704864025 CEST49864443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.704905033 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.712507010 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.712522030 CEST49864443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.712548971 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.712558985 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.725316048 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.727792025 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.727804899 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.733571053 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.733586073 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.733957052 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.733967066 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.780168056 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.780307055 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.780394077 CEST49863443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.782119036 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.782164097 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.782243967 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.782273054 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.786477089 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.810118914 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.810257912 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.810439110 CEST49864443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.833563089 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.833590984 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.833611012 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.833656073 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.833692074 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.833719015 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.833745956 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.833746910 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.833766937 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.833792925 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.833792925 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.833792925 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.833839893 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.876912117 CEST49863443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.876912117 CEST49863443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.876954079 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.876981974 CEST4434986313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.878106117 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.878134966 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.878160954 CEST49865443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.878161907 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.878180981 CEST4434986513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.878204107 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.878226042 CEST49866443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.878237009 CEST4434986613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.879683971 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.879683971 CEST49862443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.879690886 CEST49864443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.879690886 CEST49864443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.879724026 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.879741907 CEST4434986413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.879750013 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.879785061 CEST4434986213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.883745909 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.883805037 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.883869886 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.884958029 CEST49868443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.884990931 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.885046005 CEST49868443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.885287046 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.885327101 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.885811090 CEST49869443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.885885000 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.885941029 CEST49869443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.886127949 CEST49869443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.886158943 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.886823893 CEST49870443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.886854887 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.886914968 CEST49870443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.886930943 CEST49868443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.886945963 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.887162924 CEST49870443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.887191057 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.888144970 CEST49871443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.888154984 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:11.888206005 CEST49871443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.891390085 CEST49871443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:11.891403913 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.525767088 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.526417971 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.526478052 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.526783943 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.526799917 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.535729885 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.537834883 CEST49870443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.537879944 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.538300037 CEST49870443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.538311958 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.559721947 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.560031891 CEST49868443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.560061932 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.560544014 CEST49868443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.560550928 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.564876080 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.565294027 CEST49869443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.565326929 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.565727949 CEST49869443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.565737963 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.572666883 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.573084116 CEST49871443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.573101997 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.573457956 CEST49871443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.573463917 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.624099970 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.624140978 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.624305010 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.624337912 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.624413013 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.624454975 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.624454975 CEST49867443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.624495983 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.624526978 CEST4434986713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.627402067 CEST49872443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.627484083 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.627585888 CEST49872443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.627706051 CEST49872443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.627732992 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.636893034 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.637056112 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.637129068 CEST49870443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.637192011 CEST49870443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.637192011 CEST49870443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.637223959 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.637248993 CEST4434987013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.639698029 CEST49873443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.639760971 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.639921904 CEST49873443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.640028954 CEST49873443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.640055895 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.668951988 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.669116974 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.669183016 CEST49869443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.669219971 CEST49869443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.669219971 CEST49869443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.669235945 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.669255972 CEST4434986913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.671602011 CEST49874443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.671628952 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.671706915 CEST49874443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.671869040 CEST49874443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.671895027 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.676173925 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.676450968 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.676510096 CEST49871443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.676548004 CEST49871443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.676568985 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.676584959 CEST49871443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.676592112 CEST4434987113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.678584099 CEST49875443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.678668022 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.678755999 CEST49875443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.678890944 CEST49875443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.678922892 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.705132961 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.705363989 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.705416918 CEST49868443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.705465078 CEST49868443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.705465078 CEST49868443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.705482960 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.705497026 CEST4434986813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.707340956 CEST49876443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.707441092 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:12.707530975 CEST49876443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.707638025 CEST49876443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:12.707675934 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.285010099 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.285821915 CEST49873443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.285878897 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.286154032 CEST49873443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.286168098 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.313807964 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.314347029 CEST49872443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.314408064 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.314560890 CEST49872443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.314578056 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.320427895 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.320677996 CEST49874443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.320698977 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.320987940 CEST49874443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.320997953 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.322367907 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.322607040 CEST49875443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.322664022 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.322912931 CEST49875443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.322927952 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.353812933 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.354289055 CEST49876443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.354348898 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.354739904 CEST49876443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.354793072 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.384309053 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.384464025 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.384639025 CEST49873443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.384942055 CEST49873443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.384943008 CEST49873443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.384974957 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.384994984 CEST4434987313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.388648033 CEST49877443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.388685942 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.388967991 CEST49877443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.388968945 CEST49877443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.389005899 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.417609930 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.417762995 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.417839050 CEST49872443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.418019056 CEST49872443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.418019056 CEST49872443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.418067932 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.418102980 CEST4434987213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.419358015 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.419564009 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.419656992 CEST49874443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.419789076 CEST49874443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.419806957 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.419831038 CEST49874443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.419843912 CEST4434987413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.420114994 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.420130014 CEST4434987813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.420192957 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.420315027 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.420327902 CEST4434987813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.421777964 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.421792030 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.421881914 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.421962976 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.421974897 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.422135115 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.422158957 CEST49875443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.422188044 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.422199011 CEST49875443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.422199965 CEST49875443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.422214985 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.422240973 CEST4434987513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.424046993 CEST49880443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.424103975 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.424184084 CEST49880443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.424300909 CEST49880443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.424319983 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.455221891 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.455400944 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.455495119 CEST49876443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.455574036 CEST49876443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.455574036 CEST49876443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.455615044 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.455646992 CEST4434987613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.458189011 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.458229065 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:13.458292007 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.458434105 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:13.458452940 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.030457020 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.031119108 CEST49877443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.031147003 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.031548977 CEST49877443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.031553984 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.060125113 CEST4434987813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.060772896 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.060808897 CEST4434987813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.061034918 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.061042070 CEST4434987813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.064440966 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.064831018 CEST49880443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.064888000 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.065251112 CEST49880443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.065263987 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.074861050 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.075223923 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.075283051 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.075531006 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.075546980 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.090578079 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.090894938 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.090939045 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.091211081 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.091218948 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.129595041 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.129718065 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.129779100 CEST49877443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.130031109 CEST49877443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.130031109 CEST49877443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.130048990 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.130059004 CEST4434987713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.132823944 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.132863998 CEST4434988213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.132968903 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.133121967 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.133142948 CEST4434988213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.158312082 CEST4434987813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.158502102 CEST4434987813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.158679008 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.158679008 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.158679008 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.160729885 CEST49883443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.160793066 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.160876989 CEST49883443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.160986900 CEST49883443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.161003113 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.162575006 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.162740946 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.162803888 CEST49880443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.162851095 CEST49880443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.162851095 CEST49880443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.162875891 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.162899971 CEST4434988013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.164757967 CEST49884443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.164844036 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.164921045 CEST49884443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.165031910 CEST49884443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.165055990 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.174475908 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.174694061 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.174752951 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.174837112 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.174879074 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.175035000 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.175035000 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.175035000 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.177051067 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.177134037 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.177428961 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.177428961 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.177558899 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.190289021 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.190582991 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.190620899 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.190634012 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.190687895 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.190732002 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.190751076 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.190763950 CEST49881443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.190771103 CEST4434988113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.192605019 CEST49886443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.192672968 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.192759991 CEST49886443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.192871094 CEST49886443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.192905903 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.466626883 CEST49878443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.466650963 CEST4434987813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.482429028 CEST49879443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.482490063 CEST4434987913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.508846998 CEST49887443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:52:14.508935928 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:14.509078026 CEST49887443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:52:14.509325981 CEST49887443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:52:14.509361982 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:14.786600113 CEST4434988213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.787126064 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.787164927 CEST4434988213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.787645102 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.787661076 CEST4434988213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.801764965 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.802129984 CEST49883443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.802165031 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.802503109 CEST49883443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.802515984 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.824074984 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.824428082 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.824487925 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.824821949 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.824835062 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.834554911 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.834877014 CEST49886443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.834892988 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.835242987 CEST49886443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.835256100 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.844608068 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.844954967 CEST49884443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.845012903 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.845339060 CEST49884443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.845355988 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.887487888 CEST4434988213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.887631893 CEST4434988213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.887837887 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.887837887 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.887837887 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.890892982 CEST49888443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.890947104 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.891030073 CEST49888443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.891165972 CEST49888443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.891187906 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.900333881 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.900471926 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.900537968 CEST49883443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.900590897 CEST49883443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.900621891 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.900651932 CEST49883443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.900665998 CEST4434988313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.902525902 CEST49889443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.902607918 CEST4434988913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.902703047 CEST49889443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.902806997 CEST49889443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.902832031 CEST4434988913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.923824072 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.924335003 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.924468994 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.924511909 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.924542904 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.924592972 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.924639940 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.924639940 CEST49885443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.924670935 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.924714088 CEST4434988513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.927242994 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.927313089 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.927373886 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.927483082 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.927504063 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.933944941 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.934005976 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.934195042 CEST49886443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.935261965 CEST49886443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.935261965 CEST49886443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.935312986 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.935348034 CEST4434988613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.946630955 CEST49891443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.946687937 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.946758032 CEST49891443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.946902990 CEST49891443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.946917057 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.948729038 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.948899984 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.948949099 CEST49884443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.949348927 CEST49884443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.949374914 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.949399948 CEST49884443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.949413061 CEST4434988413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.952301979 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.952373981 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:14.952444077 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.952565908 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:14.952591896 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.153506994 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:15.153805017 CEST49887443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:52:15.153839111 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:15.154567957 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:15.155515909 CEST49887443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:52:15.155775070 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:15.189352989 CEST49882443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.189383030 CEST4434988213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.199101925 CEST49887443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:52:15.543035984 CEST4434988913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.543544054 CEST49889443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.543626070 CEST4434988913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.544018984 CEST49889443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.544033051 CEST4434988913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.576378107 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.579874039 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.579952002 CEST49888443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.580027103 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.580312967 CEST49888443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.580326080 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.580549955 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.580579996 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.580858946 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.580869913 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.592441082 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.594723940 CEST49891443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.594753027 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.595139980 CEST49891443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.595149040 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.623116970 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.623652935 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.623725891 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.624068975 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.624102116 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.641213894 CEST4434988913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.641863108 CEST4434988913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.642055035 CEST49889443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.642622948 CEST49889443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.642648935 CEST4434988913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.646816015 CEST49893443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.646852970 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.646909952 CEST49893443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.647058010 CEST49893443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.647075891 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.679862022 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.679932117 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.679989100 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.680007935 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.680053949 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.680103064 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.680171967 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.680171967 CEST49890443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.680187941 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.680207968 CEST4434989013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.681730032 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.681886911 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.681938887 CEST49888443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.682151079 CEST49888443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.682151079 CEST49888443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.682187080 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.682210922 CEST4434988813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.682374001 CEST49894443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.682387114 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.682437897 CEST49894443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.682719946 CEST49894443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.682734966 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.684218884 CEST49895443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.684282064 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.684348106 CEST49895443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.684464931 CEST49895443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.684494972 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.693468094 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.693871975 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.693928957 CEST49891443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.694015980 CEST49891443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.694032907 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.694055080 CEST49891443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.694067955 CEST4434989113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.696127892 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.696208000 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.696284056 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.696432114 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.696465969 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.723192930 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.723257065 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.723313093 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.723336935 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.723366022 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.723464966 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.723464966 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.723464966 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.725214005 CEST49897443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.725239992 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:15.725315094 CEST49897443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.725430965 CEST49897443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:15.725445032 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.044372082 CEST49892443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.044445992 CEST4434989213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.327826977 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.341847897 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.349231958 CEST49894443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.349271059 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.350543976 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.353241920 CEST49894443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.353249073 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.361175060 CEST49893443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.361191034 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.361515045 CEST49893443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.361521006 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.361699104 CEST49895443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.361763000 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.362003088 CEST49895443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.362015963 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.367176056 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.367456913 CEST49897443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.367469072 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.367790937 CEST49897443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.367795944 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.389188051 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.399360895 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.399435043 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.399722099 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.399736881 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.449147940 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.449311972 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.449393034 CEST49894443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.449605942 CEST49894443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.449628115 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.449640989 CEST49894443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.449649096 CEST4434989413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.452694893 CEST49898443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.452728033 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.452810049 CEST49898443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.452929974 CEST49898443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.452946901 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.460654974 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.460792065 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.460861921 CEST49895443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.460925102 CEST49895443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.460926056 CEST49895443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.460963964 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.460988045 CEST4434989513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.463221073 CEST49899443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.463305950 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.463454962 CEST49899443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.463546038 CEST49899443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.463572025 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.464319944 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.464451075 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.464513063 CEST49893443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.464565039 CEST49893443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.464565039 CEST49893443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.464584112 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.464598894 CEST4434989313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.466716051 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.466799974 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.467062950 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.467062950 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.467226028 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.474205017 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.474355936 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.474411011 CEST49897443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.474436045 CEST49897443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.474443913 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.474452972 CEST49897443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.474457026 CEST4434989713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.476330042 CEST49901443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.476418972 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.476505041 CEST49901443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.476636887 CEST49901443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.476660013 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.504481077 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.504930019 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.505002975 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.505023956 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.505188942 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.505188942 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.505188942 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.506937981 CEST49902443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.506961107 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.507028103 CEST49902443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.507159948 CEST49902443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.507183075 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:16.716224909 CEST49896443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:16.716284990 CEST4434989613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.096468925 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.096977949 CEST49898443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.097003937 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.097429037 CEST49898443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.097435951 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.110342026 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.110704899 CEST49899443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.110781908 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.111049891 CEST49899443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.111067057 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.118447065 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.118798018 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.118885040 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.118999004 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.119024992 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.148035049 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.148394108 CEST49902443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.148452997 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.148715019 CEST49902443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.148730040 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.171283960 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.171602964 CEST49901443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.171639919 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.171945095 CEST49901443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.171955109 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.195549011 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.195700884 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.195779085 CEST49898443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.195877075 CEST49898443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.195895910 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.195925951 CEST49898443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.195940018 CEST4434989813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.198559046 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.198600054 CEST4434990313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.198827982 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.198827982 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.198892117 CEST4434990313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.208873034 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.209022999 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.209101915 CEST49899443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.209203959 CEST49899443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.209203959 CEST49899443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.209244967 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.209289074 CEST4434989913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.211082935 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.211122990 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.211215019 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.211313009 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.211329937 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.218646049 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.218728065 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.218827963 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.218905926 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.218907118 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.219270945 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.219270945 CEST49900443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.219336987 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.219372988 CEST4434990013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.220824003 CEST49905443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.220887899 CEST4434990513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.220967054 CEST49905443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.221067905 CEST49905443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.221086025 CEST4434990513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.247270107 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.247328043 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.247378111 CEST49902443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.247473955 CEST49902443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.247509003 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.247550011 CEST49902443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.247567892 CEST4434990213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.250875950 CEST49906443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.250921965 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.251000881 CEST49906443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.251101017 CEST49906443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.251130104 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.273968935 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.274111986 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.274319887 CEST49901443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.274404049 CEST49901443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.274404049 CEST49901443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.274427891 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.274449110 CEST4434990113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.276110888 CEST49907443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.276149988 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.276216030 CEST49907443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.276319027 CEST49907443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.276331902 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.852941990 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.853851080 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.853890896 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.854324102 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.854350090 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.865145922 CEST4434990313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.865588903 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.865678072 CEST4434990313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.865742922 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.865757942 CEST4434990313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.874386072 CEST4434990513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.874614954 CEST49905443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.874635935 CEST4434990513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.874897957 CEST49905443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.874903917 CEST4434990513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.889193058 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.889702082 CEST49906443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.889738083 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.890106916 CEST49906443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.890117884 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.924716949 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.925071001 CEST49907443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.925108910 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.925388098 CEST49907443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.925395012 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.951209068 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.951284885 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.951383114 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.951402903 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.951467037 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.951775074 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.951796055 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.951816082 CEST49904443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.951822996 CEST4434990413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.954880953 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.954965115 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.955240011 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.955240965 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.955369949 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.967241049 CEST4434990313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.967603922 CEST4434990313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.967742920 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.967742920 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.967744112 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.969583988 CEST49909443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.969666004 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.969755888 CEST49909443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.969870090 CEST49909443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.969897985 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.975881100 CEST4434990513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.976027012 CEST4434990513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.976111889 CEST49905443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.976113081 CEST49905443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.976170063 CEST49905443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.976195097 CEST4434990513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.978775978 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.978805065 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.978890896 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.979001999 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.979028940 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.987468958 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.987637997 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.987720966 CEST49906443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.987787008 CEST49906443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.987787008 CEST49906443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.987818956 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.987852097 CEST4434990613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.989962101 CEST49911443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.990046024 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:17.990156889 CEST49911443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.990297079 CEST49911443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:17.990335941 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.022608995 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.022770882 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.022842884 CEST49907443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.022881031 CEST49907443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.022881031 CEST49907443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.022898912 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.022912025 CEST4434990713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.024739981 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.024825096 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.024915934 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.025037050 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.025070906 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.280082941 CEST49903443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.280143976 CEST4434990313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.600174904 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.600878954 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.600939035 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.601438999 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.601491928 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.608762026 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.609652996 CEST49909443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.609695911 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.610084057 CEST49909443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.610096931 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.620904922 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.651484013 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.662743092 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.662780046 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.663428068 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.663436890 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.664160013 CEST49911443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.664218903 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.664563894 CEST49911443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.664617062 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.676682949 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.677795887 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.677836895 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.678390026 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.678404093 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.700643063 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.700740099 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.700850010 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.700931072 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.700931072 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.701020002 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.701020002 CEST49908443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.701061010 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.701092005 CEST4434990813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.706752062 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.706918001 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.706981897 CEST49909443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.711543083 CEST49909443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.711580038 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.711607933 CEST49909443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.711637974 CEST4434990913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.717365026 CEST49913443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.717452049 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.717689037 CEST49913443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.720411062 CEST49913443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.720462084 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.730561972 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.730679035 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.730757952 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.730891943 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.730937958 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.758775949 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.758862972 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.758917093 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.758935928 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.759147882 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.759202003 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.761454105 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.761454105 CEST49910443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.761471987 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.761492014 CEST4434991013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.776701927 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.776771069 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.776835918 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.776859045 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.776930094 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.776979923 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.777268887 CEST49915443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.777312994 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.777376890 CEST49915443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.780265093 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.780266047 CEST49912443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.780289888 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.780313015 CEST4434991213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.789302111 CEST49915443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.789328098 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.806387901 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.806423903 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.806495905 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.806651115 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.806668997 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.809689045 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.810302019 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.810379982 CEST49911443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.813769102 CEST49911443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.813807964 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.813841105 CEST49911443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.813855886 CEST4434991113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.824119091 CEST49917443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.824201107 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:18.824285030 CEST49917443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.824390888 CEST49917443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:18.824435949 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.316293001 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.317117929 CEST49913443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.317181110 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.317606926 CEST49913443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.317661047 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.405517101 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.405895948 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.405925989 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.406342983 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.406351089 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.418479919 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.418628931 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.418699980 CEST49913443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.418771982 CEST49913443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.418771982 CEST49913443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.418802977 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.418826103 CEST4434991313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.422184944 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.422267914 CEST4434991813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.422360897 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.422487020 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.422508001 CEST4434991813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.488898993 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.489233017 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.489257097 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.489617109 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.489624977 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.500227928 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.501187086 CEST49917443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.501243114 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.501547098 CEST49917443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.501562119 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.502964020 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.503262043 CEST49915443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.503292084 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.503789902 CEST49915443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.503799915 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.509310961 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.509612083 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.509660959 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.509691954 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.509716988 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.509763002 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.509793043 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.509807110 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.509821892 CEST49914443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.509829044 CEST4434991413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.512423992 CEST49919443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.512454033 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.512514114 CEST49919443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.512618065 CEST49919443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.512625933 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.586432934 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.586498976 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.586555958 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.586575985 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.586602926 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.586651087 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.586791039 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.586808920 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.586822033 CEST49916443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.586827993 CEST4434991613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.589623928 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.589709044 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.589994907 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.589996099 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.590127945 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.599905968 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.600049973 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.600140095 CEST49917443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.600219011 CEST49917443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.600219011 CEST49917443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.600259066 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.600287914 CEST4434991713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.601989985 CEST49921443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.602040052 CEST4434992113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.602137089 CEST49921443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.602226973 CEST49921443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.602241993 CEST4434992113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.608539104 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.608686924 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.608748913 CEST49915443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.608800888 CEST49915443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.608800888 CEST49915443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.608820915 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.608839989 CEST4434991513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.610507011 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.610527039 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:19.610610008 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.610708952 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:19.610730886 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.079236031 CEST4434991813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.079768896 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.079849005 CEST4434991813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.080250025 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.080265045 CEST4434991813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.153207064 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.153564930 CEST49919443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.153583050 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.154005051 CEST49919443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.154011011 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.179260969 CEST4434991813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.179423094 CEST4434991813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.179719925 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.179719925 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.179721117 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.182384968 CEST49923443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.182507038 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.182605028 CEST49923443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.182756901 CEST49923443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.182810068 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.243815899 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.244447947 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.244530916 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.244899988 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.244915009 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.260772943 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.261198997 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.261276960 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.261476040 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.261492968 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.265060902 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.265192032 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.265284061 CEST49919443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.265311003 CEST49919443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.265326023 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.265333891 CEST49919443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.265338898 CEST4434991913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.265675068 CEST4434992113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.267879963 CEST49921443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.267908096 CEST4434992113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.267940044 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.268023014 CEST4434992413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.268105984 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.268205881 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.268208027 CEST49921443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.268218040 CEST4434992113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.268237114 CEST4434992413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.358161926 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.358311892 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.358390093 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.358407974 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.358473063 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.358525991 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.358525991 CEST49922443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.358567953 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.358596087 CEST4434992213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.360421896 CEST49925443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.360439062 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.360513926 CEST49925443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.360636950 CEST49925443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.360646963 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.366389990 CEST4434992113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.366750002 CEST4434992113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.366828918 CEST49921443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.366828918 CEST49921443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.366867065 CEST49921443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.366878033 CEST4434992113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.368558884 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.368566990 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.368633032 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.368736982 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.368743896 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.449111938 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.449210882 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.449325085 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.449404955 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.449404955 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.449531078 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.449532032 CEST49920443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.449572086 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.449603081 CEST4434992013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.451528072 CEST49927443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.451610088 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.452259064 CEST49927443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.452699900 CEST49927443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.452733994 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.483076096 CEST49918443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.483138084 CEST4434991813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.837893009 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.838618994 CEST49923443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.838679075 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.839003086 CEST49923443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.839020967 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.938246965 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.938538074 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.938630104 CEST49923443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.938710928 CEST49923443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.938710928 CEST49923443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.938751936 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.938780069 CEST4434992313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.941611052 CEST49928443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.941709995 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.941792965 CEST49928443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.941939116 CEST49928443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.941958904 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.945681095 CEST4434992413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.946252108 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.946336031 CEST4434992413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:20.946574926 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:20.946589947 CEST4434992413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.042268038 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.042752981 CEST49925443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.042767048 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.043181896 CEST49925443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.043186903 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.049896002 CEST4434992413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.050224066 CEST4434992413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.050415039 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.050415039 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.050415039 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.052962065 CEST49929443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.053018093 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.053226948 CEST49929443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.053273916 CEST49929443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.053287983 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.090293884 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.105403900 CEST49927443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.105482101 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.105732918 CEST49927443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.105747938 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.144999981 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.145148039 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.145309925 CEST49925443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.186642885 CEST49925443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.186642885 CEST49925443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.186678886 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.186691999 CEST4434992513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.201647043 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.201805115 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.201984882 CEST49927443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.232346058 CEST49927443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.232346058 CEST49927443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.232409954 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.232441902 CEST4434992713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.356204987 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.356214046 CEST49931443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.356236935 CEST4434993013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.356300116 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.356319904 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.356389999 CEST49931443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.356442928 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.356453896 CEST4434993013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.356529951 CEST49931443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.356551886 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.359241962 CEST49924443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.359271049 CEST4434992413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.577510118 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.578212023 CEST49928443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.578286886 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.578672886 CEST49928443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.578685999 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.674988031 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.675158978 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.675219059 CEST49928443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.675251007 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.675324917 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.675405025 CEST49928443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.675554991 CEST49928443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.675585985 CEST4434992813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.693137884 CEST49932443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.693249941 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.693320990 CEST49932443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.693623066 CEST49932443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.693655014 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.718952894 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.719403982 CEST49929443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.719439030 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.719844103 CEST49929443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.719852924 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.820682049 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.820904970 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.821011066 CEST49929443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.823359013 CEST49929443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.823359013 CEST49929443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.823400021 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.823414087 CEST4434992913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.823514938 CEST49934443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.823596001 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.823677063 CEST49934443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.823803902 CEST49934443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:21.823858023 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:21.998481989 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.001672029 CEST49931443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.001749039 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.002042055 CEST4434993013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.002110004 CEST49931443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.002125978 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.002427101 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.002454996 CEST4434993013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.002859116 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.002865076 CEST4434993013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.096920013 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.097074986 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.097166061 CEST49931443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.097244024 CEST49931443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.097280025 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.097326994 CEST49931443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.097342968 CEST4434993113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.099852085 CEST49935443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.099946022 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.100020885 CEST49935443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.100162983 CEST49935443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.100195885 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.100466967 CEST4434993013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.100768089 CEST4434993013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.100924969 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.100924969 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.100924969 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.102705956 CEST49936443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.102752924 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.102816105 CEST49936443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.102943897 CEST49936443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.102961063 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.329476118 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.329921961 CEST49932443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.329978943 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.330344915 CEST49932443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.330358028 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.404246092 CEST49930443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.404269934 CEST4434993013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.428113937 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.428307056 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.428381920 CEST49932443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.428462029 CEST49932443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.428498030 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.428524017 CEST49932443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.428539038 CEST4434993213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.431283951 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.431366920 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.431478977 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.431628942 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.431689024 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.476725101 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.477401018 CEST49934443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.477461100 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.477807999 CEST49934443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.477861881 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.578005075 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.578071117 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.578157902 CEST49934443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.578496933 CEST49934443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.578496933 CEST49934443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.578563929 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.578602076 CEST4434993413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.585222006 CEST49938443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.585304022 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.585382938 CEST49938443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.585525036 CEST49938443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.585568905 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.740801096 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.741291046 CEST49935443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.741327047 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.741656065 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.741754055 CEST49935443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.741769075 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.742085934 CEST49936443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.742100954 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.742508888 CEST49936443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.742516041 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.839262009 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.839504957 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.839520931 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.839585066 CEST49935443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.839627028 CEST49935443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.839627028 CEST49935443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.839652061 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.839673996 CEST4434993513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.840224028 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.840452909 CEST49936443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.840476990 CEST49936443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.840497017 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.840508938 CEST49936443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.840517044 CEST4434993613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.842730045 CEST49939443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.842761993 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.842825890 CEST49939443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.842808008 CEST49940443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.842907906 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.842976093 CEST49940443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.843036890 CEST49939443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.843053102 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:22.843127012 CEST49940443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:22.843163013 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.087650061 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.088455915 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.088546991 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.088582039 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.088597059 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.188114882 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.188271046 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.188369989 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.188554049 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.188554049 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.188554049 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.191451073 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.191535950 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.191853046 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.191853046 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.191987038 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.222805023 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.223366976 CEST49938443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.223478079 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.223737955 CEST49938443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.223754883 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.321075916 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.321217060 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.321424961 CEST49938443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.321507931 CEST49938443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.321507931 CEST49938443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.321578979 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.321611881 CEST4434993813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.323749065 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.323832989 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.327117920 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.327543974 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.327599049 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.478943110 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.480159998 CEST49940443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.480240107 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.480568886 CEST49940443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.480587959 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.482917070 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.489053965 CEST49937443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.489113092 CEST4434993713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.490772963 CEST49939443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.490797997 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.491251945 CEST49939443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.491259098 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.569014072 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:23.569094896 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:23.569308043 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:23.569402933 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:23.569427967 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:23.577441931 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.577615976 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.577713966 CEST49940443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.577948093 CEST49940443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.577948093 CEST49940443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.577986002 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.578008890 CEST4434994013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.580785036 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.580868006 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.581016064 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.581161976 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.581197023 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.586601019 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.586743116 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.586868048 CEST49939443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.587002039 CEST49939443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.587018967 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.587030888 CEST49939443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.587038040 CEST4434993913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.588897943 CEST49945443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.588952065 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.589061975 CEST49945443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.589160919 CEST49945443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.589179993 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.837718964 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.838846922 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.838924885 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.839710951 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.839725018 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.935997963 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.936006069 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.936064959 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.936094999 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.936127901 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.936189890 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.936672926 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.936672926 CEST49941443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.936702967 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.936722994 CEST4434994113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.939946890 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.939999104 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.940073013 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.940227985 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.940249920 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.963665009 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.964097023 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.964114904 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.964628935 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.964638948 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.995261908 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.995619059 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.995630026 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:23.996093035 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:23.996098042 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.062263012 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.062397957 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.062454939 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.062473059 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.062560081 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.062587023 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.062587023 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.062612057 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.062660933 CEST49942443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.062674046 CEST4434994213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.065028906 CEST49947443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.065112114 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.065181017 CEST49947443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.065289021 CEST49947443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.065320015 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.093943119 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.094011068 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.094059944 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.094069004 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.094099045 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.094141960 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.094191074 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.094204903 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.094216108 CEST49926443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.094222069 CEST4434992613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.096281052 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.096306086 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.096365929 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.096482038 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.096496105 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.199091911 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:24.199630022 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:24.199692965 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:24.200220108 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:24.200526953 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:24.200619936 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:24.200696945 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:24.200696945 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:24.200748920 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:24.249413967 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.250320911 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.250391960 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.250654936 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.250669003 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.275971889 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.276385069 CEST49945443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.276463032 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.276628017 CEST49945443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.276642084 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.352591991 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.352664948 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.352767944 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.352818012 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.352818966 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.353110075 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.353110075 CEST49944443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.353174925 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.353209972 CEST4434994413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.355742931 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.355834007 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.355926991 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.356082916 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.356106997 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.381737947 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.382497072 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.382574081 CEST49945443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.382623911 CEST49945443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.382625103 CEST49945443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.382659912 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.382684946 CEST4434994513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.384712934 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.384737968 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.384874105 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.384983063 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.385006905 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.498570919 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:24.499090910 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:24.499159098 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:24.499234915 CEST49943443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:24.499270916 CEST44349943142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:24.592034101 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.592524052 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.592567921 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.593007088 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.593019009 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.695142031 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.695199013 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.695256948 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.695287943 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.695318937 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.695373058 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.695549965 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.695549965 CEST49946443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.695573092 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.695594072 CEST4434994613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.698431969 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.698460102 CEST4434995113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.698524952 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.698697090 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.698710918 CEST4434995113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.704623938 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.704973936 CEST49947443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.705032110 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.705379009 CEST49947443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.705394030 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.745452881 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.745769024 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.745788097 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.746134043 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.746138096 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.807044029 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.807189941 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.807245970 CEST49947443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.807277918 CEST49947443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.807293892 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.807306051 CEST49947443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.807312012 CEST4434994713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.809874058 CEST49952443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.809890032 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.809961081 CEST49952443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.810089111 CEST49952443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.810101032 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.844552994 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.844613075 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.844708920 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.844724894 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.844768047 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.844825029 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.844863892 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.844876051 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.844885111 CEST49948443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.844888926 CEST4434994813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.847240925 CEST49953443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.847290993 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.847539902 CEST49953443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.847706079 CEST49953443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.847722054 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.996324062 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.996731043 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.996809959 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:24.997085094 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:24.997101068 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.037568092 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.038702011 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.038718939 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.039092064 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.039102077 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.053133011 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:25.053329945 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:25.053395987 CEST49887443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:52:25.096250057 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.096316099 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.096400023 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.096414089 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.096504927 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.096504927 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.096549034 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.096576929 CEST49949443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.096591949 CEST4434994913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.098337889 CEST49954443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.098391056 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.098489046 CEST49954443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.098572969 CEST49954443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.098599911 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.137636900 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.137712955 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.137825966 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.137871027 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.137914896 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.137975931 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.137999058 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.138021946 CEST49950443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.138035059 CEST4434995013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.143475056 CEST49955443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.143496990 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.143636942 CEST49955443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.147429943 CEST49955443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.147464037 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.352518082 CEST4434995113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.353066921 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.353094101 CEST4434995113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.353521109 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.353526115 CEST4434995113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.452491999 CEST4434995113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.452754021 CEST4434995113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.452915907 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.452915907 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.452915907 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.454102993 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.454615116 CEST49952443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.454644918 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.454931974 CEST49952443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.454937935 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.456007004 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.456090927 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.456202984 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.456392050 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.456429005 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.485603094 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.487907887 CEST49953443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.487938881 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.488284111 CEST49953443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.488296986 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.551726103 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.552474022 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.552561045 CEST49952443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.552787066 CEST49952443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.552795887 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.552824974 CEST49952443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.552829027 CEST4434995213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.555531979 CEST49957443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.555623055 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.559654951 CEST49957443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.559777021 CEST49957443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.559798956 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.584148884 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.584297895 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.584379911 CEST49953443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.584534883 CEST49953443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.584534883 CEST49953443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.584561110 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.584583044 CEST4434995313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.586380959 CEST49958443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.586405993 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.586489916 CEST49958443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.586610079 CEST49958443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.586632967 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.743455887 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.743823051 CEST49954443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.743843079 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.744251013 CEST49954443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.744261026 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.764389992 CEST49951443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.764405012 CEST4434995113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.823442936 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.823816061 CEST49955443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.823827028 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.824273109 CEST49955443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.824276924 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.862564087 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.862926006 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.863037109 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.863104105 CEST49954443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.863171101 CEST49954443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.863171101 CEST49954443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.863199949 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.863221884 CEST4434995413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.865906000 CEST49959443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.865989923 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.866086006 CEST49959443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.866208076 CEST49959443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.866233110 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.924968958 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.925188065 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.925569057 CEST49955443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.925600052 CEST49955443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.925611973 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.925622940 CEST49955443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.925626993 CEST4434995513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.927438021 CEST49960443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.927527905 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:25.927638054 CEST49960443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.927737951 CEST49960443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:25.927767992 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.154282093 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.156208038 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.156267881 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.156687975 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.156742096 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.214370966 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.215034962 CEST49957443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.215073109 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.215369940 CEST49957443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.215404987 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.233867884 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.234216928 CEST49958443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.234251976 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.234611988 CEST49958443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.234627008 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.256537914 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.256665945 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.256751060 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.256774902 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.256864071 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.257077932 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.257077932 CEST49956443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.257126093 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.257153988 CEST4434995613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.259902954 CEST49961443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.259988070 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.260082006 CEST49961443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.260246038 CEST49961443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.260270119 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.312834978 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.313189030 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.313261032 CEST49957443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.313352108 CEST49957443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.313352108 CEST49957443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.313395023 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.313420057 CEST4434995713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.315356016 CEST49962443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.315455914 CEST4434996213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.315538883 CEST49962443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.315689087 CEST49962443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.315727949 CEST4434996213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.365556955 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.365582943 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.365621090 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.365675926 CEST49958443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.365792990 CEST49958443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.365793943 CEST49958443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.365809917 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.365830898 CEST4434995813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.367767096 CEST49963443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.367835999 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.367929935 CEST49963443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.368051052 CEST49963443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.368087053 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.374663115 CEST49887443192.168.2.4142.250.184.228
                        Oct 7, 2024 02:52:26.374726057 CEST44349887142.250.184.228192.168.2.4
                        Oct 7, 2024 02:52:26.374871016 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:26.374939919 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:26.375061035 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:26.375293970 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:26.375329971 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:26.510430098 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.510843992 CEST49959443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.510917902 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.511257887 CEST49959443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.511271954 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.570529938 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.571983099 CEST49960443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.572062969 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.572431087 CEST49960443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.572446108 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.611828089 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.612047911 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.612140894 CEST49959443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.612319946 CEST49959443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.612358093 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.612406969 CEST49959443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.612421989 CEST4434995913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.614826918 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.614912987 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.615650892 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.615765095 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.615786076 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.669574976 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.669728994 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.669817924 CEST49960443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.670022011 CEST49960443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.670022011 CEST49960443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.670067072 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.670094967 CEST4434996013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.672892094 CEST49966443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.672974110 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.673100948 CEST49966443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.673201084 CEST49966443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.673226118 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.912218094 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.912682056 CEST49961443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.912729025 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.913101912 CEST49961443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.913115978 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.990654945 CEST4434996213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.991030931 CEST49962443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.991055965 CEST4434996213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:26.991430044 CEST49962443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:26.991441011 CEST4434996213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.012780905 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.013021946 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.013096094 CEST49961443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.013143063 CEST49961443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.013144016 CEST49961443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.013171911 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.013192892 CEST4434996113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.015377045 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.015697002 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.015731096 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.015790939 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.015808105 CEST49963443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.015866995 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.015948057 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.015960932 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.016041994 CEST49963443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.016057014 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.023461103 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:27.023740053 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:27.023782015 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:27.024630070 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:27.024920940 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:27.025073051 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:27.025089979 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:27.025114059 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:27.025166988 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:27.076066017 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:27.302503109 CEST4434996213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.302563906 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.302701950 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.302706003 CEST4434996213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.302807093 CEST49963443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.302926064 CEST49963443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.302932024 CEST49962443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.302932024 CEST49962443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.302967072 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.303006887 CEST49963443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.303021908 CEST4434996313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.303021908 CEST49962443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.303050995 CEST4434996213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.305886984 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.305938959 CEST49969443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.305978060 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.306021929 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.306071997 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.306086063 CEST49969443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.306229115 CEST49969443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.306253910 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.306297064 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.306328058 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.323719025 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:27.324057102 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:27.324126005 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:27.324270010 CEST49964443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:27.324301004 CEST44349964142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:27.495043993 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.495491982 CEST49966443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.495553017 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.495944023 CEST49966443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.495958090 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.502604961 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.502975941 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.503015995 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.503235102 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.503246069 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.595077038 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.595323086 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.595400095 CEST49966443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.595433950 CEST49966443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.595448971 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.595464945 CEST49966443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.595472097 CEST4434996613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.598169088 CEST49970443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.598252058 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.598365068 CEST49970443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.598494053 CEST49970443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.598515987 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.606455088 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.606554985 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.606606960 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.606617928 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.606662989 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.606707096 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.606719971 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.606733084 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.606733084 CEST49965443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.606739998 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.606749058 CEST4434996513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.609139919 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.609236956 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.609316111 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.609467030 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.609498978 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.661170006 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.661709070 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.661747932 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.662050009 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.662056923 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.759838104 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.760272026 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.760320902 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.760329962 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.760377884 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.760437965 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.760437965 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.760437965 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.760468006 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.762723923 CEST49972443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.762789965 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.762868881 CEST49972443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.763031006 CEST49972443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.763056040 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.946716070 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.948051929 CEST49969443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.948117971 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.948607922 CEST49969443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.948622942 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.972973108 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.975029945 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.975076914 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:27.975455046 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:27.975467920 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.045330048 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.045483112 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.045619011 CEST49969443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.045998096 CEST49969443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.045998096 CEST49969443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.046039104 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.046065092 CEST4434996913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.048463106 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.048491001 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.048594952 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.048708916 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.048717976 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.060158014 CEST49967443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.060185909 CEST4434996713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.075159073 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.075227022 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.075324059 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.075330973 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.076427937 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.120851040 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.120851994 CEST49968443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.120908022 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.120939970 CEST4434996813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.126312971 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.126322031 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.126416922 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.126694918 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.126707077 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.253123999 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.254582882 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.294538975 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.306189060 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.306216002 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.306763887 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.306776047 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.307045937 CEST49970443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.307118893 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.307374001 CEST49970443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.307404041 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.402113914 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.402187109 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.402295113 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.402323961 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.402358055 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.402456045 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.402483940 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.402507067 CEST49971443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.402519941 CEST4434997113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.405004025 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.405893087 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.405961037 CEST49970443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.407305956 CEST49970443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.407305956 CEST49970443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.407352924 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.407397985 CEST4434997013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.410037994 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.410120964 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.410242081 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.410768986 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.410801888 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.411533117 CEST49976443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.411616087 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.411705017 CEST49976443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.411866903 CEST49976443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.411901951 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.420260906 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.420852900 CEST49972443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.420871019 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.421274900 CEST49972443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.421284914 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.520147085 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.520319939 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.520418882 CEST49972443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.520693064 CEST49972443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.520693064 CEST49972443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.520720005 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.520742893 CEST4434997213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.522792101 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.522825003 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.522891045 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.523008108 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.523021936 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.686585903 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.687115908 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.687155008 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.687681913 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.687690020 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.785648108 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.785690069 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.785794973 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.785825014 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.785944939 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.785972118 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.785972118 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.785995960 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.786011934 CEST49973443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.786019087 CEST4434997313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.788856030 CEST49978443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.788885117 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.788947105 CEST49978443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.789074898 CEST49978443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.789086103 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.805536985 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.805881977 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.805901051 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.806274891 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.806282043 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.910152912 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.910218000 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.910376072 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.910507917 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.910507917 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.910895109 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.910896063 CEST49974443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.910943031 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.910959005 CEST4434997413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.913311005 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.913394928 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:28.913511992 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.913633108 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:28.913657904 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.046612978 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.047049999 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.047081947 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.047463894 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.047494888 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.087727070 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.088485956 CEST49976443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.088567019 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.088646889 CEST49976443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.088661909 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.144550085 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.144730091 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.144813061 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.144850969 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.144881964 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.144958019 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.144958019 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.144999981 CEST49975443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.145024061 CEST4434997513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.147556067 CEST49980443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.147614002 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.147777081 CEST49980443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.147871017 CEST49980443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.147887945 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.161478043 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.161767960 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.161787033 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.162120104 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.162126064 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.190970898 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.191107988 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.191194057 CEST49976443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.191272020 CEST49976443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.191272974 CEST49976443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.191314936 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.191340923 CEST4434997613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.193059921 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.193149090 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.193233967 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.193337917 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.193361998 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.259681940 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.259834051 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.259881973 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.259885073 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.259936094 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.260020018 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.260051012 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.260088921 CEST49977443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.260094881 CEST4434997713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.261836052 CEST49982443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.261871099 CEST4434998213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.261957884 CEST49982443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.262053013 CEST49982443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.262072086 CEST4434998213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.429908037 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.430439949 CEST49978443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.430463076 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.430942059 CEST49978443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.430948019 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.527911901 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.528110981 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.528194904 CEST49978443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.528280020 CEST49978443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.528296947 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.528311014 CEST49978443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.528317928 CEST4434997813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.532073975 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.532160997 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.532443047 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.532443047 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.532576084 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.557861090 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.558317900 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.558403015 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.558697939 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.558715105 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.659379959 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.659504890 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.659573078 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.659636021 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.659679890 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.659738064 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.659738064 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.659784079 CEST49979443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.659811020 CEST4434997913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.662439108 CEST49984443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.662523031 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.662616968 CEST49984443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.662899017 CEST49984443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.662978888 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.814855099 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.815475941 CEST49980443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.815519094 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.815943003 CEST49980443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.815953970 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.845278025 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.846153021 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.846246004 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.846282005 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.846297026 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.909847021 CEST4434998213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.910590887 CEST49982443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.910677910 CEST4434998213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.910749912 CEST49982443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.910767078 CEST4434998213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.918459892 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.918658018 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.918751001 CEST49980443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.918960094 CEST49980443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.918960094 CEST49980443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.918989897 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.919034958 CEST4434998013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.921637058 CEST49985443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.921685934 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.921765089 CEST49985443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.921905994 CEST49985443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.921916962 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.946907997 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.947026968 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.947132111 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.947303057 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.947304010 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.947484016 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.947484016 CEST49981443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.947525978 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.947556973 CEST4434998113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.949412107 CEST49986443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.949450970 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:29.949517965 CEST49986443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.949639082 CEST49986443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:29.949662924 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.010348082 CEST4434998213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.010622978 CEST4434998213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.010735035 CEST49982443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.010735035 CEST49982443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.010842085 CEST49982443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.010880947 CEST4434998213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.012933016 CEST49987443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.013015985 CEST4434998713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.013103008 CEST49987443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.013453960 CEST49987443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.013535976 CEST4434998713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.210833073 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.211322069 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.211435080 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.211842060 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.211926937 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.324248075 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.324604988 CEST49984443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.324683905 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.324982882 CEST49984443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.324996948 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.325444937 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.325504065 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.325573921 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.325598955 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.325671911 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.325673103 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.325793982 CEST49983443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.325833082 CEST4434998313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.329562902 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.329612017 CEST4434998813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.329693079 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.329843044 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.329863071 CEST4434998813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.424618959 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.424778938 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.424844027 CEST49984443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.424988985 CEST49984443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.424988985 CEST49984443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.425033092 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.425059080 CEST4434998413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.427563906 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.427658081 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.427746058 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.427876949 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.427900076 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.566004992 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.566507101 CEST49985443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.566526890 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.566992044 CEST49985443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.566998959 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.596359968 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.634109020 CEST49986443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.634129047 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.634758949 CEST49986443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.634764910 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.666599035 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.666743040 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.666826963 CEST49985443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.667176962 CEST49985443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.667197943 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.667234898 CEST49985443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.667243004 CEST4434998513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.698906898 CEST49990443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.698966980 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.699047089 CEST49990443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.702207088 CEST49990443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.702254057 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.708733082 CEST4434998713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.712160110 CEST49987443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.712220907 CEST4434998713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.712641954 CEST49987443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.712693930 CEST4434998713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.730437040 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.730508089 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.730608940 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.730779886 CEST49986443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.730961084 CEST49986443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.730984926 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.730997086 CEST49986443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.731004000 CEST4434998613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.760994911 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.761082888 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.761185884 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.771080971 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.771157980 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.814524889 CEST4434998713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.814694881 CEST4434998713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.814874887 CEST49987443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.814874887 CEST49987443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.814956903 CEST49987443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.814994097 CEST4434998713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.823074102 CEST49992443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.823143959 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.823232889 CEST49992443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.823546886 CEST49992443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.823575020 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.972193956 CEST4434998813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.972796917 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.972877026 CEST4434998813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:30.973309040 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:30.973361015 CEST4434998813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.070698023 CEST4434998813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.071193933 CEST4434998813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.071708918 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.071708918 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.071708918 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.074026108 CEST49993443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.074114084 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.074366093 CEST49993443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.074366093 CEST49993443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.074496031 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.094410896 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.094966888 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.095026016 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.095237970 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.095251083 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.199949980 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.200012922 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.200114012 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.200160980 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.200325966 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.200752974 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.200753927 CEST49989443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.200846910 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.200882912 CEST4434998913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.203777075 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.203861952 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.203969955 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.204099894 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.204124928 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.348535061 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.349050999 CEST49990443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.349109888 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.349386930 CEST49990443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.349401951 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.373378038 CEST49988443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.373439074 CEST4434998813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.435132027 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.437305927 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.437366009 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.437766075 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.437818050 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.447786093 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.447937012 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.448008060 CEST49990443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.448064089 CEST49990443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.448064089 CEST49990443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.448097944 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.448124886 CEST4434999013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.450666904 CEST49995443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.450768948 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.450859070 CEST49995443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.450953960 CEST49995443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.450973988 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.503619909 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.505104065 CEST49992443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.505162954 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.505568981 CEST49992443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.505582094 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.538604021 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.538642883 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.538691998 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.538826942 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.538826942 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.538955927 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.538957119 CEST49991443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.538996935 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.539025068 CEST4434999113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.541470051 CEST49996443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.541521072 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.541594982 CEST49996443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.541709900 CEST49996443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.541728973 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.602858067 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.603003025 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.603075027 CEST49992443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.603121996 CEST49992443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.603121996 CEST49992443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.603149891 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.603172064 CEST4434999213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.605057955 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.605099916 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.605313063 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.605313063 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.605377913 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.766628027 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.766995907 CEST49993443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.767029047 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.767412901 CEST49993443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.767421007 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.869014978 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.869204044 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.869283915 CEST49993443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.869635105 CEST49993443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.869635105 CEST49993443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.869702101 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.869739056 CEST4434999313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.869935036 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.870320082 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.870347023 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.870769024 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.870781898 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.872319937 CEST49998443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.872359991 CEST4434999813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.872426987 CEST49998443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.872524023 CEST49998443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.872533083 CEST4434999813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.970202923 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.970779896 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.970920086 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.970983982 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.970983982 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.971072912 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.971072912 CEST49994443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.971115112 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.971178055 CEST4434999413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.973001003 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.973052025 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:31.973124027 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.973252058 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:31.973263025 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.137080908 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.137746096 CEST49995443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.137831926 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.138078928 CEST49995443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.138093948 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.176781893 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.177236080 CEST49996443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.177275896 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.177689075 CEST49996443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.177695036 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.238275051 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.238421917 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.238497019 CEST49995443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.238636017 CEST49995443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.238698006 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.238732100 CEST49995443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.238748074 CEST4434999513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.241360903 CEST50000443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.241451025 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.241543055 CEST50000443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.241673946 CEST50000443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.241712093 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.253843069 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.254432917 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.254476070 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.254774094 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.254801035 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.277193069 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.277257919 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.277365923 CEST49996443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.277637959 CEST49996443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.277657986 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.277672052 CEST49996443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.277678013 CEST4434999613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.279676914 CEST50001443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.279761076 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.279860020 CEST50001443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.279975891 CEST50001443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.280004025 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.353080034 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.353144884 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.353249073 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.353307009 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.353307009 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.353352070 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.353369951 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.353384972 CEST49997443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.353393078 CEST4434999713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.355309963 CEST50002443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.355422020 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.355711937 CEST50002443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.355711937 CEST50002443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.355868101 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.543970108 CEST4434999813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.544471979 CEST49998443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.544502974 CEST4434999813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.545191050 CEST49998443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.545217037 CEST4434999813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.614161968 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.614506006 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.614543915 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.614831924 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.614837885 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.646575928 CEST4434999813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.646724939 CEST4434999813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.646781921 CEST49998443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.646821976 CEST49998443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.646836042 CEST4434999813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.649703979 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.649813890 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.649888039 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.650001049 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.650029898 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.712637901 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.712795019 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.712841988 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.712855101 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.712893963 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.712925911 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.712949038 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.712963104 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.712963104 CEST49999443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.712971926 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.712980032 CEST4434999913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.715070009 CEST50004443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.715105057 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.715174913 CEST50004443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.715307951 CEST50004443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.715322971 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.894848108 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.899209976 CEST50000443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.899266005 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.899638891 CEST50000443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.899651051 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.927776098 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.928412914 CEST50001443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.928493977 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.928872108 CEST50001443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:32.928925991 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.996890068 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.997049093 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:32.997127056 CEST50000443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.011028051 CEST50000443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.011084080 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.011117935 CEST50000443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.011135101 CEST4435000013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.011938095 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.015328884 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.015443087 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.015742064 CEST50002443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.015768051 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.015824080 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.016160011 CEST50002443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.016212940 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.016267061 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.016307116 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.031084061 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.031152964 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.031280041 CEST50001443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.032082081 CEST50001443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.032083035 CEST50001443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.032149076 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.032186031 CEST4435000113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.037210941 CEST50006443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.037292957 CEST4435000613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.037399054 CEST50006443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.037619114 CEST50006443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.037657022 CEST4435000613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.112592936 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.112787962 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.113038063 CEST50002443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.118844032 CEST50002443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.118906021 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.118968964 CEST50002443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.118988037 CEST4435000213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.162623882 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.162668943 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.162744999 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.165987015 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.166002035 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.307336092 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.307804108 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.307879925 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.308295012 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.308309078 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.391861916 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.392549038 CEST50004443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.392587900 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.393079042 CEST50004443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.393085957 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.409286976 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.409356117 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.409465075 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.409591913 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.409591913 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.409826040 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.409826040 CEST50003443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.409869909 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.409899950 CEST4435000313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.412578106 CEST50008443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.412620068 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.412898064 CEST50008443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.412898064 CEST50008443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.412961960 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.495656013 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.495803118 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.495907068 CEST50004443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.497904062 CEST50004443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.497904062 CEST50004443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.497914076 CEST50009443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.497925043 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.497940063 CEST4435000413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.497956991 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.498030901 CEST50009443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.498130083 CEST50009443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.498137951 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.657805920 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.658891916 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.658972979 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.659239054 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.659291983 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.714838982 CEST4435000613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.715506077 CEST50006443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.715583086 CEST4435000613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.716020107 CEST50006443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.716072083 CEST4435000613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.756979942 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.757055044 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.757153988 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.757232904 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.757234097 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.757319927 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.757319927 CEST50005443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.757359982 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.757390022 CEST4435000513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.759980917 CEST50010443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.760031939 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.760097980 CEST50010443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.760206938 CEST50010443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.760215044 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.806238890 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.806570053 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.806586981 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.806956053 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.806962013 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.819344997 CEST4435000613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.819531918 CEST4435000613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.819700956 CEST50006443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.819701910 CEST50006443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.821657896 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.821696997 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.821778059 CEST50006443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.821813107 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.821837902 CEST4435000613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.822001934 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.822010994 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.904838085 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.904906034 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.904948950 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.904958963 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.905005932 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.905025959 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.905047894 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.905062914 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.905064106 CEST50007443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.905076027 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.905085087 CEST4435000713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.906667948 CEST50012443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.906737089 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:33.906809092 CEST50012443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.906917095 CEST50012443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:33.906934023 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.050961018 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.051403046 CEST50008443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.051430941 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.051915884 CEST50008443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.051923037 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.138319016 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.138871908 CEST50009443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.138930082 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.139199972 CEST50009443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.139213085 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.148742914 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.148968935 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.149039030 CEST50008443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.149355888 CEST50008443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.149355888 CEST50008443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.149388075 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.149408102 CEST4435000813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.151866913 CEST50013443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.151972055 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.152157068 CEST50013443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.152230024 CEST50013443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.152247906 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.238166094 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.238318920 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.238563061 CEST50009443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.238775969 CEST50009443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.238775969 CEST50009443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.238796949 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.238810062 CEST4435000913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.241183043 CEST50014443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.241266966 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.241657972 CEST50014443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.241657972 CEST50014443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.241771936 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.450778008 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.451349020 CEST50010443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.451379061 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.451751947 CEST50010443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.451759100 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.471220970 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.471641064 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.471668005 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.471980095 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.471986055 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.558486938 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.558630943 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.558691978 CEST50010443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.558739901 CEST50010443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.558739901 CEST50010443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.558762074 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.558773994 CEST4435001013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.560785055 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.562748909 CEST50015443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.562832117 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.562913895 CEST50015443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.563522100 CEST50012443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.563580036 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.564100981 CEST50015443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.564100981 CEST50012443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.564188957 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.564220905 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.572309971 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.572427034 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.572478056 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.572488070 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.572501898 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.572547913 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.572570086 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.572570086 CEST50011443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.572582006 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.572616100 CEST4435001113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.574599028 CEST50016443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.574681997 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.574788094 CEST50016443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.574929953 CEST50016443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.574956894 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.661847115 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.662012100 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.662194967 CEST50012443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.662292004 CEST50012443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.662292957 CEST50012443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.662333012 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.662363052 CEST4435001213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.664968014 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.665060997 CEST4435001713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.665149927 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.665307999 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.665327072 CEST4435001713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.793651104 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.794006109 CEST50013443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.794064045 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:34.794385910 CEST50013443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:34.794399023 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.063232899 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.063420057 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.063513041 CEST50013443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.063594103 CEST50013443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.063594103 CEST50013443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.063637018 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.063666105 CEST4435001313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.065968037 CEST50018443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.066015005 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.066097021 CEST50018443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.066236019 CEST50018443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.066261053 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.070396900 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.070799112 CEST50014443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.070831060 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.071213961 CEST50014443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.071224928 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.172657013 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.172837019 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.172900915 CEST50014443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.172971964 CEST50014443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.172971964 CEST50014443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.172992945 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.173012972 CEST4435001413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.175470114 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.175553083 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.175645113 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.175748110 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.175769091 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.253149986 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.253704071 CEST50016443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.253763914 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.254029989 CEST50016443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.254082918 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.255289078 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.255750895 CEST50015443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.255834103 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.255943060 CEST50015443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.255971909 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.307670116 CEST4435001713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.308221102 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.308263063 CEST4435001713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.308574915 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.308584929 CEST4435001713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.354231119 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.354599953 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.354800940 CEST50016443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.354885101 CEST50016443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.354885101 CEST50016443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.354926109 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.354958057 CEST4435001613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.355443954 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.355597019 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.355773926 CEST50015443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.356162071 CEST50015443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.356163025 CEST50015443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.356228113 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.356262922 CEST4435001513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.359908104 CEST50020443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.359949112 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.360143900 CEST50020443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.360821009 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.360877991 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.360940933 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.361438990 CEST50020443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.361465931 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.361536980 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.361553907 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.408304930 CEST4435001713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.408438921 CEST4435001713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.408617973 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.408618927 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.408618927 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.410434008 CEST50022443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.410453081 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.410510063 CEST50022443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.410645008 CEST50022443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.410659075 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.706139088 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.706773043 CEST50018443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.706820965 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.707258940 CEST50018443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.707268000 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.721467018 CEST50017443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.721489906 CEST4435001713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.806942940 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.807104111 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.807178974 CEST50018443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.807285070 CEST50018443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.807307005 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.807329893 CEST50018443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.807343006 CEST4435001813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.810079098 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.810111046 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.810189009 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.810337067 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.810353041 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.844959021 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.845627069 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.845712900 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.846007109 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.846061945 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.947097063 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.947201014 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.947299957 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.947479963 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.947479963 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.947566032 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.947566032 CEST50019443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.947607994 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.947642088 CEST4435001913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.949623108 CEST50024443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.949657917 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:35.949729919 CEST50024443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.949851990 CEST50024443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:35.949857950 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.002157927 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.002590895 CEST50020443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.002629995 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.002979994 CEST50020443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.003006935 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.015558004 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.015973091 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.016009092 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.016298056 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.016304970 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.063968897 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.064366102 CEST50022443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.064402103 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.064723015 CEST50022443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.064728975 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.101624966 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.101778030 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.101939917 CEST50020443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.102000952 CEST50020443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.102025032 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.102041006 CEST50020443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.102047920 CEST4435002013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.104603052 CEST50025443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.104686022 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.104795933 CEST50025443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.104929924 CEST50025443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.104955912 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.116925001 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.116956949 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.117005110 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.117018938 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.117055893 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.117187977 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.117208958 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.117238998 CEST50021443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.117247105 CEST4435002113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.119070053 CEST50026443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.119153023 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.119240999 CEST50026443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.119368076 CEST50026443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.119419098 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.164248943 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.164494991 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.164580107 CEST50022443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.164608955 CEST50022443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.164608955 CEST50022443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.164618015 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.164628029 CEST4435002213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.166387081 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.166425943 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.166491985 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.166595936 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.166610003 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.476978064 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.477786064 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.477826118 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.478287935 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.478315115 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.579026937 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.579097033 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.579195976 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.579231977 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.579253912 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.579447031 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.579462051 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.579472065 CEST50023443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.579477072 CEST4435002313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.581949949 CEST50028443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.582045078 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.582145929 CEST50028443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.582267046 CEST50028443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.582288980 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.604671001 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.605506897 CEST50024443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.605532885 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.605678082 CEST50024443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.605690956 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.706083059 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.706289053 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.706337929 CEST50024443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.706376076 CEST50024443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.706398010 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.706412077 CEST50024443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.706418991 CEST4435002413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.708487034 CEST50029443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.708571911 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.708664894 CEST50029443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.708790064 CEST50029443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.708811045 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.752700090 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.753559113 CEST50025443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.753640890 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.753998041 CEST50025443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.754050970 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.781246901 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.781614065 CEST50026443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.781672955 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.782037020 CEST50026443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.782051086 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.850049973 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.850332975 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.850351095 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.850692034 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.850697041 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.851667881 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.851819992 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.851885080 CEST50025443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.851948977 CEST50025443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.851983070 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.852009058 CEST50025443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.852022886 CEST4435002513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.854387999 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.854470968 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.854552031 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.854644060 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.854662895 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.881612062 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.881860971 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.881926060 CEST50026443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.881977081 CEST50026443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.881977081 CEST50026443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.882000923 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.882003069 CEST4435002613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.884263992 CEST50031443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.884355068 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.884429932 CEST50031443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.884562969 CEST50031443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.884584904 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.952867985 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.952960014 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.953003883 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.953016043 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.953053951 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.953097105 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.953119993 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.953134060 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.953134060 CEST50027443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.953141928 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.953150988 CEST4435002713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.954900026 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.954941034 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:36.955003023 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.955112934 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:36.955130100 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.222353935 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.223320961 CEST50028443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.223381042 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.223926067 CEST50028443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.223978996 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.300116062 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.300637007 CEST50029443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.300695896 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.300874949 CEST50029443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.300889969 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.321567059 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.321712017 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.321778059 CEST50028443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.321819067 CEST50028443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.321819067 CEST50028443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.321835995 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.321858883 CEST4435002813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.324307919 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.324332952 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.324400902 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.324506998 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.324516058 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.403126001 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.403202057 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.403300047 CEST50029443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.403422117 CEST50029443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.403460026 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.403506041 CEST50029443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.403522015 CEST4435002913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.406414986 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.406443119 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.406521082 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.406661987 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.406677961 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.494963884 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.495325089 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.495417118 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.495754004 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.495768070 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.529114008 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.529458046 CEST50031443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.529489994 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.530172110 CEST50031443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.530178070 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.594041109 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.594151974 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.594305992 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.594357967 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.594427109 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.594427109 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.594470978 CEST50030443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.594506979 CEST4435003013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.596465111 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.596503019 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.596575022 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.596689939 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.596699953 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.625133991 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.625468969 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.625478029 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.625863075 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.625866890 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.628264904 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.628421068 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.628508091 CEST50031443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.628537893 CEST50031443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.628549099 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.628582001 CEST50031443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.628598928 CEST4435003113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.630440950 CEST50036443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.630486012 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.630561113 CEST50036443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.630675077 CEST50036443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.630687952 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.728512049 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.728539944 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.728630066 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.728652954 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.728770018 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.729324102 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.729439974 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.729474068 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.729501009 CEST50032443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.729513884 CEST4435003213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.732904911 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.732988119 CEST4435003713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.733081102 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.733186960 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.733222008 CEST4435003713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.973674059 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.974358082 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.974383116 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:37.974783897 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:37.974787951 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.043663979 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.044151068 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.044177055 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.044527054 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.044531107 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.072515011 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.072571993 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.072643995 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.072658062 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.072696924 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.072848082 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.074120045 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.074127913 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.074139118 CEST50033443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.074143887 CEST4435003313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.084589958 CEST50038443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.084672928 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.084767103 CEST50038443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.084969997 CEST50038443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.085005045 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.142354965 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.142379999 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.142458916 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.142458916 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.142509937 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.142597914 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.142606020 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.142615080 CEST50034443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.142617941 CEST4435003413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.144589901 CEST50039443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.144681931 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.144769907 CEST50039443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.145008087 CEST50039443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.145045996 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.235511065 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.236124992 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.236217022 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.236660004 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.236665964 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.271210909 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.271686077 CEST50036443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.271761894 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.271965027 CEST50036443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.271979094 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.309520006 CEST4435003713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.310142994 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.310231924 CEST4435003713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.310550928 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.310605049 CEST4435003713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.337970018 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.338022947 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.338141918 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.338155031 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.343738079 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.343738079 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.343786001 CEST50035443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.343822956 CEST4435003513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.346134901 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.346216917 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.346810102 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.346924067 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.346955061 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.372291088 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.372426987 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.372526884 CEST50036443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.372632980 CEST50036443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.372673035 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.372778893 CEST50036443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.372793913 CEST4435003613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.375521898 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.375607014 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.375703096 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.375791073 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.375823021 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.408268929 CEST4435003713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.408410072 CEST4435003713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.408612013 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.408612013 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.408612013 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.410285950 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.410320997 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.410408020 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.410501003 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.410516977 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.716774940 CEST50037443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.716836929 CEST4435003713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.753542900 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.766113043 CEST50038443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.766170025 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.766566038 CEST50038443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.766581059 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.785213947 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.785801888 CEST50039443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.785866022 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.786252975 CEST50039443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.786266088 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.862355947 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.862514019 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.862607956 CEST50038443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.862782955 CEST50038443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.862782955 CEST50038443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.862823963 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.862849951 CEST4435003813.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.866523981 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.866578102 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.866656065 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.866890907 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.866921902 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.883352995 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.883531094 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.883620024 CEST50039443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.883671999 CEST50039443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.883671999 CEST50039443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.883688927 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.883698940 CEST4435003913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.885900021 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.885982037 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.886087894 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.886226892 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.886260033 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.995855093 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.996320963 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.996381044 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:38.996725082 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:38.996737957 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.023612022 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.024071932 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.024133921 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.024446964 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.024466038 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.089636087 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.090049982 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.090081930 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.090420961 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.090431929 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.096267939 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.096328020 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.096410990 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.096438885 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.096466064 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.096499920 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.096532106 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.096582890 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.096610069 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.096636057 CEST50040443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.096648932 CEST4435004013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.098604918 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.098643064 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.098745108 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.098936081 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.098953962 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.125547886 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.125612974 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.125716925 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.125746965 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.125773907 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.125844955 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.125897884 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.125927925 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.125927925 CEST50041443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.125947952 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.125966072 CEST4435004113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.128000975 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.128029108 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.128108978 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.128212929 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.128220081 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.196958065 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.196986914 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.197007895 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.197091103 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.197115898 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.197180986 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.287826061 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.287940979 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.287962914 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.287992001 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.288027048 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.288062096 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.288105011 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.288117886 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.290672064 CEST50047443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.290756941 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.290859938 CEST50047443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.290978909 CEST50047443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.291007042 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.310039997 CEST50042443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.310051918 CEST4435004213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.434731007 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.435589075 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.435632944 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.436136961 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.436150074 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.533178091 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.533231020 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.533364058 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.533510923 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.533510923 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.533827066 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.533827066 CEST50043443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.533859968 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.533884048 CEST4435004313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.535381079 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.535866976 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.535952091 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.536124945 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.536142111 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.537094116 CEST50049443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.537122965 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.537213087 CEST50049443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.537398100 CEST50049443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.537419081 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.636753082 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.636814117 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.636856079 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.636976004 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.636976957 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.637044907 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.637128115 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.722450972 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.722515106 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.722661018 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.722799063 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.722800016 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.722940922 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.722940922 CEST50044443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.722984076 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.723020077 CEST4435004413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.725949049 CEST50050443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.725981951 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.726063013 CEST50050443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.726217985 CEST50050443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.726224899 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.753390074 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.753838062 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.753878117 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.754219055 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.754225969 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.775527954 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.775896072 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.775912046 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.776241064 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.776247025 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.860208035 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.860274076 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.860348940 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.860373974 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.860404968 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.860430002 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.860461950 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.861121893 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.861143112 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.861155033 CEST50045443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.861161947 CEST4435004513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.867805958 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.867886066 CEST4435005113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.867961884 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.868464947 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.868503094 CEST4435005113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.886007071 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.886060953 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.886111975 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.886130095 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.886174917 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.886226892 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.886585951 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.886600971 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.886619091 CEST50046443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.886625051 CEST4435004613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.893246889 CEST50052443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.893285990 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.893347979 CEST50052443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.893865108 CEST50052443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.893882036 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.936973095 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.944190025 CEST50047443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.944250107 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:39.944842100 CEST50047443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:39.944895983 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.039896011 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.039987087 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.040164948 CEST50047443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.040288925 CEST50047443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.040288925 CEST50047443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.040333986 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.040365934 CEST4435004713.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.044533014 CEST50053443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.044637918 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.044728994 CEST50053443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.045598984 CEST50053443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.045634031 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.216384888 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.229705095 CEST50049443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.229724884 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.230350018 CEST50049443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.230360031 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.339772940 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.339905977 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.339972019 CEST50049443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.340205908 CEST50049443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.340244055 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.340269089 CEST50049443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.340285063 CEST4435004913.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.343370914 CEST50054443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.343453884 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.343547106 CEST50054443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.343744040 CEST50054443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.343761921 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.377743959 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.378695011 CEST50050443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.378710985 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.379021883 CEST50050443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.379038095 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.478923082 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.479075909 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.479175091 CEST50050443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.479350090 CEST50050443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.479413986 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.479453087 CEST50050443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.479470015 CEST4435005013.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.482175112 CEST50055443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.482215881 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.482292891 CEST50055443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.482470036 CEST50055443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.482487917 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.516470909 CEST4435005113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.517215967 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.517297029 CEST4435005113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.517644882 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.517698050 CEST4435005113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.583677053 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.584402084 CEST50052443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.584439039 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.584563017 CEST50052443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.584572077 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.616822958 CEST4435005113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.616977930 CEST4435005113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.617197990 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.617197990 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.617197990 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.620002031 CEST50056443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.620040894 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.620131969 CEST50056443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.620357990 CEST50056443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.620373011 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.688270092 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.688611031 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.688714981 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.688987970 CEST50052443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.688987970 CEST50052443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.690045118 CEST50052443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.690063953 CEST4435005213.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.690383911 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.691101074 CEST50053443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.691188097 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.691236973 CEST50053443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.691251993 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.796750069 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.796835899 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.796905994 CEST50053443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.797069073 CEST50053443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.797113895 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.797143936 CEST50053443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.797158957 CEST4435005313.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.919297934 CEST50051443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.919359922 CEST4435005113.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.983202934 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.983797073 CEST50054443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.983839989 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:40.984251976 CEST50054443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:40.984265089 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.081830978 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.081971884 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.082170963 CEST50054443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.082240105 CEST50054443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.082241058 CEST50054443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.082273960 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.082298040 CEST4435005413.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.172538996 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.173150063 CEST50055443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.173192024 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.173820019 CEST50055443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.173860073 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.278511047 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.278650045 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.278750896 CEST50055443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.279087067 CEST50055443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.279087067 CEST50055443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.279118061 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.279134035 CEST4435005513.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.280529022 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.282746077 CEST50056443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.282767057 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.283112049 CEST50056443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.283118963 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.380858898 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.380981922 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.381057024 CEST50056443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.381185055 CEST50056443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.381213903 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:41.381226063 CEST50056443192.168.2.413.107.246.45
                        Oct 7, 2024 02:52:41.381234884 CEST4435005613.107.246.45192.168.2.4
                        Oct 7, 2024 02:52:55.565252066 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:55.565310955 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:55.565484047 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:55.565877914 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:55.565895081 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:56.235100031 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:56.235542059 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:56.235564947 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:56.236077070 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:56.236756086 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:56.236835003 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:56.236897945 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:56.236913919 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:56.236927032 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:56.602655888 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:56.602987051 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:56.603082895 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:56.603461981 CEST50057443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:56.603485107 CEST44350057142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:59.535165071 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:59.535228968 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:52:59.535316944 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:59.535660982 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:52:59.535679102 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:53:00.190885067 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:53:00.191483974 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:53:00.191513062 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:53:00.192985058 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:53:00.193550110 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:53:00.193694115 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:53:00.193706036 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:53:00.193717003 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:53:00.193737984 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:53:00.248132944 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:53:00.487333059 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:53:00.487953901 CEST44350058142.250.181.238192.168.2.4
                        Oct 7, 2024 02:53:00.488030910 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:53:00.488178968 CEST50058443192.168.2.4142.250.181.238
                        Oct 7, 2024 02:53:00.488203049 CEST44350058142.250.181.238192.168.2.4
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 7, 2024 02:51:09.942647934 CEST5221953192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:09.942792892 CEST5880753192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:09.949656010 CEST53522191.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:09.949928999 CEST53588071.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:09.951159000 CEST53541811.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:09.953600883 CEST53492821.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:10.931339025 CEST5145053192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:10.931792021 CEST4999353192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:10.938335896 CEST53514501.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:10.938385010 CEST53499931.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:10.993829012 CEST53616091.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:14.451245070 CEST5565053192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:14.451401949 CEST4935553192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:14.513293982 CEST53556501.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:14.513530016 CEST53493551.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:17.090528011 CEST53553001.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:19.603580952 CEST5100453192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:19.603749037 CEST5502053192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:19.610392094 CEST53510041.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:19.610410929 CEST53550201.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:20.994309902 CEST6097353192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:20.994725943 CEST6339953192.168.2.41.1.1.1
                        Oct 7, 2024 02:51:21.001257896 CEST53609731.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:21.002126932 CEST53633991.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:22.198012114 CEST138138192.168.2.4192.168.2.255
                        Oct 7, 2024 02:51:22.490792990 CEST53498801.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:28.004874945 CEST53537011.1.1.1192.168.2.4
                        Oct 7, 2024 02:51:46.834997892 CEST53569701.1.1.1192.168.2.4
                        Oct 7, 2024 02:52:09.804878950 CEST53613721.1.1.1192.168.2.4
                        Oct 7, 2024 02:52:09.897198915 CEST53591251.1.1.1192.168.2.4
                        Oct 7, 2024 02:52:21.732057095 CEST53575121.1.1.1192.168.2.4
                        Oct 7, 2024 02:52:23.552150011 CEST6415053192.168.2.41.1.1.1
                        Oct 7, 2024 02:52:23.552232981 CEST5758453192.168.2.41.1.1.1
                        Oct 7, 2024 02:52:23.559007883 CEST53575841.1.1.1192.168.2.4
                        Oct 7, 2024 02:52:23.559206009 CEST53641501.1.1.1192.168.2.4
                        Oct 7, 2024 02:52:38.226003885 CEST53541931.1.1.1192.168.2.4
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Oct 7, 2024 02:51:09.942647934 CEST192.168.2.41.1.1.10x518cStandard query (0)youtube.comA (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:09.942792892 CEST192.168.2.41.1.1.10x4180Standard query (0)youtube.com65IN (0x0001)false
                        Oct 7, 2024 02:51:10.931339025 CEST192.168.2.41.1.1.10x95d1Standard query (0)www.youtube.comA (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.931792021 CEST192.168.2.41.1.1.10x5f27Standard query (0)www.youtube.com65IN (0x0001)false
                        Oct 7, 2024 02:51:14.451245070 CEST192.168.2.41.1.1.10x83e9Standard query (0)www.google.comA (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:14.451401949 CEST192.168.2.41.1.1.10x7014Standard query (0)www.google.com65IN (0x0001)false
                        Oct 7, 2024 02:51:19.603580952 CEST192.168.2.41.1.1.10xb478Standard query (0)accounts.youtube.comA (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:19.603749037 CEST192.168.2.41.1.1.10x4feaStandard query (0)accounts.youtube.com65IN (0x0001)false
                        Oct 7, 2024 02:51:20.994309902 CEST192.168.2.41.1.1.10xd0fdStandard query (0)play.google.comA (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:20.994725943 CEST192.168.2.41.1.1.10x4763Standard query (0)play.google.com65IN (0x0001)false
                        Oct 7, 2024 02:52:23.552150011 CEST192.168.2.41.1.1.10xeabStandard query (0)play.google.comA (IP address)IN (0x0001)false
                        Oct 7, 2024 02:52:23.552232981 CEST192.168.2.41.1.1.10xba09Standard query (0)play.google.com65IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Oct 7, 2024 02:51:09.949656010 CEST1.1.1.1192.168.2.40x518cNo error (0)youtube.com142.250.186.78A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:09.949928999 CEST1.1.1.1192.168.2.40x4180No error (0)youtube.com65IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)www.youtube.comyoutube-ui.l.google.comCNAME (Canonical name)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.185.238A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.186.78A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.186.174A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.186.46A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.74.206A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com172.217.18.14A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.185.174A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.186.110A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.184.206A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.184.238A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com172.217.16.206A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com172.217.16.142A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.185.142A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com216.58.206.46A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.181.238A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938335896 CEST1.1.1.1192.168.2.40x95d1No error (0)youtube-ui.l.google.com142.250.185.206A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938385010 CEST1.1.1.1192.168.2.40x5f27No error (0)www.youtube.comyoutube-ui.l.google.comCNAME (Canonical name)IN (0x0001)false
                        Oct 7, 2024 02:51:10.938385010 CEST1.1.1.1192.168.2.40x5f27No error (0)youtube-ui.l.google.com65IN (0x0001)false
                        Oct 7, 2024 02:51:14.513293982 CEST1.1.1.1192.168.2.40x83e9No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:14.513530016 CEST1.1.1.1192.168.2.40x7014No error (0)www.google.com65IN (0x0001)false
                        Oct 7, 2024 02:51:19.610392094 CEST1.1.1.1192.168.2.40xb478No error (0)accounts.youtube.comwww3.l.google.comCNAME (Canonical name)IN (0x0001)false
                        Oct 7, 2024 02:51:19.610392094 CEST1.1.1.1192.168.2.40xb478No error (0)www3.l.google.com142.250.186.46A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:51:19.610410929 CEST1.1.1.1192.168.2.40x4feaNo error (0)accounts.youtube.comwww3.l.google.comCNAME (Canonical name)IN (0x0001)false
                        Oct 7, 2024 02:51:21.001257896 CEST1.1.1.1192.168.2.40xd0fdNo error (0)play.google.com142.250.181.238A (IP address)IN (0x0001)false
                        Oct 7, 2024 02:52:23.559206009 CEST1.1.1.1192.168.2.40xeabNo error (0)play.google.com142.250.181.238A (IP address)IN (0x0001)false
                        • youtube.com
                        • www.youtube.com
                        • fs.microsoft.com
                        • https:
                          • play.google.com
                          • www.google.com
                        • slscr.update.microsoft.com
                        • otelrules.azureedge.net
                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.449733142.250.186.78443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:10 UTC851OUTGET /account?=https://accounts.google.com/v3/signin/challenge/pwd HTTP/1.1
                        Host: youtube.com
                        Connection: keep-alive
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-User: ?1
                        Sec-Fetch-Dest: document
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-10-07 00:51:10 UTC1919INHTTP/1.1 301 Moved Permanently
                        Content-Type: application/binary
                        X-Content-Type-Options: nosniff
                        Expires: Mon, 07 Oct 2024 00:51:10 GMT
                        Date: Mon, 07 Oct 2024 00:51:10 GMT
                        Cache-Control: private, max-age=31536000
                        Location: https://www.youtube.com/account?=https%3A%2F%2Faccounts.google.com%2Fv3%2Fsignin%2Fchallenge%2Fpwd
                        X-Frame-Options: SAMEORIGIN
                        Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                        Origin-Trial: AmhMBR6zCLzDDxpW+HfpP67BqwIknWnyMOXOQGfzYswFmJe+fgaI6XZgAzcxOrzNtP7hEDsOo1jdjFnVr2IdxQ4AAAB4eyJvcmlnaW4iOiJodHRwczovL3lvdXR1YmUuY29tOjQ0MyIsImZlYXR1cmUiOiJXZWJWaWV3WFJlcXVlc3RlZFdpdGhEZXByZWNhdGlvbiIsImV4cGlyeSI6MTc1ODA2NzE5OSwiaXNTdWJkb21haW4iOnRydWV9
                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                        Vary: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                        Content-Security-Policy: require-trusted-types-for 'script'
                        Report-To: {"group":"youtube_main","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/youtube_main"}]}
                        Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
                        Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="youtube_main"
                        P3P: CP="This is not a P3P policy! See http://support.google.com/accounts/answer/151657?hl=en for more info."
                        Server: ESF
                        Content-Length: 0
                        X-XSS-Protection: 0
                        Set-Cookie: YSC=omnWoqYJUmg; Domain=.youtube.com; Path=/; Secure; HttpOnly; SameSite=none; Partitioned
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Connection: close


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.449736142.250.185.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:11 UTC894OUTGET /account?=https%3A%2F%2Faccounts.google.com%2Fv3%2Fsignin%2Fchallenge%2Fpwd HTTP/1.1
                        Host: www.youtube.com
                        Connection: keep-alive
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-User: ?1
                        Sec-Fetch-Dest: document
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: YSC=omnWoqYJUmg
                        2024-10-07 00:51:11 UTC2530INHTTP/1.1 303 See Other
                        Content-Type: application/binary
                        X-Content-Type-Options: nosniff
                        Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                        Pragma: no-cache
                        Expires: Mon, 01 Jan 1990 00:00:00 GMT
                        Date: Mon, 07 Oct 2024 00:51:11 GMT
                        Location: https://accounts.google.com/ServiceLogin?service=youtube&uilel=3&passive=true&continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%253F%253Dhttps%25253A%25252F%25252Faccounts.google.com%25252Fv3%25252Fsignin%25252Fchallenge%25252Fpwd%26feature%3Dredirect_login&hl=en
                        Strict-Transport-Security: max-age=31536000
                        X-Frame-Options: SAMEORIGIN
                        Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
                        Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="youtube_main"
                        Content-Security-Policy: require-trusted-types-for 'script'
                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                        Vary: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                        Origin-Trial: AmhMBR6zCLzDDxpW+HfpP67BqwIknWnyMOXOQGfzYswFmJe+fgaI6XZgAzcxOrzNtP7hEDsOo1jdjFnVr2IdxQ4AAAB4eyJvcmlnaW4iOiJodHRwczovL3lvdXR1YmUuY29tOjQ0MyIsImZlYXR1cmUiOiJXZWJWaWV3WFJlcXVlc3RlZFdpdGhEZXByZWNhdGlvbiIsImV4cGlyeSI6MTc1ODA2NzE5OSwiaXNTdWJkb21haW4iOnRydWV9
                        Report-To: {"group":"youtube_main","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/youtube_main"}]}
                        P3P: CP="This is not a P3P policy! See http://support.google.com/accounts/answer/151657?hl=en for more info."
                        Server: ESF
                        Content-Length: 0
                        X-XSS-Protection: 0
                        Set-Cookie: GPS=1; Domain=.youtube.com; Expires=Mon, 07-Oct-2024 01:21:11 GMT; Path=/; Secure; HttpOnly
                        Set-Cookie: VISITOR_INFO1_LIVE=Qpa91Fv4dOQ; Domain=.youtube.com; Expires=Sat, 05-Apr-2025 00:51:11 GMT; Path=/; Secure; HttpOnly; SameSite=none; Partitioned
                        Set-Cookie: VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgOw%3D%3D; Domain=.youtube.com; Expires=Sat, 05-Apr-2025 00:51:11 GMT; Path=/; Secure; HttpOnly; SameSite=none; Partitioned
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Connection: close


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        2192.168.2.449742184.28.90.27443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:15 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        Accept-Encoding: identity
                        User-Agent: Microsoft BITS/7.8
                        Host: fs.microsoft.com
                        2024-10-07 00:51:15 UTC467INHTTP/1.1 200 OK
                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                        Content-Type: application/octet-stream
                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                        Server: ECAcc (lpl/EF45)
                        X-CID: 11
                        X-Ms-ApiVersion: Distribute 1.2
                        X-Ms-Region: prod-weu-z1
                        Cache-Control: public, max-age=230067
                        Date: Mon, 07 Oct 2024 00:51:15 GMT
                        Connection: close
                        X-CID: 2


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        3192.168.2.449744184.28.90.27443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:16 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        Accept-Encoding: identity
                        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                        Range: bytes=0-2147483646
                        User-Agent: Microsoft BITS/7.8
                        Host: fs.microsoft.com
                        2024-10-07 00:51:16 UTC515INHTTP/1.1 200 OK
                        ApiVersion: Distribute 1.1
                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                        Content-Type: application/octet-stream
                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                        Server: ECAcc (lpl/EF06)
                        X-CID: 11
                        X-Ms-ApiVersion: Distribute 1.2
                        X-Ms-Region: prod-weu-z1
                        Cache-Control: public, max-age=230002
                        Date: Mon, 07 Oct 2024 00:51:16 GMT
                        Content-Length: 55
                        Connection: close
                        X-CID: 2
                        2024-10-07 00:51:16 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        4192.168.2.449761142.250.181.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:21 UTC549OUTOPTIONS /log?format=json&hasfast=true&authuser=0 HTTP/1.1
                        Host: play.google.com
                        Connection: keep-alive
                        Accept: */*
                        Access-Control-Request-Method: POST
                        Access-Control-Request-Headers: x-goog-authuser
                        Origin: https://accounts.google.com
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Dest: empty
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-10-07 00:51:22 UTC520INHTTP/1.1 200 OK
                        Access-Control-Allow-Origin: https://accounts.google.com
                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                        Access-Control-Max-Age: 86400
                        Access-Control-Allow-Credentials: true
                        Access-Control-Allow-Headers: X-Playlog-Web,authorization,origin,x-goog-authuser
                        Content-Type: text/plain; charset=UTF-8
                        Date: Mon, 07 Oct 2024 00:51:21 GMT
                        Server: Playlog
                        Content-Length: 0
                        X-XSS-Protection: 0
                        X-Frame-Options: SAMEORIGIN
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Connection: close


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        5192.168.2.449762142.250.181.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:21 UTC549OUTOPTIONS /log?format=json&hasfast=true&authuser=0 HTTP/1.1
                        Host: play.google.com
                        Connection: keep-alive
                        Accept: */*
                        Access-Control-Request-Method: POST
                        Access-Control-Request-Headers: x-goog-authuser
                        Origin: https://accounts.google.com
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Dest: empty
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-10-07 00:51:22 UTC520INHTTP/1.1 200 OK
                        Access-Control-Allow-Origin: https://accounts.google.com
                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                        Access-Control-Max-Age: 86400
                        Access-Control-Allow-Credentials: true
                        Access-Control-Allow-Headers: X-Playlog-Web,authorization,origin,x-goog-authuser
                        Content-Type: text/plain; charset=UTF-8
                        Date: Mon, 07 Oct 2024 00:51:21 GMT
                        Server: Playlog
                        Content-Length: 0
                        X-XSS-Protection: 0
                        X-Frame-Options: SAMEORIGIN
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Connection: close


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        6192.168.2.449764142.250.181.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:22 UTC1124OUTPOST /log?format=json&hasfast=true&authuser=0 HTTP/1.1
                        Host: play.google.com
                        Connection: keep-alive
                        Content-Length: 519
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-arch: "x86"
                        Content-Type: application/x-www-form-urlencoded;charset=UTF-8
                        sec-ch-ua-full-version: "117.0.5938.132"
                        sec-ch-ua-platform-version: "10.0.0"
                        X-Goog-AuthUser: 0
                        sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                        sec-ch-ua-bitness: "64"
                        sec-ch-ua-model: ""
                        sec-ch-ua-wow64: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept: */*
                        Origin: https://accounts.google.com
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Dest: empty
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-10-07 00:51:22 UTC519OUTData Raw: 5b 5b 31 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 22 65 6e 22 2c 6e 75 6c 6c 2c 22 33 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 47 6f 6f 67 6c 65 20 43 68 72 6f 6d 65 22 2c 22 31 31 37 22 5d 2c 5b 22 4e 6f 74 3b 41 3d 42 72 61 6e 64 22 2c 22 38 22 5d 2c 5b 22 43 68 72 6f 6d 69 75 6d 22 2c 22 31 31 37 22 5d 5d 2c 30 2c 22 57 69 6e 64 6f 77 73 22 2c 22 31 30 2e 30 2e 30 22 2c 22 78 38 36 22 2c 22 22 2c 22 31 31 37 2e 30 2e 35 39 33 38 2e 31 33 32 22 5d 2c 5b 31 2c 30 2c 30 2c 30 2c 30 5d 5d 5d 2c 31 38 32 38 2c 5b 5b 22 31 37 32 38 32 36 32 32 38 30 32 38 37 22 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c
                        Data Ascii: [[1,null,null,null,null,null,null,null,null,null,[null,null,null,null,"en",null,"31",null,[[["Google Chrome","117"],["Not;A=Brand","8"],["Chromium","117"]],0,"Windows","10.0.0","x86","","117.0.5938.132"],[1,0,0,0,0]]],1828,[["1728262280287",null,null,null
                        2024-10-07 00:51:22 UTC932INHTTP/1.1 200 OK
                        Access-Control-Allow-Origin: https://accounts.google.com
                        Cross-Origin-Resource-Policy: cross-origin
                        Access-Control-Allow-Credentials: true
                        Access-Control-Allow-Headers: X-Playlog-Web
                        Set-Cookie: NID=518=so-1sNibFdl-6xg7wPia3G7zgkAozEEeGVBirirsaV5D-qfqsSS_-a1zYQgmNq5KUFFHZgveEkKiTP_f5MGr7ydGQis7dJhDWwld8NsN69RUfN18f7clLetxa0N3mXv55HC8aFjEtu3GK2-sbkxkJ8FwIA-RgbtVO1y7sJLBmErScjpwTA; expires=Tue, 08-Apr-2025 00:51:22 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                        P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                        Content-Type: text/plain; charset=UTF-8
                        Date: Mon, 07 Oct 2024 00:51:22 GMT
                        Server: Playlog
                        Cache-Control: private
                        X-XSS-Protection: 0
                        X-Frame-Options: SAMEORIGIN
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Accept-Ranges: none
                        Vary: Accept-Encoding
                        Expires: Mon, 07 Oct 2024 00:51:22 GMT
                        Connection: close
                        Transfer-Encoding: chunked
                        2024-10-07 00:51:22 UTC137INData Raw: 38 33 0d 0a 5b 22 2d 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 41 4e 44 52 4f 49 44 5f 42 41 43 4b 55 50 22 2c 30 5d 2c 5b 22 42 41 54 54 45 52 59 5f 53 54 41 54 53 22 2c 30 5d 2c 5b 22 53 4d 41 52 54 5f 53 45 54 55 50 22 2c 30 5d 2c 5b 22 54 52 4f 4e 22 2c 30 5d 5d 2c 2d 33 33 33 34 37 33 37 35 39 34 30 32 34 39 37 31 32 32 35 5d 2c 5b 5d 2c 7b 22 31 37 35 32 33 37 33 37 35 22 3a 5b 31 30 30 30 30 5d 7d 5d 0d 0a
                        Data Ascii: 83["-1",null,[[["ANDROID_BACKUP",0],["BATTERY_STATS",0],["SMART_SETUP",0],["TRON",0]],-3334737594024971225],[],{"175237375":[10000]}]
                        2024-10-07 00:51:22 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        7192.168.2.449765142.250.181.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:22 UTC1124OUTPOST /log?format=json&hasfast=true&authuser=0 HTTP/1.1
                        Host: play.google.com
                        Connection: keep-alive
                        Content-Length: 519
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-arch: "x86"
                        Content-Type: application/x-www-form-urlencoded;charset=UTF-8
                        sec-ch-ua-full-version: "117.0.5938.132"
                        sec-ch-ua-platform-version: "10.0.0"
                        X-Goog-AuthUser: 0
                        sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                        sec-ch-ua-bitness: "64"
                        sec-ch-ua-model: ""
                        sec-ch-ua-wow64: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept: */*
                        Origin: https://accounts.google.com
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Dest: empty
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-10-07 00:51:22 UTC519OUTData Raw: 5b 5b 31 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 22 65 6e 22 2c 6e 75 6c 6c 2c 22 33 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 47 6f 6f 67 6c 65 20 43 68 72 6f 6d 65 22 2c 22 31 31 37 22 5d 2c 5b 22 4e 6f 74 3b 41 3d 42 72 61 6e 64 22 2c 22 38 22 5d 2c 5b 22 43 68 72 6f 6d 69 75 6d 22 2c 22 31 31 37 22 5d 5d 2c 30 2c 22 57 69 6e 64 6f 77 73 22 2c 22 31 30 2e 30 2e 30 22 2c 22 78 38 36 22 2c 22 22 2c 22 31 31 37 2e 30 2e 35 39 33 38 2e 31 33 32 22 5d 2c 5b 31 2c 30 2c 30 2c 30 2c 30 5d 5d 5d 2c 31 38 32 38 2c 5b 5b 22 31 37 32 38 32 36 32 32 38 30 32 30 35 22 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c
                        Data Ascii: [[1,null,null,null,null,null,null,null,null,null,[null,null,null,null,"en",null,"31",null,[[["Google Chrome","117"],["Not;A=Brand","8"],["Chromium","117"]],0,"Windows","10.0.0","x86","","117.0.5938.132"],[1,0,0,0,0]]],1828,[["1728262280205",null,null,null
                        2024-10-07 00:51:23 UTC932INHTTP/1.1 200 OK
                        Access-Control-Allow-Origin: https://accounts.google.com
                        Cross-Origin-Resource-Policy: cross-origin
                        Access-Control-Allow-Credentials: true
                        Access-Control-Allow-Headers: X-Playlog-Web
                        Set-Cookie: NID=518=XqXSGk8CZxiaCMiwLFRVwsG2tQluZDiR1GeHv-GYN2qxkc4CxtV0kkehhaL_vC-lHBHOFrVZ0DtMoFE4hltcihsBAfG_XKsV1dVm4zl0OcORrh_rNX7k189D_YuqEK0zBGitfKeNj2pX7donU1Sbu2-IeLkiwASuK6ThYvdsKQE24b2aag; expires=Tue, 08-Apr-2025 00:51:22 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                        P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                        Content-Type: text/plain; charset=UTF-8
                        Date: Mon, 07 Oct 2024 00:51:22 GMT
                        Server: Playlog
                        Cache-Control: private
                        X-XSS-Protection: 0
                        X-Frame-Options: SAMEORIGIN
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Accept-Ranges: none
                        Vary: Accept-Encoding
                        Expires: Mon, 07 Oct 2024 00:51:22 GMT
                        Connection: close
                        Transfer-Encoding: chunked
                        2024-10-07 00:51:23 UTC137INData Raw: 38 33 0d 0a 5b 22 2d 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 41 4e 44 52 4f 49 44 5f 42 41 43 4b 55 50 22 2c 30 5d 2c 5b 22 42 41 54 54 45 52 59 5f 53 54 41 54 53 22 2c 30 5d 2c 5b 22 53 4d 41 52 54 5f 53 45 54 55 50 22 2c 30 5d 2c 5b 22 54 52 4f 4e 22 2c 30 5d 5d 2c 2d 33 33 33 34 37 33 37 35 39 34 30 32 34 39 37 31 32 32 35 5d 2c 5b 5d 2c 7b 22 31 37 35 32 33 37 33 37 35 22 3a 5b 31 30 30 30 30 5d 7d 5d 0d 0a
                        Data Ascii: 83["-1",null,[[["ANDROID_BACKUP",0],["BATTERY_STATS",0],["SMART_SETUP",0],["TRON",0]],-3334737594024971225],[],{"175237375":[10000]}]
                        2024-10-07 00:51:23 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        8192.168.2.449740142.250.184.228443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:23 UTC1213OUTGET /favicon.ico HTTP/1.1
                        Host: www.google.com
                        Connection: keep-alive
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-arch: "x86"
                        sec-ch-ua-full-version: "117.0.5938.132"
                        sec-ch-ua-platform-version: "10.0.0"
                        sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                        sec-ch-ua-bitness: "64"
                        sec-ch-ua-model: ""
                        sec-ch-ua-wow64: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: image
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: NID=518=XqXSGk8CZxiaCMiwLFRVwsG2tQluZDiR1GeHv-GYN2qxkc4CxtV0kkehhaL_vC-lHBHOFrVZ0DtMoFE4hltcihsBAfG_XKsV1dVm4zl0OcORrh_rNX7k189D_YuqEK0zBGitfKeNj2pX7donU1Sbu2-IeLkiwASuK6ThYvdsKQE24b2aag
                        2024-10-07 00:51:23 UTC704INHTTP/1.1 200 OK
                        Accept-Ranges: bytes
                        Cross-Origin-Resource-Policy: cross-origin
                        Cross-Origin-Opener-Policy-Report-Only: same-origin; report-to="static-on-bigtable"
                        Report-To: {"group":"static-on-bigtable","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/static-on-bigtable"}]}
                        Content-Length: 5430
                        X-Content-Type-Options: nosniff
                        Server: sffe
                        X-XSS-Protection: 0
                        Date: Mon, 07 Oct 2024 00:35:07 GMT
                        Expires: Tue, 15 Oct 2024 00:35:07 GMT
                        Cache-Control: public, max-age=691200
                        Last-Modified: Tue, 22 Oct 2019 18:30:00 GMT
                        Content-Type: image/x-icon
                        Vary: Accept-Encoding
                        Age: 976
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Connection: close
                        2024-10-07 00:51:23 UTC686INData Raw: 00 00 01 00 02 00 10 10 00 00 01 00 20 00 68 04 00 00 26 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 8e 04 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 20 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 30 fd fd fd 96 fd fd fd d8 fd fd fd f9 fd fd fd f9 fd fd fd d7 fd fd fd 94 fe fe fe 2e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fe fe fe 09 fd fd fd 99 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd 95 ff ff ff 08 00 00 00 00 00 00 00 00 00 00 00 00 fe fe fe 09 fd fd fd c1 ff ff ff ff fa fd f9 ff b4 d9 a7 ff 76 ba 5d ff 58 ab 3a ff 58 aa 3a ff 72 b8 59 ff ac d5 9d ff f8 fb f6 ff ff
                        Data Ascii: h& ( 0.v]X:X:rY
                        2024-10-07 00:51:23 UTC1390INData Raw: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd d8 fd fd fd 99 ff ff ff ff 92 cf fb ff 37 52 ec ff 38 46 ea ff d0 d4 fa ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd 96 fe fe fe 32 ff ff ff ff f9 f9 fe ff 56 62 ed ff 35 43 ea ff 3b 49 eb ff 95 9c f4 ff cf d2 fa ff d1 d4 fa ff 96 9d f4 ff 52 5e ed ff e1 e3 fc ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 30 00 00 00 00 fd fd fd 9d ff ff ff ff e8 ea fd ff 58 63 ee ff 35 43 ea ff 35 43 ea ff 35 43 ea ff 35 43 ea ff 35 43 ea ff 35 43 ea ff 6c 76 f0 ff ff ff ff ff ff ff ff ff fd fd fd 98 00 00 00 00 00 00 00 00 ff ff ff 0a fd fd fd c3 ff ff ff ff f9 f9 fe ff a5 ac f6 ff 5d 69 ee ff 3c 4a eb
                        Data Ascii: 7R8F2Vb5C;IR^0Xc5C5C5C5C5C5Clv]i<J
                        2024-10-07 00:51:23 UTC1390INData Raw: ff ff ff ff ff ff ff ff ff ff fd fd fd d0 ff ff ff 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fd fd fd 8b ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff b1 d8 a3 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 60 a5 35 ff ca 8e 3e ff f9 c1 9f ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd 87 00 00 00 00 00 00 00 00 00 00 00 00 fe fe fe 25 fd fd fd fb ff ff ff ff ff ff ff ff ff ff ff ff c2 e0 b7 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 53 a8 34 ff 6e b6 54 ff 9f ce 8d ff b7 da aa ff b8 db ab ff a5 d2 95 ff 7b bc 64 ff 54 a8 35 ff 53 a8 34 ff 77 a0 37 ff e3 89 41 ff f4 85 42 ff f4 85 42 ff fc
                        Data Ascii: S4S4S4S4S4S4S4S4S4S4S4S4S4S4`5>%S4S4S4S4S4S4nT{dT5S4w7ABB
                        2024-10-07 00:51:23 UTC1390INData Raw: f4 85 42 ff f4 85 42 ff f4 85 42 ff f4 85 42 ff f4 85 42 ff f4 85 42 ff fb d5 bf ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd ea fd fd fd cb ff ff ff ff ff ff ff ff ff ff ff ff 46 cd fc ff 05 bc fb ff 05 bc fb ff 05 bc fb ff 21 ae f9 ff fb fb ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd c8 fd fd fd 9c ff ff ff ff ff ff ff ff ff ff ff ff 86 df fd ff 05 bc fb ff 05 bc fb ff 15 93 f5 ff 34 49 eb ff b3 b8 f7 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                        Data Ascii: BBBBBBF!4I
                        2024-10-07 00:51:23 UTC574INData Raw: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd d2 fe fe fe 24 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 0a fd fd fd 8d fd fd fd fc ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fd fd fd fb fd fd fd 8b fe fe fe 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fe fe fe 27 fd fd fd 9f fd fd fd f7 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                        Data Ascii: $'


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        9192.168.2.4497684.175.87.197443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:24 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=gs1szRCNStTUBPy&MD=nnK7C6a5 HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                        Host: slscr.update.microsoft.com
                        2024-10-07 00:51:24 UTC560INHTTP/1.1 200 OK
                        Cache-Control: no-cache
                        Pragma: no-cache
                        Content-Type: application/octet-stream
                        Expires: -1
                        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                        ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                        MS-CorrelationId: 15581627-82c0-4b85-a6ff-9753a93c78a7
                        MS-RequestId: c6637e06-186f-43c8-adfc-45dbfb1ec0d4
                        MS-CV: ZwispDiDXkmNOhLl.0
                        X-Microsoft-SLSClientCache: 2880
                        Content-Disposition: attachment; filename=environment.cab
                        X-Content-Type-Options: nosniff
                        Date: Mon, 07 Oct 2024 00:51:23 GMT
                        Connection: close
                        Content-Length: 24490
                        2024-10-07 00:51:24 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                        Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                        2024-10-07 00:51:24 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                        Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        10192.168.2.449780142.250.181.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:29 UTC1298OUTPOST /log?format=json&hasfast=true&authuser=0 HTTP/1.1
                        Host: play.google.com
                        Connection: keep-alive
                        Content-Length: 1218
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-arch: "x86"
                        Content-Type: text/plain;charset=UTF-8
                        sec-ch-ua-full-version: "117.0.5938.132"
                        sec-ch-ua-platform-version: "10.0.0"
                        X-Goog-AuthUser: 0
                        sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                        sec-ch-ua-bitness: "64"
                        sec-ch-ua-model: ""
                        sec-ch-ua-wow64: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept: */*
                        Origin: https://accounts.google.com
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Dest: empty
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: NID=518=XqXSGk8CZxiaCMiwLFRVwsG2tQluZDiR1GeHv-GYN2qxkc4CxtV0kkehhaL_vC-lHBHOFrVZ0DtMoFE4hltcihsBAfG_XKsV1dVm4zl0OcORrh_rNX7k189D_YuqEK0zBGitfKeNj2pX7donU1Sbu2-IeLkiwASuK6ThYvdsKQE24b2aag
                        2024-10-07 00:51:29 UTC1218OUTData Raw: 5b 5b 31 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 22 65 6e 22 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 5b 5b 22 47 6f 6f 67 6c 65 20 43 68 72 6f 6d 65 22 2c 22 31 31 37 22 5d 2c 5b 22 4e 6f 74 3b 41 3d 42 72 61 6e 64 22 2c 22 38 22 5d 2c 5b 22 43 68 72 6f 6d 69 75 6d 22 2c 22 31 31 37 22 5d 5d 2c 30 2c 22 57 69 6e 64 6f 77 73 22 2c 22 31 30 2e 30 2e 30 22 2c 22 78 38 36 22 2c 22 22 2c 22 31 31 37 2e 30 2e 35 39 33 38 2e 31 33 32 22 5d 2c 5b 34 2c 30 2c 30 2c 30 2c 30 5d 5d 5d 2c 35 35 38 2c 5b 5b 22 31 37 32 38 32 36 32 32 37 37 30 30 30 22 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c
                        Data Ascii: [[1,null,null,null,null,null,null,null,null,null,[null,null,null,null,"en",null,null,null,[[["Google Chrome","117"],["Not;A=Brand","8"],["Chromium","117"]],0,"Windows","10.0.0","x86","","117.0.5938.132"],[4,0,0,0,0]]],558,[["1728262277000",null,null,null,
                        2024-10-07 00:51:29 UTC940INHTTP/1.1 200 OK
                        Access-Control-Allow-Origin: https://accounts.google.com
                        Cross-Origin-Resource-Policy: cross-origin
                        Access-Control-Allow-Credentials: true
                        Access-Control-Allow-Headers: X-Playlog-Web
                        Set-Cookie: NID=518=AHmchaevCiY7OBgWH4iH5MFRTCn_x2cBuqNt4q04EQCLqCRDqsSzUn5g0YWY53gaDuVUBLRrMFtTW40lRvEYspcb1BtCouoFsePxkXJlP1K8qhAQAdhUp3UU6odAoRjTkCsWk6y7jgN_MG9__Id8NkOYXfrojrz7fQxegJiqkOVtMC-djAHiHjKYPw; expires=Tue, 08-Apr-2025 00:51:29 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                        P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                        Content-Type: text/plain; charset=UTF-8
                        Date: Mon, 07 Oct 2024 00:51:29 GMT
                        Server: Playlog
                        Cache-Control: private
                        X-XSS-Protection: 0
                        X-Frame-Options: SAMEORIGIN
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Accept-Ranges: none
                        Vary: Accept-Encoding
                        Expires: Mon, 07 Oct 2024 00:51:29 GMT
                        Connection: close
                        Transfer-Encoding: chunked
                        2024-10-07 00:51:29 UTC137INData Raw: 38 33 0d 0a 5b 22 2d 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 41 4e 44 52 4f 49 44 5f 42 41 43 4b 55 50 22 2c 30 5d 2c 5b 22 42 41 54 54 45 52 59 5f 53 54 41 54 53 22 2c 30 5d 2c 5b 22 53 4d 41 52 54 5f 53 45 54 55 50 22 2c 30 5d 2c 5b 22 54 52 4f 4e 22 2c 30 5d 5d 2c 2d 33 33 33 34 37 33 37 35 39 34 30 32 34 39 37 31 32 32 35 5d 2c 5b 5d 2c 7b 22 31 37 35 32 33 37 33 37 35 22 3a 5b 31 30 30 30 30 5d 7d 5d 0d 0a
                        Data Ascii: 83["-1",null,[[["ANDROID_BACKUP",0],["BATTERY_STATS",0],["SMART_SETUP",0],["TRON",0]],-3334737594024971225],[],{"175237375":[10000]}]
                        2024-10-07 00:51:29 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        11192.168.2.449781142.250.181.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:52 UTC1289OUTPOST /log?hasfast=true&authuser=0&format=json HTTP/1.1
                        Host: play.google.com
                        Connection: keep-alive
                        Content-Length: 1068
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-arch: "x86"
                        sec-ch-ua-full-version: "117.0.5938.132"
                        Content-Type: text/plain;charset=UTF-8
                        sec-ch-ua-platform-version: "10.0.0"
                        sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                        sec-ch-ua-bitness: "64"
                        sec-ch-ua-model: ""
                        sec-ch-ua-wow64: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept: */*
                        Origin: https://accounts.google.com
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: empty
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: NID=518=AHmchaevCiY7OBgWH4iH5MFRTCn_x2cBuqNt4q04EQCLqCRDqsSzUn5g0YWY53gaDuVUBLRrMFtTW40lRvEYspcb1BtCouoFsePxkXJlP1K8qhAQAdhUp3UU6odAoRjTkCsWk6y7jgN_MG9__Id8NkOYXfrojrz7fQxegJiqkOVtMC-djAHiHjKYPw
                        2024-10-07 00:51:52 UTC1068OUTData Raw: 5b 5b 31 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 22 65 6e 22 2c 6e 75 6c 6c 2c 22 62 6f 71 5f 69 64 65 6e 74 69 74 79 66 72 6f 6e 74 65 6e 64 61 75 74 68 75 69 73 65 72 76 65 72 5f 32 30 32 34 31 30 30 31 2e 30 36 5f 70 30 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 47 6f 6f 67 6c 65 20 43 68 72 6f 6d 65 22 2c 22 31 31 37 22 5d 2c 5b 22 4e 6f 74 3b 41 3d 42 72 61 6e 64 22 2c 22 38 22 5d 2c 5b 22 43 68 72 6f 6d 69 75 6d 22 2c 22 31 31 37 22 5d 5d 2c 30 2c 22 57 69 6e 64 6f 77 73 22 2c 22 31 30 2e 30 2e 30 22 2c 22 78 38 36 22 2c 22 22 2c 22 31 31 37 2e 30 2e 35 39 33 38 2e 31 33 32 22 5d 2c 5b 33 2c 30 2c 30
                        Data Ascii: [[1,null,null,null,null,null,null,null,null,null,[null,null,null,null,"en",null,"boq_identityfrontendauthuiserver_20241001.06_p0",null,[[["Google Chrome","117"],["Not;A=Brand","8"],["Chromium","117"]],0,"Windows","10.0.0","x86","","117.0.5938.132"],[3,0,0
                        2024-10-07 00:51:53 UTC523INHTTP/1.1 200 OK
                        Access-Control-Allow-Origin: https://accounts.google.com
                        Cross-Origin-Resource-Policy: cross-origin
                        Access-Control-Allow-Credentials: true
                        Access-Control-Allow-Headers: X-Playlog-Web
                        Content-Type: text/plain; charset=UTF-8
                        Date: Mon, 07 Oct 2024 00:51:53 GMT
                        Server: Playlog
                        Cache-Control: private
                        X-XSS-Protection: 0
                        X-Frame-Options: SAMEORIGIN
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Accept-Ranges: none
                        Vary: Accept-Encoding
                        Connection: close
                        Transfer-Encoding: chunked
                        2024-10-07 00:51:53 UTC137INData Raw: 38 33 0d 0a 5b 22 2d 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 41 4e 44 52 4f 49 44 5f 42 41 43 4b 55 50 22 2c 30 5d 2c 5b 22 42 41 54 54 45 52 59 5f 53 54 41 54 53 22 2c 30 5d 2c 5b 22 53 4d 41 52 54 5f 53 45 54 55 50 22 2c 30 5d 2c 5b 22 54 52 4f 4e 22 2c 30 5d 5d 2c 2d 33 33 33 34 37 33 37 35 39 34 30 32 34 39 37 31 32 32 35 5d 2c 5b 5d 2c 7b 22 31 37 35 32 33 37 33 37 35 22 3a 5b 31 30 30 30 30 5d 7d 5d 0d 0a
                        Data Ascii: 83["-1",null,[[["ANDROID_BACKUP",0],["BATTERY_STATS",0],["SMART_SETUP",0],["TRON",0]],-3334737594024971225],[],{"175237375":[10000]}]
                        2024-10-07 00:51:53 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        12192.168.2.449782142.250.181.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:53 UTC1329OUTPOST /log?format=json&hasfast=true&authuser=0 HTTP/1.1
                        Host: play.google.com
                        Connection: keep-alive
                        Content-Length: 1345
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-arch: "x86"
                        Content-Type: application/x-www-form-urlencoded;charset=UTF-8
                        sec-ch-ua-full-version: "117.0.5938.132"
                        sec-ch-ua-platform-version: "10.0.0"
                        X-Goog-AuthUser: 0
                        sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                        sec-ch-ua-bitness: "64"
                        sec-ch-ua-model: ""
                        sec-ch-ua-wow64: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept: */*
                        Origin: https://accounts.google.com
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Dest: empty
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: NID=518=AHmchaevCiY7OBgWH4iH5MFRTCn_x2cBuqNt4q04EQCLqCRDqsSzUn5g0YWY53gaDuVUBLRrMFtTW40lRvEYspcb1BtCouoFsePxkXJlP1K8qhAQAdhUp3UU6odAoRjTkCsWk6y7jgN_MG9__Id8NkOYXfrojrz7fQxegJiqkOVtMC-djAHiHjKYPw
                        2024-10-07 00:51:53 UTC1345OUTData Raw: 5b 5b 31 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 22 65 6e 22 2c 6e 75 6c 6c 2c 22 33 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 47 6f 6f 67 6c 65 20 43 68 72 6f 6d 65 22 2c 22 31 31 37 22 5d 2c 5b 22 4e 6f 74 3b 41 3d 42 72 61 6e 64 22 2c 22 38 22 5d 2c 5b 22 43 68 72 6f 6d 69 75 6d 22 2c 22 31 31 37 22 5d 5d 2c 30 2c 22 57 69 6e 64 6f 77 73 22 2c 22 31 30 2e 30 2e 30 22 2c 22 78 38 36 22 2c 22 22 2c 22 31 31 37 2e 30 2e 35 39 33 38 2e 31 33 32 22 5d 2c 5b 31 2c 30 2c 30 2c 30 2c 30 5d 5d 5d 2c 31 38 32 38 2c 5b 5b 22 31 37 32 38 32 36 32 33 31 32 33 35 37 22 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c
                        Data Ascii: [[1,null,null,null,null,null,null,null,null,null,[null,null,null,null,"en",null,"31",null,[[["Google Chrome","117"],["Not;A=Brand","8"],["Chromium","117"]],0,"Windows","10.0.0","x86","","117.0.5938.132"],[1,0,0,0,0]]],1828,[["1728262312357",null,null,null
                        2024-10-07 00:51:54 UTC523INHTTP/1.1 200 OK
                        Access-Control-Allow-Origin: https://accounts.google.com
                        Cross-Origin-Resource-Policy: cross-origin
                        Access-Control-Allow-Credentials: true
                        Access-Control-Allow-Headers: X-Playlog-Web
                        Content-Type: text/plain; charset=UTF-8
                        Date: Mon, 07 Oct 2024 00:51:53 GMT
                        Server: Playlog
                        Cache-Control: private
                        X-XSS-Protection: 0
                        X-Frame-Options: SAMEORIGIN
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Accept-Ranges: none
                        Vary: Accept-Encoding
                        Connection: close
                        Transfer-Encoding: chunked
                        2024-10-07 00:51:54 UTC137INData Raw: 38 33 0d 0a 5b 22 2d 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 41 4e 44 52 4f 49 44 5f 42 41 43 4b 55 50 22 2c 30 5d 2c 5b 22 42 41 54 54 45 52 59 5f 53 54 41 54 53 22 2c 30 5d 2c 5b 22 53 4d 41 52 54 5f 53 45 54 55 50 22 2c 30 5d 2c 5b 22 54 52 4f 4e 22 2c 30 5d 5d 2c 2d 33 33 33 34 37 33 37 35 39 34 30 32 34 39 37 31 32 32 35 5d 2c 5b 5d 2c 7b 22 31 37 35 32 33 37 33 37 35 22 3a 5b 31 30 30 30 30 5d 7d 5d 0d 0a
                        Data Ascii: 83["-1",null,[[["ANDROID_BACKUP",0],["BATTERY_STATS",0],["SMART_SETUP",0],["TRON",0]],-3334737594024971225],[],{"175237375":[10000]}]
                        2024-10-07 00:51:54 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        13192.168.2.449783142.250.181.238443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:55 UTC1329OUTPOST /log?format=json&hasfast=true&authuser=0 HTTP/1.1
                        Host: play.google.com
                        Connection: keep-alive
                        Content-Length: 1336
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-arch: "x86"
                        Content-Type: application/x-www-form-urlencoded;charset=UTF-8
                        sec-ch-ua-full-version: "117.0.5938.132"
                        sec-ch-ua-platform-version: "10.0.0"
                        X-Goog-AuthUser: 0
                        sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                        sec-ch-ua-bitness: "64"
                        sec-ch-ua-model: ""
                        sec-ch-ua-wow64: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept: */*
                        Origin: https://accounts.google.com
                        X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                        Sec-Fetch-Site: same-site
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Dest: empty
                        Referer: https://accounts.google.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: NID=518=AHmchaevCiY7OBgWH4iH5MFRTCn_x2cBuqNt4q04EQCLqCRDqsSzUn5g0YWY53gaDuVUBLRrMFtTW40lRvEYspcb1BtCouoFsePxkXJlP1K8qhAQAdhUp3UU6odAoRjTkCsWk6y7jgN_MG9__Id8NkOYXfrojrz7fQxegJiqkOVtMC-djAHiHjKYPw
                        2024-10-07 00:51:55 UTC1336OUTData Raw: 5b 5b 31 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 22 65 6e 22 2c 6e 75 6c 6c 2c 22 33 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 47 6f 6f 67 6c 65 20 43 68 72 6f 6d 65 22 2c 22 31 31 37 22 5d 2c 5b 22 4e 6f 74 3b 41 3d 42 72 61 6e 64 22 2c 22 38 22 5d 2c 5b 22 43 68 72 6f 6d 69 75 6d 22 2c 22 31 31 37 22 5d 5d 2c 30 2c 22 57 69 6e 64 6f 77 73 22 2c 22 31 30 2e 30 2e 30 22 2c 22 78 38 36 22 2c 22 22 2c 22 31 31 37 2e 30 2e 35 39 33 38 2e 31 33 32 22 5d 2c 5b 31 2c 30 2c 30 2c 30 2c 30 5d 5d 5d 2c 31 38 32 38 2c 5b 5b 22 31 37 32 38 32 36 32 33 31 34 34 34 38 22 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c
                        Data Ascii: [[1,null,null,null,null,null,null,null,null,null,[null,null,null,null,"en",null,"31",null,[[["Google Chrome","117"],["Not;A=Brand","8"],["Chromium","117"]],0,"Windows","10.0.0","x86","","117.0.5938.132"],[1,0,0,0,0]]],1828,[["1728262314448",null,null,null
                        2024-10-07 00:51:56 UTC523INHTTP/1.1 200 OK
                        Access-Control-Allow-Origin: https://accounts.google.com
                        Cross-Origin-Resource-Policy: cross-origin
                        Access-Control-Allow-Credentials: true
                        Access-Control-Allow-Headers: X-Playlog-Web
                        Content-Type: text/plain; charset=UTF-8
                        Date: Mon, 07 Oct 2024 00:51:56 GMT
                        Server: Playlog
                        Cache-Control: private
                        X-XSS-Protection: 0
                        X-Frame-Options: SAMEORIGIN
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Accept-Ranges: none
                        Vary: Accept-Encoding
                        Connection: close
                        Transfer-Encoding: chunked
                        2024-10-07 00:51:56 UTC137INData Raw: 38 33 0d 0a 5b 22 2d 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 41 4e 44 52 4f 49 44 5f 42 41 43 4b 55 50 22 2c 30 5d 2c 5b 22 42 41 54 54 45 52 59 5f 53 54 41 54 53 22 2c 30 5d 2c 5b 22 53 4d 41 52 54 5f 53 45 54 55 50 22 2c 30 5d 2c 5b 22 54 52 4f 4e 22 2c 30 5d 5d 2c 2d 33 33 33 34 37 33 37 35 39 34 30 32 34 39 37 31 32 32 35 5d 2c 5b 5d 2c 7b 22 31 37 35 32 33 37 33 37 35 22 3a 5b 31 30 30 30 30 5d 7d 5d 0d 0a
                        Data Ascii: 83["-1",null,[[["ANDROID_BACKUP",0],["BATTERY_STATS",0],["SMART_SETUP",0],["TRON",0]],-3334737594024971225],[],{"175237375":[10000]}]
                        2024-10-07 00:51:56 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination Port
                        14192.168.2.44978413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:51:58 UTC195OUTGET /rules/other-Win32-v19.bundle HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:51:58 UTC540INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:51:58 GMT
                        Content-Type: text/plain
                        Content-Length: 218853
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public
                        Last-Modified: Fri, 04 Oct 2024 23:21:50 GMT
                        ETag: "0x8DCE4CB535A72FA"
                        x-ms-request-id: 4dad204e-401e-005b-4bf5-169c0c000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005158Z-1657d5bbd482tlqpvyz9e93p5400000002w00000000077cn
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:51:58 UTC15844INData Raw: 31 30 30 30 76 35 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 22 20 56 3d 22 35 22 20 44 43 3d 22 45 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 52 75 6c 65 45 72 72 6f 72 73 41 67 67 72 65 67 61 74 65 64 22 20 41 54 54 3d 22 66 39 39 38 63 63 35 62 61 34 64 34 34 38 64 36 61 31 65 38 65 39 31 33 66 66 31 38 62 65 39 34 2d 64 64 31 32 32 65 30 61 2d 66 63 66 38 2d 34 64 63 35 2d 39 64 62 62 2d 36 61 66 61 63 35 33 32 35 31 38 33 2d 37 34 30 35 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 53 3d 22 37 30 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 20 50 53 55 22 20
                        Data Ascii: 1000v5+<?xml version="1.0" encoding="utf-8"?><R Id="1000" V="5" DC="ESM" EN="Office.Telemetry.RuleErrorsAggregated" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" S="70" DL="A" DCa="PSP PSU"
                        2024-10-07 00:51:59 UTC16384INData Raw: 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 42 22 20 49 3d 22 35 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e
                        Data Ascii: "0" /> </L> <R> <V V="400" T="I32" /> </R> </O> </R> </O> </C> <C T="B" I="5" O="false"> <O T="AND"> <L> <O T="GE"> <L> <S T="1" F="0" />
                        2024-10-07 00:51:59 UTC16384INData Raw: 20 20 3c 53 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 53 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 38 32 30 76 33 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 38 32 30 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 43 6f 6e 74 61 63 74 43 61 72 64 50 72 6f 70 65 72 74 69 65 73 43 6f 75 6e 74 73 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31
                        Data Ascii: <ST> <S T="1" /> </ST></R><$!#>10820v3+<?xml version="1.0" encoding="utf-8"?><R Id="10820" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardPropertiesCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-781
                        2024-10-07 00:51:59 UTC16384INData Raw: 20 54 3d 22 55 36 34 22 20 49 3d 22 38 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 45 76 65 6e 74 73 5f 41 76 67 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 41 76 65 72 61 67 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 39 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 41 67 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 30 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20
                        Data Ascii: T="U64" I="8" O="false" N="Events_Avg"> <S T="2" F="Average" /> </C> <C T="U32" I="9" O="true" N="Purged_Age"> <S T="4" F="Count" /> </C> <C T="U32" I="10" O="true" N="Purged_Count"> <S T="5" F="Count" /> </C> <C T="U32"
                        2024-10-07 00:51:59 UTC16384INData Raw: 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 43 61 72 64 5f 56 61 6c 69 64 50 65 72 73 6f 6e 61 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 43 61 72 64 5f 56 61 6c 69 64 4d 61 6e 61 67 65 72 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f
                        Data Ascii: "0" O="false" N="Count_CreateCard_ValidPersona_False"> <C> <S T="10" /> </C> </C> <C T="U32" I="1" O="false" N="Count_CreateCard_ValidManager_False"> <C> <S T="11" /> </C> </C> <C T="U32" I="2" O="false" N="Co
                        2024-10-07 00:51:59 UTC16384INData Raw: 20 20 20 20 3c 53 20 54 3d 22 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 39 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 57 61 73 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a
                        Data Ascii: <S T="31" /> </C> </C> <C T="U32" I="19" O="false" N="Paint_IMsoPersona_WasNull_Count"> <C> <S T="32" /> </C> </C> <C T="U32" I="20" O="false" N="Paint_IMsoPersona_Null_Count"> <C> <S T="33" /> </C>
                        2024-10-07 00:51:59 UTC16384INData Raw: 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 52 65 74 72 69 65 76 61 6c 4d 69 6c 6c 69 73 65 63 6f 6e 64 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 32 30 30 22 20 54 3d 22 49 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 52 65 74 72 69 65 76 61 6c 4d 69 6c 6c 69 73 65 63
                        Data Ascii: <S T="3" F="RetrievalMilliseconds" /> </L> <R> <V V="200" T="I64" /> </R> </O> </L> <R> <O T="LT"> <L> <S T="3" F="RetrievalMillisec
                        2024-10-07 00:51:59 UTC16384INData Raw: 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e 74 65 67 72 61 74 69 6f 6e 46 69 72 73 74 43 61 6c 6c 53 75 63 63 65 73 73 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e
                        Data Ascii: R> <V V="0" T="I32" /> </R> </O> </F> </S> <C T="U32" I="0" O="false" N="Ocom2IUCOfficeIntegrationFirstCallSuccessCount"> <C> <S T="9" /> </C> </C> <C T="U32" I="1" O="false" N="Ocom2IUCOfficeIn
                        2024-10-07 00:51:59 UTC16384INData Raw: 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 36 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 54 65 6e 61 6e 74 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 55 73 65 72 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20
                        Data Ascii: R> </O> </F> <F T="6"> <O T="AND"> <L> <S T="3" F="Tenant enabled" /> </L> <R> <O T="EQ"> <L> <S T="3" F="User enabled" /> </L>
                        2024-10-07 00:51:59 UTC16384INData Raw: 54 3d 22 36 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 48 74 74 70 53 74 61 74 75 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 34 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
                        Data Ascii: T="6"> <O T="EQ"> <L> <S T="2" F="HttpStatus" /> </L> <R> <V V="404" T="U32" /> </R> </O> </F> <F T="7"> <O T="AND"> <L> <O T="GE"> <


                        Session IDSource IPSource PortDestination IPDestination Port
                        15192.168.2.44978713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule120600v4s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 2980
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:10 GMT
                        ETag: "0x8DC582BA80D96A1"
                        x-ms-request-id: 8aaf7b13-d01e-0028-46fd-167896000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd48q6t9vvmrkd293mg00000002s000000000a4gv
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC2980INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 30 22 20 56 3d 22 34 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 44 65 76 69 63 65 43 6f 6e 73 6f 6c 69 64 61 74 65 64 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120600" V="4" DC="SM" EN="Office.System.SystemHealthMetadataDeviceConsolidated" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC"


                        Session IDSource IPSource PortDestination IPDestination Port
                        16192.168.2.44978613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule224902v2s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 450
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:25 GMT
                        ETag: "0x8DC582BD4C869AE"
                        x-ms-request-id: d4448e94-101e-00a2-2703-179f2e000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd48f7nlxc7n5fnfzh000000002e0000000007vu5
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC450INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 32 32 34 39 30 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 62 72 35 71 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 33 22 20 47 3d 22 7b 61 33 36 61 39 37 30 64 2d 34 35 61 39 2d 34 65 30 64 2d 39 63 61 62 2d 32 61 32 33 35 63 63 39 64 37 63 36 7d 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 47 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 4e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="224902" V="2" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120100" /> <UTS T="2" Id="bbr5q" /> <SS T="3" G="{a36a970d-45a9-4e0d-9cab-2a235cc9d7c6}" /> </S> <C T="G" I="0" O="falseN


                        Session IDSource IPSource PortDestination IPDestination Port
                        17192.168.2.44978513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC193OUTGET /rules/rule120402v21s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 3788
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
                        ETag: "0x8DC582BAC2126A6"
                        x-ms-request-id: 4545068c-701e-0050-0e05-176767000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd487nf59mzf5b3gk8n00000002g0000000000bpb
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC3788INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 34 30 32 22 20 56 3d 22 32 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 55 6e 67 72 61 63 65 66 75 6c 41 70 70 45 78 69 74 44 65 73 6b 74 6f 70 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 43 65 6e 73 75 73 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 22 20 78 6d 6c 6e 73 3d 22 22
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120402" V="21" DC="SM" EN="Office.System.SystemHealthUngracefulAppExitDesktop" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSP" xmlns=""


                        Session IDSource IPSource PortDestination IPDestination Port
                        18192.168.2.44978813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule120608v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 2160
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                        ETag: "0x8DC582BA3B95D81"
                        x-ms-request-id: c59bb0f9-701e-0097-2d01-17b8c1000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd48qjg85buwfdynm5w00000002yg000000000n6m
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC2160INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 37 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 33 22 20 52 3d 22 31 32 30 36 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 34 22 20 52 3d 22 31 32 30 36 31 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 35 22 20 52 3d 22 31 32 30 36 31 34 22 20 2f 3e 0d 0a 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120608" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <R T="1" R="120609" /> <R T="2" R="120679" /> <R T="3" R="120610" /> <R T="4" R="120612" /> <R T="5" R="120614" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        19192.168.2.44978913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule120609v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 408
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                        ETag: "0x8DC582BB56D3AFB"
                        x-ms-request-id: b27588a3-a01e-003d-6001-1798d7000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd48p2j6x2quer0q02800000002z000000000ayyk
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 38 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 44 64 5d 5b 45 65 5d 5b 4c 6c 5d 5b 4c 6c 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120609" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120682" /> <SR T="2" R="^([Dd][Ee][Ll][Ll])"> <S T="1" F="0" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                        Session IDSource IPSource PortDestination IPDestination Port
                        20192.168.2.44979113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule120611v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 415
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:56 GMT
                        ETag: "0x8DC582B9F6F3512"
                        x-ms-request-id: 1707b783-801e-00a3-53e5-167cfb000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd48vhs7r2p1ky7cs5w000000031g00000000ft2m
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4c 6c 5d 5b 45 65 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 56 76 5d 5b 4f 6f 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120611" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <SR T="2" R="([Ll][Ee][Nn][Oo][Vv][Oo])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                        Session IDSource IPSource PortDestination IPDestination Port
                        21192.168.2.44979213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule120612v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 471
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:25 GMT
                        ETag: "0x8DC582BB10C598B"
                        x-ms-request-id: 73fc0cc0-d01e-008e-5fee-16387a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd48qjg85buwfdynm5w00000002s000000000tw5w
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120612" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        22192.168.2.44979313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule120613v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 632
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                        ETag: "0x8DC582BB6E3779E"
                        x-ms-request-id: 15158de7-401e-0029-4b00-179b43000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd482lxwq1dp2t1zwkc00000002dg00000000rha5
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC632INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 48 68 5d 5b 50 70 5d 28 5b 5e 45 5d 7c 24 29 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 33 22 20 52 3d 22 28 5b 48 68 5d 5b 45 65 5d 5b 57 77 5d 5b 4c 6c 5d 5b 45 65 5d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120613" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <SR T="2" R="^([Hh][Pp]([^E]|$))"> <S T="1" F="1" M="Ignore" /> </SR> <SR T="3" R="([Hh][Ee][Ww][Ll][Ee]


                        Session IDSource IPSource PortDestination IPDestination Port
                        23192.168.2.44979013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule120610v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 474
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:46 GMT
                        ETag: "0x8DC582B9964B277"
                        x-ms-request-id: 3ea0840d-701e-0053-1012-173a0a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd48xlwdx82gahegw4000000002yg00000000bz7s
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120610" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        24192.168.2.44979413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:00 UTC192OUTGET /rules/rule120614v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:00 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:00 GMT
                        Content-Type: text/xml
                        Content-Length: 467
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:08 GMT
                        ETag: "0x8DC582BA6C038BC"
                        x-ms-request-id: 87fc294c-201e-0051-40f3-167340000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005200Z-1657d5bbd482lxwq1dp2t1zwkc00000002cg00000000v6x6
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:00 UTC467INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120614" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        25192.168.2.44979513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:01 UTC192OUTGET /rules/rule120615v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:01 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:01 GMT
                        Content-Type: text/xml
                        Content-Length: 407
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:42 GMT
                        ETag: "0x8DC582BBAD04B7B"
                        x-ms-request-id: 789c8418-601e-0032-5905-17eebb000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005201Z-1657d5bbd48jwrqbupe3ktsx9w00000003100000000044vt
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:01 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 53 73 5d 5b 55 75 5d 5b 53 73 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120615" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <SR T="2" R="([Aa][Ss][Uu][Ss])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                        Session IDSource IPSource PortDestination IPDestination Port
                        26192.168.2.44979913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:01 UTC192OUTGET /rules/rule120619v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:01 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:01 GMT
                        Content-Type: text/xml
                        Content-Length: 407
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:41 GMT
                        ETag: "0x8DC582B9698189B"
                        x-ms-request-id: 99ffd5e0-b01e-0053-0101-17cdf8000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005201Z-1657d5bbd48sdh4cyzadbb374800000002gg00000000p1c9
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:01 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 43 63 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120619" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <SR T="2" R="([Aa][Cc][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                        Session IDSource IPSource PortDestination IPDestination Port
                        27192.168.2.44979613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:01 UTC192OUTGET /rules/rule120616v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:01 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:01 GMT
                        Content-Type: text/xml
                        Content-Length: 486
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                        ETag: "0x8DC582BB344914B"
                        x-ms-request-id: 0a3893d3-c01e-0082-33ee-16af72000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005201Z-1657d5bbd48tnj6wmberkg2xy800000002sg00000000nyuf
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:01 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120616" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        28192.168.2.44979813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:01 UTC192OUTGET /rules/rule120618v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:01 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:01 GMT
                        Content-Type: text/xml
                        Content-Length: 486
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:30 GMT
                        ETag: "0x8DC582B9018290B"
                        x-ms-request-id: bf7deccb-401e-0064-0f0e-1754af000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005201Z-1657d5bbd48cpbzgkvtewk0wu000000002y0000000001bg2
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:01 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120618" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        29192.168.2.44979713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:01 UTC192OUTGET /rules/rule120617v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:01 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:01 GMT
                        Content-Type: text/xml
                        Content-Length: 427
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:02 GMT
                        ETag: "0x8DC582BA310DA18"
                        x-ms-request-id: 915c1ee4-001e-0079-3000-1712e8000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005201Z-1657d5bbd48p2j6x2quer0q02800000002zg0000000087x3
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:01 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 5b 53 73 5d 5b 4f 6f 5d 5b 46 66 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120617" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo][Ss][Oo][Ff][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                        Session IDSource IPSource PortDestination IPDestination Port
                        30192.168.2.44980113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:02 UTC192OUTGET /rules/rule120622v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:02 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:02 GMT
                        Content-Type: text/xml
                        Content-Length: 477
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
                        ETag: "0x8DC582BB8CEAC16"
                        x-ms-request-id: c2d0a885-201e-0003-7ced-16f85a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005202Z-1657d5bbd48tqvfc1ysmtbdrg000000002qg000000002v7f
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:02 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120622" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        31192.168.2.44980313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:02 UTC192OUTGET /rules/rule120624v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:02 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:02 GMT
                        Content-Type: text/xml
                        Content-Length: 494
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                        ETag: "0x8DC582BB7010D66"
                        x-ms-request-id: d3d0b776-b01e-003d-1803-17d32c000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005202Z-1657d5bbd48xlwdx82gahegw4000000002yg00000000bzbv
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:02 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120624" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        32192.168.2.44980213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:02 UTC192OUTGET /rules/rule120620v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:02 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:02 GMT
                        Content-Type: text/xml
                        Content-Length: 469
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                        ETag: "0x8DC582BBA701121"
                        x-ms-request-id: e72ec3ca-501e-005b-2401-17d7f7000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005202Z-1657d5bbd48xlwdx82gahegw4000000002yg00000000bzbw
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:02 UTC469INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120620" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        33192.168.2.44980013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:02 UTC192OUTGET /rules/rule120621v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:02 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:02 GMT
                        Content-Type: text/xml
                        Content-Length: 415
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                        ETag: "0x8DC582BA41997E3"
                        x-ms-request-id: 27ba9a72-001e-0046-2a01-17da4b000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005202Z-1657d5bbd482krtfgrg72dfbtn00000002k00000000057bk
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:02 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 56 76 5d 5b 4d 6d 5d 5b 57 77 5d 5b 41 61 5d 5b 52 72 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120621" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <SR T="2" R="([Vv][Mm][Ww][Aa][Rr][Ee])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                        Session IDSource IPSource PortDestination IPDestination Port
                        34192.168.2.44980413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:02 UTC192OUTGET /rules/rule120623v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:02 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:02 GMT
                        Content-Type: text/xml
                        Content-Length: 464
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:43 GMT
                        ETag: "0x8DC582B97FB6C3C"
                        x-ms-request-id: 5a59384b-a01e-0053-3602-178603000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005202Z-1657d5bbd48tnj6wmberkg2xy800000002x0000000004rma
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:02 UTC464INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 47 67 5d 5b 49 69 5d 5b 47 67 5d 5b 41 61 5d 5b 42 62 5d 5b 59 79 5d 5b 54 74 5d 5b 45 65 5d 20 5b 54 74 5d 5b 45 65 5d 5b 43 63 5d 5b 48 68 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 4c 6c 5d 5b 4f 6f 5d 5b 47 67 5d 5b 59 79 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120623" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <SR T="2" R="([Gg][Ii][Gg][Aa][Bb][Yy][Tt][Ee] [Tt][Ee][Cc][Hh][Nn][Oo][Ll][Oo][Gg][Yy])"> <S T="1" F="1" M="Ignor


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        35192.168.2.4498054.175.87.197443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:02 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=gs1szRCNStTUBPy&MD=nnK7C6a5 HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                        Host: slscr.update.microsoft.com
                        2024-10-07 00:52:03 UTC560INHTTP/1.1 200 OK
                        Cache-Control: no-cache
                        Pragma: no-cache
                        Content-Type: application/octet-stream
                        Expires: -1
                        Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                        ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                        MS-CorrelationId: 9b53cdce-6dc8-4f58-abe6-e79a70f9444b
                        MS-RequestId: f3e317a1-389a-4731-a169-fa8a0550a6e5
                        MS-CV: FKeYsoKEA0aOsZjy.0
                        X-Microsoft-SLSClientCache: 1440
                        Content-Disposition: attachment; filename=environment.cab
                        X-Content-Type-Options: nosniff
                        Date: Mon, 07 Oct 2024 00:52:02 GMT
                        Connection: close
                        Content-Length: 30005
                        2024-10-07 00:52:03 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                        Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                        2024-10-07 00:52:03 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                        Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                        Session IDSource IPSource PortDestination IPDestination Port
                        36192.168.2.44980613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:03 UTC192OUTGET /rules/rule120625v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:03 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:03 GMT
                        Content-Type: text/xml
                        Content-Length: 419
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:42 GMT
                        ETag: "0x8DC582B9748630E"
                        x-ms-request-id: 09392ef7-101e-0046-3f05-1791b0000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005203Z-1657d5bbd482tlqpvyz9e93p5400000002v000000000c8yq
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:03 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 46 66 5d 5b 55 75 5d 5b 4a 6a 5d 5b 49 69 5d 5b 54 74 5d 5b 53 73 5d 5b 55 75 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120625" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <SR T="2" R="([Ff][Uu][Jj][Ii][Tt][Ss][Uu])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                        Session IDSource IPSource PortDestination IPDestination Port
                        37192.168.2.44980913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:03 UTC192OUTGET /rules/rule120628v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:03 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:03 GMT
                        Content-Type: text/xml
                        Content-Length: 468
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:51 GMT
                        ETag: "0x8DC582B9C8E04C8"
                        x-ms-request-id: 81e42967-c01e-0014-5ee9-16a6a3000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005203Z-1657d5bbd48tqvfc1ysmtbdrg000000002pg000000006be1
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:03 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120628" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        38192.168.2.44981013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:03 UTC192OUTGET /rules/rule120629v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:03 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:03 GMT
                        Content-Type: text/xml
                        Content-Length: 428
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
                        ETag: "0x8DC582BAC4F34CA"
                        x-ms-request-id: 6be05283-001e-00a2-2700-17d4d5000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005203Z-1657d5bbd482tlqpvyz9e93p5400000002r000000000ut4t
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:03 UTC428INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 2d 5b 53 73 5d 5b 54 74 5d 5b 41 61 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120629" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo]-[Ss][Tt][Aa][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                        Session IDSource IPSource PortDestination IPDestination Port
                        39192.168.2.44980713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:03 UTC192OUTGET /rules/rule120626v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:03 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:03 GMT
                        Content-Type: text/xml
                        Content-Length: 472
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:53 GMT
                        ETag: "0x8DC582B9DACDF62"
                        x-ms-request-id: 20b36261-201e-006e-7102-17bbe3000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005203Z-1657d5bbd48vlsxxpe15ac3q7n00000002p000000000msph
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:03 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120626" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        40192.168.2.44980813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:03 UTC192OUTGET /rules/rule120627v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:03 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:03 GMT
                        Content-Type: text/xml
                        Content-Length: 404
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:54 GMT
                        ETag: "0x8DC582B9E8EE0F3"
                        x-ms-request-id: f57b7c9f-801e-00a0-4a13-172196000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005203Z-1657d5bbd482tlqpvyz9e93p5400000002x000000000551r
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:03 UTC404INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4e 6e 5d 5b 45 65 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120627" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <SR T="2" R="^([Nn][Ee][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S


                        Session IDSource IPSource PortDestination IPDestination Port
                        41192.168.2.44981113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:03 UTC192OUTGET /rules/rule120630v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:03 GMT
                        Content-Type: text/xml
                        Content-Length: 499
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:45 GMT
                        ETag: "0x8DC582B98CEC9F6"
                        x-ms-request-id: 40323690-a01e-0002-0100-175074000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005203Z-1657d5bbd48qjg85buwfdynm5w00000002yg000000000nmd
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC499INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120630" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        42192.168.2.44981213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:03 UTC192OUTGET /rules/rule120631v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 415
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                        ETag: "0x8DC582B988EBD12"
                        x-ms-request-id: c530354f-501e-0016-5013-17181b000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd48762wn1qw4s5sd3000000002k000000000nr3h
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 48 68 5d 5b 55 75 5d 5b 41 61 5d 5b 57 77 5d 5b 45 65 5d 5b 49 69 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120631" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <SR T="2" R="([Hh][Uu][Aa][Ww][Ee][Ii])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                        Session IDSource IPSource PortDestination IPDestination Port
                        43192.168.2.44981413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:04 UTC192OUTGET /rules/rule120633v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 419
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                        ETag: "0x8DC582BB32BB5CB"
                        x-ms-request-id: d415a278-e01e-0051-6efe-1684b2000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd48sdh4cyzadbb374800000002g000000000ruwx
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 53 73 5d 5b 41 61 5d 5b 4d 6d 5d 5b 53 73 5d 5b 55 75 5d 5b 4e 6e 5d 5b 47 67 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120633" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <SR T="2" R="([Ss][Aa][Mm][Ss][Uu][Nn][Gg])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                        Session IDSource IPSource PortDestination IPDestination Port
                        44192.168.2.44981313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:04 UTC192OUTGET /rules/rule120632v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 471
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                        ETag: "0x8DC582BB5815C4C"
                        x-ms-request-id: 7cec3a6f-e01e-0033-3414-174695000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd48brl8we3nu8cxwgn00000002yg00000000uqnp
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120632" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        45192.168.2.44981513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:04 UTC192OUTGET /rules/rule120634v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 494
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
                        ETag: "0x8DC582BB8972972"
                        x-ms-request-id: 688d2aae-a01e-0084-3466-179ccd000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd48dfrdj7px744zp8s00000002m0000000002chg
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120634" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120633" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        46192.168.2.44981613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:04 UTC192OUTGET /rules/rule120635v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 420
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:53 GMT
                        ETag: "0x8DC582B9DAE3EC0"
                        x-ms-request-id: 4c0632d0-601e-0097-4413-17f33a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd482tlqpvyz9e93p5400000002t000000000kfr9
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC420INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 54 74 5d 5b 4f 6f 5d 5b 53 73 5d 5b 48 68 5d 5b 49 69 5d 5b 42 62 5d 5b 41 61 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120635" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120633" /> <SR T="2" R="^([Tt][Oo][Ss][Hh][Ii][Bb][Aa])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O


                        Session IDSource IPSource PortDestination IPDestination Port
                        47192.168.2.44981713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:04 UTC192OUTGET /rules/rule120636v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 472
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:52 GMT
                        ETag: "0x8DC582B9D43097E"
                        x-ms-request-id: b27116a7-a01e-003d-3a00-1798d7000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd48sqtlf1huhzuwq7000000002c000000000v1zn
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120636" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120635" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        48192.168.2.44981813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:04 UTC192OUTGET /rules/rule120637v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 427
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:12 GMT
                        ETag: "0x8DC582BA909FA21"
                        x-ms-request-id: a62739ea-301e-005d-6402-17e448000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd48q6t9vvmrkd293mg00000002s000000000a4th
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 41 61 5d 5b 4e 6e 5d 5b 41 61 5d 5b 53 73 5d 5b 4f 6f 5d 5b 4e 6e 5d 5b 49 69 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120637" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120635" /> <SR T="2" R="([Pp][Aa][Nn][Aa][Ss][Oo][Nn][Ii][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                        Session IDSource IPSource PortDestination IPDestination Port
                        49192.168.2.44982013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:04 UTC192OUTGET /rules/rule120639v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 423
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:36 GMT
                        ETag: "0x8DC582BB7564CE8"
                        x-ms-request-id: a2d01d3c-801e-0083-4800-17f0ae000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd48qjg85buwfdynm5w00000002v000000000cwkg
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC423INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 44 64 5d 5b 59 79 5d 5b 4e 6e 5d 5b 41 61 5d 5b 42 62 5d 5b 4f 6f 5d 5b 4f 6f 5d 5b 4b 6b 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120639" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120637" /> <SR T="2" R="([Dd][Yy][Nn][Aa][Bb][Oo][Oo][Kk])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0


                        Session IDSource IPSource PortDestination IPDestination Port
                        50192.168.2.44981913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:04 UTC192OUTGET /rules/rule120638v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:04 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:04 GMT
                        Content-Type: text/xml
                        Content-Length: 486
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:35 GMT
                        ETag: "0x8DC582B92FCB436"
                        x-ms-request-id: b8f8ddc8-601e-0001-115a-17faeb000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005204Z-1657d5bbd48sdh4cyzadbb374800000002mg00000000b1ex
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:04 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120638" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120637" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        51192.168.2.44982113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:05 UTC192OUTGET /rules/rule120640v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:05 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:05 GMT
                        Content-Type: text/xml
                        Content-Length: 478
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:48 GMT
                        ETag: "0x8DC582B9B233827"
                        x-ms-request-id: 4dd19665-401e-005b-7705-179c0c000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005205Z-1657d5bbd48t66tjar5xuq22r800000002sg000000008zmp
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:05 UTC478INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120640" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120639" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        52192.168.2.44982213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:05 UTC192OUTGET /rules/rule120641v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:05 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:05 GMT
                        Content-Type: text/xml
                        Content-Length: 404
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:39 GMT
                        ETag: "0x8DC582B95C61A3C"
                        x-ms-request-id: 151ca1e1-401e-0029-2b03-179b43000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005205Z-1657d5bbd48xdq5dkwwugdpzr0000000033g000000008m59
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:05 UTC404INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4d 6d 5d 5b 53 73 5d 5b 49 69 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120641" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120639" /> <SR T="2" R="^([Mm][Ss][Ii])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S


                        Session IDSource IPSource PortDestination IPDestination Port
                        53192.168.2.44982313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:05 UTC192OUTGET /rules/rule120642v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:05 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:05 GMT
                        Content-Type: text/xml
                        Content-Length: 468
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:24 GMT
                        ETag: "0x8DC582BB046B576"
                        x-ms-request-id: db28b7eb-d01e-0065-5efe-16b77a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005205Z-1657d5bbd48t66tjar5xuq22r800000002ug000000001are
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:05 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120642" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120641" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        54192.168.2.44982413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:05 UTC192OUTGET /rules/rule120643v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:05 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:05 GMT
                        Content-Type: text/xml
                        Content-Length: 400
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:28 GMT
                        ETag: "0x8DC582BB2D62837"
                        x-ms-request-id: 11b227e2-601e-0002-7f6b-17a786000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005205Z-1657d5bbd482lxwq1dp2t1zwkc00000002hg000000007fwv
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:05 UTC400INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4c 6c 5d 5b 47 67 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120643" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120641" /> <SR T="2" R="^([Ll][Gg])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S T="


                        Session IDSource IPSource PortDestination IPDestination Port
                        55192.168.2.44982513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:05 UTC192OUTGET /rules/rule120644v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:05 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:05 GMT
                        Content-Type: text/xml
                        Content-Length: 479
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:37 GMT
                        ETag: "0x8DC582BB7D702D0"
                        x-ms-request-id: 1be548a6-001e-00a2-4166-17d4d5000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005205Z-1657d5bbd48lknvp09v995n79000000002d000000000au63
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:05 UTC479INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120644" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120643" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        56192.168.2.44982613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:06 UTC192OUTGET /rules/rule120645v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:06 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:06 GMT
                        Content-Type: text/xml
                        Content-Length: 425
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:40 GMT
                        ETag: "0x8DC582BBA25094F"
                        x-ms-request-id: 7709e3c3-b01e-0097-5e02-174f33000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005206Z-1657d5bbd48vlsxxpe15ac3q7n00000002n000000000rcwv
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:06 UTC425INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 4d 6d 5d 5b 41 61 5d 5b 5a 7a 5d 5b 4f 6f 5d 5b 4e 6e 5d 20 5b 45 65 5d 5b 43 63 5d 32 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120645" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120643" /> <SR T="2" R="([Aa][Mm][Aa][Zz][Oo][Nn] [Ee][Cc]2)"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I=


                        Session IDSource IPSource PortDestination IPDestination Port
                        57192.168.2.44982713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:06 UTC192OUTGET /rules/rule120646v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:06 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:06 GMT
                        Content-Type: text/xml
                        Content-Length: 475
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:28 GMT
                        ETag: "0x8DC582BB2BE84FD"
                        x-ms-request-id: c5dbf9be-001e-0017-2cf1-160c3c000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005206Z-1657d5bbd48sdh4cyzadbb374800000002m000000000dhvc
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:06 UTC475INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120646" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120645" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        58192.168.2.44983013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:06 UTC192OUTGET /rules/rule120649v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:06 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:06 GMT
                        Content-Type: text/xml
                        Content-Length: 416
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:21 GMT
                        ETag: "0x8DC582BAEA4B445"
                        x-ms-request-id: cb78c1b2-201e-003f-2e04-176d94000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005206Z-1657d5bbd48brl8we3nu8cxwgn000000035g000000000huu
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:06 UTC416INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 46 66 5d 5b 45 65 5d 5b 44 64 5d 5b 4f 6f 5d 5b 52 72 5d 5b 41 61 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120649" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120647" /> <SR T="2" R="^([Ff][Ee][Dd][Oo][Rr][Aa])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tr


                        Session IDSource IPSource PortDestination IPDestination Port
                        59192.168.2.44982813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:06 UTC192OUTGET /rules/rule120647v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:06 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:06 GMT
                        Content-Type: text/xml
                        Content-Length: 448
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                        ETag: "0x8DC582BB389F49B"
                        x-ms-request-id: 5a5a1e5c-a01e-001e-18f5-1649ef000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005206Z-1657d5bbd48qjg85buwfdynm5w00000002tg00000000maye
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:06 UTC448INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 50 70 5d 5b 41 61 5d 5b 43 63 5d 5b 48 68 5d 5b 45 65 5d 20 5b 53 73 5d 5b 4f 6f 5d 5b 46 66 5d 5b 54 74 5d 5b 57 77 5d 5b 41 61 5d 5b 52 72 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120647" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120645" /> <SR T="2" R="([Aa][Pp][Aa][Cc][Hh][Ee] [Ss][Oo][Ff][Tt][Ww][Aa][Rr][Ee])"> <S T="1" F="1" M="Ignore" /> </SR>


                        Session IDSource IPSource PortDestination IPDestination Port
                        60192.168.2.44982913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:06 UTC192OUTGET /rules/rule120648v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:06 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:06 GMT
                        Content-Type: text/xml
                        Content-Length: 491
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                        ETag: "0x8DC582B98B88612"
                        x-ms-request-id: 721d8bd8-801e-002a-4f00-1731dc000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005206Z-1657d5bbd48t66tjar5xuq22r800000002rg00000000c99e
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:06 UTC491INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120648" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120647" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        61192.168.2.44983213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120651v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 415
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:10 GMT
                        ETag: "0x8DC582BA80D96A1"
                        x-ms-request-id: 04801829-801e-00ac-6301-17fd65000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd48p2j6x2quer0q02800000002vg00000000qgcd
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 47 67 5d 5b 4f 6f 5d 5b 4f 6f 5d 5b 47 67 5d 5b 4c 6c 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120651" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120649" /> <SR T="2" R="([Gg][Oo][Oo][Gg][Ll][Ee])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                        Session IDSource IPSource PortDestination IPDestination Port
                        62192.168.2.44983413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120653v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 419
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:51 GMT
                        ETag: "0x8DC582B9C710B28"
                        x-ms-request-id: 1ed82642-401e-0048-7b12-170409000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd482lxwq1dp2t1zwkc00000002g000000000dvh4
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 49 69 5d 5b 4e 6e 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 54 74 5d 5b 45 65 5d 5b 4b 6b 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120653" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120651" /> <SR T="2" R="([Ii][Nn][Nn][Oo][Tt][Ee][Kk])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                        Session IDSource IPSource PortDestination IPDestination Port
                        63192.168.2.44983313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120652v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 471
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:43 GMT
                        ETag: "0x8DC582B97E6FCDD"
                        x-ms-request-id: 2f3972b1-401e-0035-1b02-1782d8000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd48vhs7r2p1ky7cs5w000000030000000000nwuu
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120652" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120651" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        64192.168.2.44983113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120650v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 479
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                        ETag: "0x8DC582B989EE75B"
                        x-ms-request-id: 27b6de9f-001e-0046-1e00-17da4b000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd48jwrqbupe3ktsx9w00000003200000000009p0
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC479INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120650" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120649" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        65192.168.2.44983513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120654v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 477
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:05 GMT
                        ETag: "0x8DC582BA54DCC28"
                        x-ms-request-id: cde3aec9-601e-0084-63e5-166b3f000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd48dfrdj7px744zp8s00000002mg000000000srn
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120654" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120653" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        66192.168.2.44983613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120655v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 419
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:37 GMT
                        ETag: "0x8DC582BB7F164C3"
                        x-ms-request-id: 3a03d6b9-d01e-0066-52e9-16ea17000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd48tnj6wmberkg2xy800000002u000000000fvay
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4e 6e 5d 5b 49 69 5d 5b 4d 6d 5d 5b 42 62 5d 5b 4f 6f 5d 5b 58 78 5d 5b 58 78 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120655" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120653" /> <SR T="2" R="([Nn][Ii][Mm][Bb][Oo][Xx][Xx])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                        Session IDSource IPSource PortDestination IPDestination Port
                        67192.168.2.44983913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120657v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 419
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:57 GMT
                        ETag: "0x8DC582B9FF95F80"
                        x-ms-request-id: 46a5aa72-701e-0032-6004-17a540000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd48tnj6wmberkg2xy800000002xg000000003ctu
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4e 6e 5d 5b 55 75 5d 5b 54 74 5d 5b 41 61 5d 5b 4e 6e 5d 5b 49 69 5d 5b 58 78 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120657" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120655" /> <SR T="2" R="([Nn][Uu][Tt][Aa][Nn][Ii][Xx])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                        Session IDSource IPSource PortDestination IPDestination Port
                        68192.168.2.44983813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120658v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 472
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:34 GMT
                        ETag: "0x8DC582BB650C2EC"
                        x-ms-request-id: d803a4ff-401e-0083-3904-17075c000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd482tlqpvyz9e93p5400000002r000000000utc4
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120658" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120657" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        69192.168.2.44984013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120659v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:07 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 468
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                        ETag: "0x8DC582BB3EAF226"
                        x-ms-request-id: b0fdb72d-401e-0015-37ce-160e8d000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd48jwrqbupe3ktsx9w00000002z000000000avw9
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:07 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4f 6f 5d 5b 50 70 5d 5b 45 65 5d 5b 4e 6e 5d 5b 53 73 5d 5b 54 74 5d 5b 41 61 5d 5b 43 63 5d 5b 4b 6b 5d 20 5b 46 66 5d 5b 4f 6f 5d 5b 55 75 5d 5b 4e 6e 5d 5b 44 64 5d 5b 41 61 5d 5b 54 74 5d 5b 49 69 5d 5b 4f 6f 5d 5b 4e 6e 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120659" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120657" /> <SR T="2" R="([Oo][Pp][Ee][Nn][Ss][Tt][Aa][Cc][Kk] [Ff][Oo][Uu][Nn][Dd][Aa][Tt][Ii][Oo][Nn])"> <S T="1" F="1" M="I


                        Session IDSource IPSource PortDestination IPDestination Port
                        70192.168.2.44983713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:07 UTC192OUTGET /rules/rule120656v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:08 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:07 GMT
                        Content-Type: text/xml
                        Content-Length: 477
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                        ETag: "0x8DC582BA48B5BDD"
                        x-ms-request-id: 678513bd-b01e-0053-4460-17cdf8000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005207Z-1657d5bbd48762wn1qw4s5sd3000000002pg000000006av9
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:08 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120656" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120655" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        71192.168.2.44984113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:08 UTC192OUTGET /rules/rule120660v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:08 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:08 GMT
                        Content-Type: text/xml
                        Content-Length: 485
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:39 GMT
                        ETag: "0x8DC582BB9769355"
                        x-ms-request-id: 8d3bec0a-601e-0070-32fe-16a0c9000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005208Z-1657d5bbd48q6t9vvmrkd293mg00000002n000000000ts57
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:08 UTC485INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120660" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120659" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        72192.168.2.44984213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:08 UTC192OUTGET /rules/rule120661v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:08 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:08 GMT
                        Content-Type: text/xml
                        Content-Length: 411
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                        ETag: "0x8DC582B989AF051"
                        x-ms-request-id: 8d044b15-901e-00ac-3902-17b69e000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005208Z-1657d5bbd48sqtlf1huhzuwq7000000002f000000000g8s4
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:08 UTC411INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4f 6f 5d 5b 56 76 5d 5b 49 69 5d 5b 52 72 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120661" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120659" /> <SR T="2" R="([Oo][Vv][Ii][Rr][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                        Session IDSource IPSource PortDestination IPDestination Port
                        73192.168.2.44984413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:08 UTC192OUTGET /rules/rule120663v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:08 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:08 GMT
                        Content-Type: text/xml
                        Content-Length: 427
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:32 GMT
                        ETag: "0x8DC582BB556A907"
                        x-ms-request-id: 0377c3fc-101e-000b-65dc-165e5c000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005208Z-1657d5bbd48cpbzgkvtewk0wu000000002wg000000007gax
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:08 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 41 61 5d 5b 52 72 5d 5b 41 61 5d 5b 4c 6c 5d 5b 4c 6c 5d 5b 45 65 5d 5b 4c 6c 5d 5b 53 73 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120663" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120661" /> <SR T="2" R="([Pp][Aa][Rr][Aa][Ll][Ll][Ee][Ll][Ss])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                        Session IDSource IPSource PortDestination IPDestination Port
                        74192.168.2.44984313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:08 UTC192OUTGET /rules/rule120662v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:08 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:08 GMT
                        Content-Type: text/xml
                        Content-Length: 470
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:42 GMT
                        ETag: "0x8DC582BBB181F65"
                        x-ms-request-id: e72b6989-501e-005b-2b00-17d7f7000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005208Z-1657d5bbd48tqvfc1ysmtbdrg000000002kg00000000hddu
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:08 UTC470INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120662" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120661" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        75192.168.2.44984513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:08 UTC192OUTGET /rules/rule120664v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:08 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:08 GMT
                        Content-Type: text/xml
                        Content-Length: 502
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                        ETag: "0x8DC582BB6A0D312"
                        x-ms-request-id: a5e58c1d-b01e-00ab-5ac9-16dafd000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005208Z-1657d5bbd48dfrdj7px744zp8s00000002e000000000p149
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:08 UTC502INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120664" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120663" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        76192.168.2.44984613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:09 UTC192OUTGET /rules/rule120665v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:09 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:09 GMT
                        Content-Type: text/xml
                        Content-Length: 407
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:52 GMT
                        ETag: "0x8DC582B9D30478D"
                        x-ms-request-id: 78a0432a-701e-001e-1805-17f5e6000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005209Z-1657d5bbd48xlwdx82gahegw4000000002xg00000000fs5n
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:09 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 53 73 5d 5b 53 73 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120665" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120663" /> <SR T="2" R="([Pp][Ss][Ss][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                        Session IDSource IPSource PortDestination IPDestination Port
                        77192.168.2.44984713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:09 UTC192OUTGET /rules/rule120666v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:09 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:09 GMT
                        Content-Type: text/xml
                        Content-Length: 474
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                        ETag: "0x8DC582BB3F48DAE"
                        x-ms-request-id: ef9cab6f-f01e-0099-0d00-179171000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005209Z-1657d5bbd48brl8we3nu8cxwgn00000003500000000026xe
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:09 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120666" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120665" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        78192.168.2.44985013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:09 UTC192OUTGET /rules/rule120669v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:09 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:09 GMT
                        Content-Type: text/xml
                        Content-Length: 416
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:32 GMT
                        ETag: "0x8DC582BB5284CCE"
                        x-ms-request-id: 821e4157-c01e-0014-3301-17a6a3000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005209Z-1657d5bbd48xdq5dkwwugdpzr0000000030000000000qey1
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:09 UTC416INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 52 72 5d 5b 45 65 5d 5b 44 64 5d 20 5b 48 68 5d 5b 41 61 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120669" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120667" /> <SR T="2" R="([Rr][Ee][Dd] [Hh][Aa][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tr


                        Session IDSource IPSource PortDestination IPDestination Port
                        79192.168.2.44984813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:09 UTC192OUTGET /rules/rule120667v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:09 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:09 GMT
                        Content-Type: text/xml
                        Content-Length: 408
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:40 GMT
                        ETag: "0x8DC582BB9B6040B"
                        x-ms-request-id: 2f519f63-901e-0016-75ff-16efe9000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005209Z-1657d5bbd48vhs7r2p1ky7cs5w0000000340000000005yca
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:09 UTC408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 51 71 5d 5b 45 65 5d 5b 4d 6d 5d 5b 55 75 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120667" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120665" /> <SR T="2" R="^([Qq][Ee][Mm][Uu])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                        Session IDSource IPSource PortDestination IPDestination Port
                        80192.168.2.44984913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:09 UTC192OUTGET /rules/rule120668v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:09 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:09 GMT
                        Content-Type: text/xml
                        Content-Length: 469
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                        ETag: "0x8DC582BB3CAEBB8"
                        x-ms-request-id: b67c2655-301e-0096-2300-17e71d000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005209Z-1657d5bbd48brl8we3nu8cxwgn000000032000000000ckyg
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:09 UTC469INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120668" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120667" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        81192.168.2.44985113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120670v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:10 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 472
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:33 GMT
                        ETag: "0x8DC582B91EAD002"
                        x-ms-request-id: 763e8d43-601e-000d-6912-172618000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48p2j6x2quer0q02800000002z000000000b08u
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:10 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120670" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120669" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        82192.168.2.44985213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120671v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:10 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 432
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:15 GMT
                        ETag: "0x8DC582BAABA2A10"
                        x-ms-request-id: bfab55ab-401e-0015-6202-170e8d000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48t66tjar5xuq22r800000002u0000000003zzh
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:10 UTC432INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 53 73 5d 5b 55 75 5d 5b 50 70 5d 5b 45 65 5d 5b 52 72 5d 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120671" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120669" /> <SR T="2" R="^([Ss][Uu][Pp][Ee][Rr][Mm][Ii][Cc][Rr][Oo])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T


                        Session IDSource IPSource PortDestination IPDestination Port
                        83192.168.2.44985313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120672v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:10 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 475
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                        ETag: "0x8DC582BBA740822"
                        x-ms-request-id: 01bf113a-f01e-003c-3703-178cf0000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48762wn1qw4s5sd3000000002qg000000002tby
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:10 UTC475INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120672" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120671" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        84192.168.2.44985413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120673v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:10 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 427
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:31 GMT
                        ETag: "0x8DC582BB464F255"
                        x-ms-request-id: 7875ffac-201e-000c-7f02-1779c4000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48p2j6x2quer0q02800000002zg0000000088nq
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:10 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 54 74 5d 5b 48 68 5d 5b 49 69 5d 5b 4e 6e 5d 5b 50 70 5d 5b 55 75 5d 5b 54 74 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120673" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120671" /> <SR T="2" R="([Tt][Hh][Ii][Nn][Pp][Uu][Tt][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                        Session IDSource IPSource PortDestination IPDestination Port
                        85192.168.2.44985513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120674v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:10 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 474
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                        ETag: "0x8DC582BA4037B0D"
                        x-ms-request-id: 3b7b7106-501e-0064-43e7-161f54000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48cpbzgkvtewk0wu000000002t000000000naem
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:10 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120674" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120673" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        86192.168.2.44985713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120675v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:10 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 419
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:08 GMT
                        ETag: "0x8DC582BA6CF78C8"
                        x-ms-request-id: f196d52c-b01e-0002-1604-171b8f000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48p2j6x2quer0q0280000000320000000000bn4
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:10 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 55 75 5d 5b 50 70 5d 5b 43 63 5d 5b 4c 6c 5d 5b 4f 6f 5d 5b 55 75 5d 5b 44 64 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120675" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120673" /> <SR T="2" R="([Uu][Pp][Cc][Ll][Oo][Uu][Dd])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                        Session IDSource IPSource PortDestination IPDestination Port
                        87192.168.2.44985813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120676v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:10 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 472
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                        ETag: "0x8DC582B984BF177"
                        x-ms-request-id: 2f576d96-401e-0047-3902-178597000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48dfrdj7px744zp8s00000002dg00000000qebz
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:10 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120676" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120675" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        88192.168.2.44985913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120677v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:11 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 405
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:37 GMT
                        ETag: "0x8DC582B942B6AFF"
                        x-ms-request-id: dfb96d6a-f01e-003f-17e5-16d19d000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48p2j6x2quer0q02800000002v000000000squd
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:11 UTC405INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5e 5b 58 78 5d 5b 45 65 5d 5b 4e 6e 5d 24 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120677" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120675" /> <SR T="2" R="(^[Xx][Ee][Nn]$)"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <


                        Session IDSource IPSource PortDestination IPDestination Port
                        89192.168.2.44986013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120678v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:11 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 468
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                        ETag: "0x8DC582BBA642BF4"
                        x-ms-request-id: f5ee0945-901e-0083-4202-17bb55000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48f7nlxc7n5fnfzh000000002fg0000000025qf
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:11 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120678" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120677" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        90192.168.2.44986113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:10 UTC192OUTGET /rules/rule120679v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:11 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:10 GMT
                        Content-Type: text/xml
                        Content-Length: 174
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:33 GMT
                        ETag: "0x8DC582B91D80E15"
                        x-ms-request-id: 0607cd43-401e-0078-1b00-174d34000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005210Z-1657d5bbd48qjg85buwfdynm5w00000002r000000000vyyg
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:11 UTC174INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 37 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120679" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120677" /> </S> <T> <S T="1" /> </T></R>


                        Session IDSource IPSource PortDestination IPDestination Port
                        91192.168.2.44986213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:11 UTC192OUTGET /rules/rule120680v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:11 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:11 GMT
                        Content-Type: text/xml
                        Content-Length: 1952
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:39 GMT
                        ETag: "0x8DC582B956B0F3D"
                        x-ms-request-id: a5ff6bd9-301e-005d-3af2-16e448000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005211Z-1657d5bbd48sdh4cyzadbb374800000002qg000000000rqy
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:11 UTC1952INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 31 22 20 47 3d 22 7b 62 31 36 37 36 61 63 33 2d 37 66 65 65 2d 34 34 61 39 2d 39 61 30 65 2d 64 62 62 30 62 34 39 36 65 66 61 35 7d 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 38 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 33 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120680" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <SS T="1" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" /> <R T="2" R="120682" /> <F T="3"> <O T="LT"> <L>


                        Session IDSource IPSource PortDestination IPDestination Port
                        92192.168.2.44986313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:11 UTC192OUTGET /rules/rule120681v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:11 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:11 GMT
                        Content-Type: text/xml
                        Content-Length: 958
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:58 GMT
                        ETag: "0x8DC582BA0A31B3B"
                        x-ms-request-id: 0c165d1d-a01e-000d-7dfe-16d1ea000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005211Z-1657d5bbd48qjg85buwfdynm5w00000002u000000000h3xw
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:11 UTC958INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 38 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 38 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 33 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120681" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <R T="1" R="120608" /> <R T="2" R="120680" /> <TH T="3"> <O T="AND"> <L> <O T="EQ"> <L>


                        Session IDSource IPSource PortDestination IPDestination Port
                        93192.168.2.44986413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:11 UTC192OUTGET /rules/rule120682v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:11 UTC470INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:11 GMT
                        Content-Type: text/xml
                        Content-Length: 501
                        Connection: close
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:18 GMT
                        ETag: "0x8DC582BACFDAACD"
                        x-ms-request-id: c2f609cb-201e-0003-75fd-16f85a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005211Z-1657d5bbd48q6t9vvmrkd293mg00000002u0000000003f6c
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:11 UTC501INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 31 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 74 61 72 74 75 70 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 33 22 20 47 3d 22 7b 62 31 36 37 36 61 63 33 2d 37 66 65 65 2d 34 34 61 39 2d 39 61 30 65 2d 64 62 62 30 62 34 39 36 65 66 61 35 7d 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120682" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <A T="1" E="TelemetryStartup" /> <R T="2" R="120100" /> <SS T="3" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" /> </S> <C T="


                        Session IDSource IPSource PortDestination IPDestination Port
                        94192.168.2.44986513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:11 UTC193OUTGET /rules/rule120602v10s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:11 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:11 GMT
                        Content-Type: text/xml
                        Content-Length: 2592
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                        ETag: "0x8DC582BB5B890DB"
                        x-ms-request-id: 33b4d0ae-a01e-0032-35ff-161949000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005211Z-1657d5bbd48jwrqbupe3ktsx9w00000002ug00000000y2z8
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:11 UTC2592INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 32 22 20 56 3d 22 31 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 6e 64 4c 61 6e 67 75 61 67 65 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120602" V="10" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAndLanguage" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa=


                        Session IDSource IPSource PortDestination IPDestination Port
                        95192.168.2.44986613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:11 UTC192OUTGET /rules/rule120601v3s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:11 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:11 GMT
                        Content-Type: text/xml
                        Content-Length: 3342
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:25:34 GMT
                        ETag: "0x8DC582B927E47E9"
                        x-ms-request-id: 960edd56-701e-005c-4100-17bb94000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005211Z-1657d5bbd4824mj9d6vp65b6n400000002x000000000n13z
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:11 UTC3342INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 31 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 4f 53 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120601" V="3" DC="SM" EN="Office.System.SystemHealthMetadataOS" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC" xmlns=""> <RI


                        Session IDSource IPSource PortDestination IPDestination Port
                        96192.168.2.44986713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:12 UTC193OUTGET /rules/rule224901v11s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:12 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:12 GMT
                        Content-Type: text/xml
                        Content-Length: 2284
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:13 GMT
                        ETag: "0x8DC582BCD58BEEE"
                        x-ms-request-id: b738acd5-401e-0067-1502-1709c2000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005212Z-1657d5bbd48qjg85buwfdynm5w00000002t000000000ms3w
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:12 UTC2284INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 32 32 34 39 30 31 22 20 56 3d 22 31 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4c 69 63 65 6e 73 69 6e 67 2e 4f 66 66 69 63 65 43 6c 69 65 6e 74 4c 69 63 65 6e 73 69 6e 67 2e 44 6f 4c 69 63 65 6e 73 65 56 61 6c 69 64 61 74 69 6f 6e 22 20 41 54 54 3d 22 63 31 61 30 64 62 30 31 32 37 39 36 34 36 37 34 61 30 64 36 32 66 64 65 35 61 62 30 66 65 36 32 2d 36 65 63 34 61 63 34 35 2d 63 65 62 63 2d 34 66 38 30 2d 61 61 38 33 2d 62 36 62 39 64 33 61 38 36 65 64 37 2d 37 37 31 39 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 43 65 6e 73 75 73 22 20 54 3d 22 55 70 6c 6f 61 64 2d 4d 65 64 69 75 6d 22
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="224901" V="11" DC="SM" EN="Office.Licensing.OfficeClientLicensing.DoLicenseValidation" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalCensus" T="Upload-Medium"


                        Session IDSource IPSource PortDestination IPDestination Port
                        97192.168.2.44987013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:12 UTC192OUTGET /rules/rule701201v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:12 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:12 GMT
                        Content-Type: text/xml
                        Content-Length: 1393
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:51 GMT
                        ETag: "0x8DC582BE3E55B6E"
                        x-ms-request-id: 8a5fd43d-c01e-0066-4506-17a1ec000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005212Z-1657d5bbd48lknvp09v995n79000000002eg000000004nee
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:12 UTC1393INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 58 61 6d 6c 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 58 61 6d 6c 22
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Xaml.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenXaml"


                        Session IDSource IPSource PortDestination IPDestination Port
                        98192.168.2.44986813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:12 UTC191OUTGET /rules/rule90401v3s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:12 UTC564INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:12 GMT
                        Content-Type: text/xml
                        Content-Length: 1250
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:41 GMT
                        ETag: "0x8DC582BDE4487AA"
                        x-ms-request-id: 6418a561-001e-0082-7453-185880000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005212Z-1657d5bbd48q6t9vvmrkd293mg00000002r000000000e9fr
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_MISS
                        Accept-Ranges: bytes
                        2024-10-07 00:52:12 UTC1250INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 39 30 34 30 31 22 20 56 3d 22 33 22 20 44 43 3d 22 45 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 53 61 6d 70 6c 69 6e 67 50 6f 6c 69 63 79 22 20 41 54 54 3d 22 66 39 39 38 63 63 35 62 61 34 64 34 34 38 64 36 61 31 65 38 65 39 31 33 66 66 31 38 62 65 39 34 2d 64 64 31 32 32 65 30 61 2d 66 63 66 38 2d 34 64 63 35 2d 39 64 62 62 2d 36 61 66 61 63 35 33 32 35 31 38 33 2d 37 34 30 35 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 4d 65 74 61 64 61 74 61 22 20 2f 3e 0d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="90401" V="3" DC="ESM" EN="Office.Telemetry.SamplingPolicy" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" DL="A" DCa="PSP PSU" xmlns=""> <RIS> <RI N="Metadata" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        99192.168.2.44986913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:12 UTC192OUTGET /rules/rule701200v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:12 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:12 GMT
                        Content-Type: text/xml
                        Content-Length: 1356
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:38 GMT
                        ETag: "0x8DC582BDC681E17"
                        x-ms-request-id: 0480ed94-801e-00ac-5102-17fd65000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005212Z-1657d5bbd48p2j6x2quer0q0280000000320000000000bqc
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:12 UTC1356INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 58 61 6d 6c 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 58 61 6d 6c 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Xaml" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenXaml" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        100192.168.2.44987113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:12 UTC192OUTGET /rules/rule700201v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:12 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:12 GMT
                        Content-Type: text/xml
                        Content-Length: 1393
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:50 GMT
                        ETag: "0x8DC582BE39DFC9B"
                        x-ms-request-id: b72ef555-401e-0067-78fe-1609c2000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005212Z-1657d5bbd48p2j6x2quer0q02800000002y000000000drzx
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:12 UTC1393INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 32 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 57 6f 72 64 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 57 6f 72 64 22
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Word.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenWord"


                        Session IDSource IPSource PortDestination IPDestination Port
                        101192.168.2.44987313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:13 UTC192OUTGET /rules/rule702351v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:13 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:13 GMT
                        Content-Type: text/xml
                        Content-Length: 1395
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                        ETag: "0x8DC582BE017CAD3"
                        x-ms-request-id: cb759915-201e-003f-5f03-176d94000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005213Z-1657d5bbd48vlsxxpe15ac3q7n00000002q000000000fq3v
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:13 UTC1395INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 6f 69 63 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 6f 69 63
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Voice.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVoic


                        Session IDSource IPSource PortDestination IPDestination Port
                        102192.168.2.44987213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:13 UTC192OUTGET /rules/rule700200v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:13 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:13 GMT
                        Content-Type: text/xml
                        Content-Length: 1356
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:43 GMT
                        ETag: "0x8DC582BDF66E42D"
                        x-ms-request-id: db28c537-d01e-0065-47fe-16b77a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005213Z-1657d5bbd48762wn1qw4s5sd3000000002pg000000006b46
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:13 UTC1356INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 32 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 57 6f 72 64 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 57 6f 72 64 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Word" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenWord" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        103192.168.2.44987413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:13 UTC192OUTGET /rules/rule702350v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:13 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:13 GMT
                        Content-Type: text/xml
                        Content-Length: 1358
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:54 GMT
                        ETag: "0x8DC582BE6431446"
                        x-ms-request-id: 84e7aa3f-c01e-008e-74ff-167381000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005213Z-1657d5bbd48xsz2nuzq4vfrzg800000002r000000000156n
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:13 UTC1358INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 6f 69 63 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 6f 69 63 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Voice" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVoice" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        104192.168.2.44987513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:13 UTC192OUTGET /rules/rule701251v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:13 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:13 GMT
                        Content-Type: text/xml
                        Content-Length: 1395
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:41 GMT
                        ETag: "0x8DC582BDE12A98D"
                        x-ms-request-id: 03c3f781-101e-000b-56fe-165e5c000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005213Z-1657d5bbd48tnj6wmberkg2xy800000002t000000000nenc
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:13 UTC1395INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 69 73 69 6f 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 69 73 69
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701251" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Visio.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVisi


                        Session IDSource IPSource PortDestination IPDestination Port
                        105192.168.2.44987613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:13 UTC192OUTGET /rules/rule701250v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:13 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:13 GMT
                        Content-Type: text/xml
                        Content-Length: 1358
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                        ETag: "0x8DC582BE022ECC5"
                        x-ms-request-id: 76165599-601e-000d-1a02-172618000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005213Z-1657d5bbd4824mj9d6vp65b6n400000002y000000000fspb
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:13 UTC1358INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 69 73 69 6f 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 69 73 69 6f 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701250" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Visio" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVisio" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        106192.168.2.44987713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule700051v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1389
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                        ETag: "0x8DC582BE10A6BC1"
                        x-ms-request-id: 29f28342-e01e-003c-5d00-17c70b000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48tnj6wmberkg2xy800000002v000000000btgt
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1389INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 30 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 55 58 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 55 58 22 20 53 3d 22
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700051" V="1" DC="SM" EN="Office.Telemetry.Event.Office.UX.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenUX" S="


                        Session IDSource IPSource PortDestination IPDestination Port
                        107192.168.2.44987813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule700050v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1352
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:28:01 GMT
                        ETag: "0x8DC582BE9DEEE28"
                        x-ms-request-id: a9a45936-c01e-00a1-54f1-167e4a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48f7nlxc7n5fnfzh000000002d000000000a93d
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1352INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 30 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 55 58 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 55 58 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700050" V="1" DC="SM" EN="Office.Telemetry.Event.Office.UX" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenUX" S="Medium" /> <F T="2"> <O T


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        108192.168.2.44988013.107.246.45443796C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule702950v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1368
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:40 GMT
                        ETag: "0x8DC582BDDC22447"
                        x-ms-request-id: 173e0f62-801e-00a3-24fe-167cfb000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48sqtlf1huhzuwq7000000002hg000000006dvs
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1368INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 39 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 72 61 6e 73 6c 61 74 6f 72 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 72 61 6e 73 6c 61 74 6f 72 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702950" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Translator" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTranslator" S="Medium" /> <F T=


                        Session IDSource IPSource PortDestination IPDestination Port
                        109192.168.2.44987913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule702951v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1405
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                        ETag: "0x8DC582BE12B5C71"
                        x-ms-request-id: 6f1c5b1d-901e-0048-485a-17b800000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48xsz2nuzq4vfrzg800000002gg00000000u25y
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1405INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 39 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 72 61 6e 73 6c 61 74 6f 72 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702951" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Translator.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToke


                        Session IDSource IPSource PortDestination IPDestination Port
                        110192.168.2.44988113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule701151v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1401
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:45 GMT
                        ETag: "0x8DC582BE055B528"
                        x-ms-request-id: 3a04fc40-501e-007b-3b73-175ba2000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48gqrfwecymhhbfm800000001n00000000076c1
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1401INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 31 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 78 74 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 78 74 41
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701151" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Text.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTextA


                        Session IDSource IPSource PortDestination IPDestination Port
                        111192.168.2.44988213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule701150v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1364
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                        ETag: "0x8DC582BE1223606"
                        x-ms-request-id: 04600955-801e-00ac-55f4-16fd65000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd482lxwq1dp2t1zwkc00000002fg00000000fyrv
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1364INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 31 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 78 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 78 74 41 6e 64 46 6f 6e 74 73 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701150" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Text" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTextAndFonts" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        112192.168.2.44988313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule702201v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1397
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:56 GMT
                        ETag: "0x8DC582BE7262739"
                        x-ms-request-id: 4035d6e2-a01e-0002-4602-175074000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48f7nlxc7n5fnfzh000000002ag00000000pnq1
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1397INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 32 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 6c 6c 4d 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 6c
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.TellMe.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTel


                        Session IDSource IPSource PortDestination IPDestination Port
                        113192.168.2.44988513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule700401v2s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1403
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:38 GMT
                        ETag: "0x8DC582BDCB4853F"
                        x-ms-request-id: 87e26173-201e-0051-15e7-167340000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48xlwdx82gahegw4000000002u000000000y5tf
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1403INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 34 30 31 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700401" V="2" DC="SM" EN="Office.Telemetry.Event.Office.Telemetry.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToken


                        Session IDSource IPSource PortDestination IPDestination Port
                        114192.168.2.44988613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule700400v2s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1366
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:36 GMT
                        ETag: "0x8DC582BDB779FC3"
                        x-ms-request-id: 52963dc7-601e-0084-0e74-176b3f000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48gqrfwecymhhbfm800000001q0000000000n1c
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1366INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 34 30 30 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 6c 65 6d 65 74 72 79 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700400" V="2" DC="SM" EN="Office.Telemetry.Event.Office.Telemetry" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTelemetry" S="Medium" /> <F T="2


                        Session IDSource IPSource PortDestination IPDestination Port
                        115192.168.2.44988413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:14 UTC192OUTGET /rules/rule702200v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:14 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:14 GMT
                        Content-Type: text/xml
                        Content-Length: 1360
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:40 GMT
                        ETag: "0x8DC582BDDEB5124"
                        x-ms-request-id: 62f7f1ae-f01e-0096-4d0c-1710ef000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005214Z-1657d5bbd48brl8we3nu8cxwgn000000030000000000nnzm
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:14 UTC1360INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 32 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 54 65 6c 6c 4d 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 54 65 6c 6c 4d 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.TellMe" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenTellMe" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        116192.168.2.44988913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:15 UTC192OUTGET /rules/rule700350v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:15 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:15 GMT
                        Content-Type: text/xml
                        Content-Length: 1360
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:40 GMT
                        ETag: "0x8DC582BDD74D2EC"
                        x-ms-request-id: f076ebb2-f01e-001f-3766-175dc8000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005215Z-1657d5bbd48sqtlf1huhzuwq7000000002h0000000008f5c
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:15 UTC1360INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 33 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 79 73 74 65 6d 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.System" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSystem" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        117192.168.2.44988813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:15 UTC192OUTGET /rules/rule700351v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:15 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:15 GMT
                        Content-Type: text/xml
                        Content-Length: 1397
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                        ETag: "0x8DC582BDFD43C07"
                        x-ms-request-id: 31868579-401e-008c-0af2-1686c2000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005215Z-1657d5bbd48jwrqbupe3ktsx9w00000002w000000000rnft
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:15 UTC1397INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 33 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 79 73
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.System.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSys


                        Session IDSource IPSource PortDestination IPDestination Port
                        118192.168.2.44989013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:15 UTC192OUTGET /rules/rule703901v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:15 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:15 GMT
                        Content-Type: text/xml
                        Content-Length: 1427
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:53 GMT
                        ETag: "0x8DC582BE56F6873"
                        x-ms-request-id: 08bf7a15-f01e-0020-7706-17956b000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005215Z-1657d5bbd48762wn1qw4s5sd3000000002m000000000g3kf
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:15 UTC1427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 39 30 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 65 72 76 69 63 65 61 62 69 6c 69 74 79 4d 61 6e 61 67 65 72 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703901" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ServiceabilityManager.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="Nexu


                        Session IDSource IPSource PortDestination IPDestination Port
                        119192.168.2.44989113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:15 UTC192OUTGET /rules/rule703900v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:15 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:15 GMT
                        Content-Type: text/xml
                        Content-Length: 1390
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:49 GMT
                        ETag: "0x8DC582BE3002601"
                        x-ms-request-id: 7d21ea5d-701e-0098-0502-17395f000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005215Z-1657d5bbd48762wn1qw4s5sd3000000002fg00000000zkec
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:15 UTC1390INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 39 30 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 65 72 76 69 63 65 61 62 69 6c 69 74 79 4d 61 6e 61 67 65 72 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 65 72 76 69 63 65 61 62 69 6c 69 74 79 4d 61 6e 61 67 65 72 22 20 53 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703900" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ServiceabilityManager" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenServiceabilityManager" S=


                        Session IDSource IPSource PortDestination IPDestination Port
                        120192.168.2.44989213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:15 UTC192OUTGET /rules/rule701501v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:15 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:15 GMT
                        Content-Type: text/xml
                        Content-Length: 1401
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:48 GMT
                        ETag: "0x8DC582BE2A9D541"
                        x-ms-request-id: b6fa471e-401e-0067-43e5-1609c2000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005215Z-1657d5bbd48xdq5dkwwugdpzr00000000350000000002m90
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:15 UTC1401INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 35 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 65 63 75 72 69 74 79 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701501" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Security.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenS


                        Session IDSource IPSource PortDestination IPDestination Port
                        121192.168.2.44989413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:16 UTC192OUTGET /rules/rule702801v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:16 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:16 GMT
                        Content-Type: text/xml
                        Content-Length: 1391
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:43 GMT
                        ETag: "0x8DC582BDF58DC7E"
                        x-ms-request-id: a18d9b1d-601e-0002-1f03-17a786000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005216Z-1657d5bbd48f7nlxc7n5fnfzh000000002f00000000042xe
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:16 UTC1391INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 38 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 44 58 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 44 58 22 20 53
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702801" V="1" DC="SM" EN="Office.Telemetry.Event.Office.SDX.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSDX" S


                        Session IDSource IPSource PortDestination IPDestination Port
                        122192.168.2.44989313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:16 UTC192OUTGET /rules/rule701500v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:16 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:16 GMT
                        Content-Type: text/xml
                        Content-Length: 1364
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:28:03 GMT
                        ETag: "0x8DC582BEB6AD293"
                        x-ms-request-id: 77012b0e-b01e-0097-0bff-164f33000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005216Z-1657d5bbd48lknvp09v995n79000000002eg000000004nqf
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:16 UTC1364INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 35 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 65 63 75 72 69 74 79 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 65 63 75 72 69 74 79 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701500" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Security" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSecurity" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        123192.168.2.44989513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:16 UTC192OUTGET /rules/rule702800v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:16 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:16 GMT
                        Content-Type: text/xml
                        Content-Length: 1354
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:45 GMT
                        ETag: "0x8DC582BE0662D7C"
                        x-ms-request-id: d4fd285a-d01e-005a-06ed-167fd9000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005216Z-1657d5bbd48f7nlxc7n5fnfzh000000002f00000000042xf
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:16 UTC1354INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 38 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 44 58 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 44 58 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702800" V="1" DC="SM" EN="Office.Telemetry.Event.Office.SDX" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSDX" S="Medium" /> <F T="2"> <O


                        Session IDSource IPSource PortDestination IPDestination Port
                        124192.168.2.44989713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:16 UTC192OUTGET /rules/rule703350v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:16 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:16 GMT
                        Content-Type: text/xml
                        Content-Length: 1366
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:42 GMT
                        ETag: "0x8DC582BDF1E2608"
                        x-ms-request-id: c9f5ea47-201e-0071-33fe-16ff15000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005216Z-1657d5bbd48jwrqbupe3ktsx9w000000031g0000000023fs
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:16 UTC1366INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 33 35 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 63 72 69 70 74 4c 61 62 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 63 72 69 70 74 4c 61 62 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703350" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ScriptLab" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenScriptLab" S="Medium" /> <F T="2


                        Session IDSource IPSource PortDestination IPDestination Port
                        125192.168.2.44989613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:16 UTC192OUTGET /rules/rule703351v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:16 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:16 GMT
                        Content-Type: text/xml
                        Content-Length: 1403
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:39 GMT
                        ETag: "0x8DC582BDCDD6400"
                        x-ms-request-id: 4d5cca78-701e-0021-6ae5-163d45000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005216Z-1657d5bbd48cpbzgkvtewk0wu000000002u000000000f8xh
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:16 UTC1403INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 33 35 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 63 72 69 70 74 4c 61 62 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703351" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ScriptLab.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToken


                        Session IDSource IPSource PortDestination IPDestination Port
                        126192.168.2.44989813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule703501v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1399
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:59 GMT
                        ETag: "0x8DC582BE8C605FF"
                        x-ms-request-id: 76dbcc6a-501e-0035-36ed-16c923000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48vlsxxpe15ac3q7n00000002u0000000002efv
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1399INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 35 30 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 61 6e 64 62 6f 78 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 61
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703501" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Sandbox.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSa


                        Session IDSource IPSource PortDestination IPDestination Port
                        127192.168.2.44989913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule703500v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1362
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:43 GMT
                        ETag: "0x8DC582BDF497570"
                        x-ms-request-id: 838d785c-001e-0014-24fe-165151000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48t66tjar5xuq22r800000002n000000000tfcr
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1362INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 35 30 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 53 61 6e 64 62 6f 78 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 53 61 6e 64 62 6f 78 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703500" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Sandbox" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenSandbox" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        128192.168.2.44990013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule701801v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1403
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:38 GMT
                        ETag: "0x8DC582BDC2EEE03"
                        x-ms-request-id: 4d8e5842-701e-0021-0efe-163d45000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48q6t9vvmrkd293mg00000002rg00000000cc4f
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1403INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 38 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 52 65 73 6f 75 72 63 65 73 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701801" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Resources.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToken


                        Session IDSource IPSource PortDestination IPDestination Port
                        129192.168.2.44990213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule701051v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1399
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:47 GMT
                        ETag: "0x8DC582BE1CC18CD"
                        x-ms-request-id: cd0b82ba-d01e-0049-1304-17e7dc000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48cpbzgkvtewk0wu000000002r000000000w3pg
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1399INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 30 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 52 65 6c 65 61 73 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 52 65
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701051" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Release.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenRe


                        Session IDSource IPSource PortDestination IPDestination Port
                        130192.168.2.44990113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule701800v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1366
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:28:01 GMT
                        ETag: "0x8DC582BEA414B16"
                        x-ms-request-id: 8a56303a-c01e-0066-0f01-17a1ec000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48f7nlxc7n5fnfzh000000002ag00000000pnwd
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1366INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 38 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 52 65 73 6f 75 72 63 65 73 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 52 65 73 6f 75 72 63 65 73 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701800" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Resources" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenResources" S="Medium" /> <F T="2


                        Session IDSource IPSource PortDestination IPDestination Port
                        131192.168.2.44990413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule702751v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1403
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:28:03 GMT
                        ETag: "0x8DC582BEB866CDB"
                        x-ms-request-id: d3a3eb01-b01e-003d-1ef1-16d32c000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48f7nlxc7n5fnfzh000000002c000000000fadg
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1403INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 37 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 75 62 6c 69 73 68 65 72 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702751" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Publisher.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToken


                        Session IDSource IPSource PortDestination IPDestination Port
                        132192.168.2.44990313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule701050v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1362
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:28:03 GMT
                        ETag: "0x8DC582BEB256F43"
                        x-ms-request-id: 0c184816-a01e-000d-72ff-16d1ea000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48jwrqbupe3ktsx9w00000002w000000000rnky
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1362INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 30 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 52 65 6c 65 61 73 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 52 65 6c 65 61 73 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701050" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Release" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenRelease" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        133192.168.2.44990513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule702750v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1366
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:54 GMT
                        ETag: "0x8DC582BE5B7B174"
                        x-ms-request-id: ca2bab4f-201e-0071-5e14-17ff15000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48dfrdj7px744zp8s00000002gg00000000a9vt
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1366INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 37 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 75 62 6c 69 73 68 65 72 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 75 62 6c 69 73 68 65 72 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702750" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Publisher" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPublisher" S="Medium" /> <F T="2


                        Session IDSource IPSource PortDestination IPDestination Port
                        134192.168.2.44990613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule702301v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:17 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1399
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:28:00 GMT
                        ETag: "0x8DC582BE976026E"
                        x-ms-request-id: 4d8e59a4-701e-0021-64fe-163d45000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48vhs7r2p1ky7cs5w00000002zg00000000pcaz
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:17 UTC1399INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 6a 65 63 74 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 72
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702301" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Project.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPr


                        Session IDSource IPSource PortDestination IPDestination Port
                        135192.168.2.44990713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:17 UTC192OUTGET /rules/rule702300v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:18 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:17 GMT
                        Content-Type: text/xml
                        Content-Length: 1362
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:37 GMT
                        ETag: "0x8DC582BDC13EFEF"
                        x-ms-request-id: 4ef38422-401e-000a-160c-174a7b000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005217Z-1657d5bbd48q6t9vvmrkd293mg00000002ug000000001k0s
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:18 UTC1362INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 6a 65 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 72 6f 6a 65 63 74 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702300" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Project" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenProject" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        136192.168.2.44990813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:18 UTC192OUTGET /rules/rule703401v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:18 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:18 GMT
                        Content-Type: text/xml
                        Content-Length: 1425
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:55 GMT
                        ETag: "0x8DC582BE6BD89A1"
                        x-ms-request-id: c326dec7-201e-0003-0c12-17f85a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005218Z-1657d5bbd48vlsxxpe15ac3q7n00000002pg00000000k347
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:18 UTC1425INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 34 30 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 67 72 61 6d 6d 61 62 6c 65 53 75 72 66 61 63 65 73 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703401" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ProgrammableSurfaces.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="Nexus


                        Session IDSource IPSource PortDestination IPDestination Port
                        137192.168.2.44990913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:18 UTC192OUTGET /rules/rule703400v0s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:18 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:18 GMT
                        Content-Type: text/xml
                        Content-Length: 1388
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:37 GMT
                        ETag: "0x8DC582BDBD9126E"
                        x-ms-request-id: 75ef523f-601e-000d-02f2-162618000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005218Z-1657d5bbd48dfrdj7px744zp8s00000002g000000000d08y
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:18 UTC1388INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 34 30 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 67 72 61 6d 6d 61 62 6c 65 53 75 72 66 61 63 65 73 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 72 6f 67 72 61 6d 6d 61 62 6c 65 53 75 72 66 61 63 65 73 22 20 53 3d 22 4d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703400" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ProgrammableSurfaces" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenProgrammableSurfaces" S="M


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        138192.168.2.44991013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:18 UTC192OUTGET /rules/rule702501v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:18 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:18 GMT
                        Content-Type: text/xml
                        Content-Length: 1415
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:57 GMT
                        ETag: "0x8DC582BE7C66E85"
                        x-ms-request-id: cad35e9e-b01e-0021-3602-17cab7000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005218Z-1657d5bbd48xlwdx82gahegw4000000002yg00000000c0qa
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:18 UTC1415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 35 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 67 72 61 6d 6d 61 62 69 6c 69 74 79 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702501" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Programmability.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenan


                        Session IDSource IPSource PortDestination IPDestination Port
                        139192.168.2.44991113.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:18 UTC192OUTGET /rules/rule702500v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:18 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:18 GMT
                        Content-Type: text/xml
                        Content-Length: 1378
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:36 GMT
                        ETag: "0x8DC582BDB813B3F"
                        x-ms-request-id: 87e265fd-201e-0051-4fe7-167340000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005218Z-1657d5bbd48dfrdj7px744zp8s00000002dg00000000qf0y
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:18 UTC1378INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 35 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 72 6f 67 72 61 6d 6d 61 62 69 6c 69 74 79 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 72 6f 67 72 61 6d 6d 61 62 69 6c 69 74 79 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702500" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Programmability" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenProgrammability" S="Medium" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        140192.168.2.44991213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:18 UTC192OUTGET /rules/rule700501v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:18 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:18 GMT
                        Content-Type: text/xml
                        Content-Length: 1405
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:58 GMT
                        ETag: "0x8DC582BE89A8F82"
                        x-ms-request-id: c9f5e5fc-201e-0071-5dfe-16ff15000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005218Z-1657d5bbd48qjg85buwfdynm5w00000002wg00000000731k
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:18 UTC1405INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 35 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 6f 77 65 72 50 6f 69 6e 74 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700501" V="1" DC="SM" EN="Office.Telemetry.Event.Office.PowerPoint.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantToke


                        Session IDSource IPSource PortDestination IPDestination Port
                        141192.168.2.44991313.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:19 UTC192OUTGET /rules/rule700500v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:19 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:19 GMT
                        Content-Type: text/xml
                        Content-Length: 1368
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:53 GMT
                        ETag: "0x8DC582BE51CE7B3"
                        x-ms-request-id: 3e7839e3-701e-0053-5cff-163a0a000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005219Z-1657d5bbd48lknvp09v995n79000000002c000000000f51m
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:19 UTC1368INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 35 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 6f 77 65 72 50 6f 69 6e 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 6f 77 65 72 50 6f 69 6e 74 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700500" V="1" DC="SM" EN="Office.Telemetry.Event.Office.PowerPoint" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPowerPoint" S="Medium" /> <F T=


                        Session IDSource IPSource PortDestination IPDestination Port
                        142192.168.2.44991413.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:19 UTC192OUTGET /rules/rule702551v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:19 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:19 GMT
                        Content-Type: text/xml
                        Content-Length: 1415
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:39 GMT
                        ETag: "0x8DC582BDCE9703A"
                        x-ms-request-id: c7b470af-b01e-005c-24fe-164c66000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005219Z-1657d5bbd482lxwq1dp2t1zwkc00000002gg00000000btmw
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:19 UTC1415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 35 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 72 73 6f 6e 61 6c 69 7a 61 74 69 6f 6e 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702551" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Personalization.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenan


                        Session IDSource IPSource PortDestination IPDestination Port
                        143192.168.2.44991613.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:19 UTC192OUTGET /rules/rule701351v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:19 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:19 GMT
                        Content-Type: text/xml
                        Content-Length: 1407
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:55 GMT
                        ETag: "0x8DC582BE687B46A"
                        x-ms-request-id: 20e89b60-501e-008c-3a03-17cd39000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005219Z-1657d5bbd48t66tjar5xuq22r800000002pg00000000ktr4
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:19 UTC1407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 33 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 72 66 6f 72 6d 61 6e 63 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Performance.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTok


                        Session IDSource IPSource PortDestination IPDestination Port
                        144192.168.2.44991713.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:19 UTC192OUTGET /rules/rule701350v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:19 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:19 GMT
                        Content-Type: text/xml
                        Content-Length: 1370
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:41 GMT
                        ETag: "0x8DC582BDE62E0AB"
                        x-ms-request-id: 838d7376-001e-0014-17fe-165151000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005219Z-1657d5bbd48t66tjar5xuq22r800000002u00000000040r8
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:19 UTC1370INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 33 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 72 66 6f 72 6d 61 6e 63 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 65 72 66 6f 72 6d 61 6e 63 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Performance" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPerformance" S="Medium" /> <F


                        Session IDSource IPSource PortDestination IPDestination Port
                        145192.168.2.44991513.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:19 UTC192OUTGET /rules/rule702550v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:19 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:19 GMT
                        Content-Type: text/xml
                        Content-Length: 1378
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:53 GMT
                        ETag: "0x8DC582BE584C214"
                        x-ms-request-id: dfa7567c-f01e-003f-67de-16d19d000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005219Z-1657d5bbd48vlsxxpe15ac3q7n00000002q000000000fqc4
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:19 UTC1378INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 35 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 72 73 6f 6e 61 6c 69 7a 61 74 69 6f 6e 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 65 72 73 6f 6e 61 6c 69 7a 61 74 69 6f 6e 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702550" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Personalization" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPersonalization" S="Medium" />


                        Session IDSource IPSource PortDestination IPDestination Port
                        146192.168.2.44991813.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:20 UTC192OUTGET /rules/rule702151v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:20 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:20 GMT
                        Content-Type: text/xml
                        Content-Length: 1397
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:46 GMT
                        ETag: "0x8DC582BE156D2EE"
                        x-ms-request-id: 7d18055e-701e-0098-56ff-16395f000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005220Z-1657d5bbd48wd55zet5pcra0cg00000002mg00000000tr49
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:20 UTC1397INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 31 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 6f 70 6c 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 65 6f
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702151" V="1" DC="SM" EN="Office.Telemetry.Event.Office.People.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPeo


                        Session IDSource IPSource PortDestination IPDestination Port
                        147192.168.2.44991913.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:20 UTC192OUTGET /rules/rule702150v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:20 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:20 GMT
                        Content-Type: text/xml
                        Content-Length: 1360
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:28:07 GMT
                        ETag: "0x8DC582BEDC8193E"
                        x-ms-request-id: b1fbfe33-a01e-003d-4fd4-1698d7000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005220Z-1657d5bbd48sdh4cyzadbb374800000002hg00000000kg6t
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:20 UTC1360INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 31 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 50 65 6f 70 6c 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 50 65 6f 70 6c 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702150" V="1" DC="SM" EN="Office.Telemetry.Event.Office.People" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenPeople" S="Medium" /> <F T="2">


                        Session IDSource IPSource PortDestination IPDestination Port
                        148192.168.2.44992013.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:20 UTC192OUTGET /rules/rule703001v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:20 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:20 GMT
                        Content-Type: text/xml
                        Content-Length: 1406
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:28:03 GMT
                        ETag: "0x8DC582BEB16F27E"
                        x-ms-request-id: 770fdf22-501e-0035-0d02-17c923000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005220Z-1657d5bbd48vlsxxpe15ac3q7n00000002u0000000002end
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:20 UTC1406INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 33 30 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 4d 61 63 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="703001" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Outlook.Mac.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTok


                        Session IDSource IPSource PortDestination IPDestination Port
                        149192.168.2.44992213.107.246.45443
                        TimestampBytes transferredDirectionData
                        2024-10-07 00:52:20 UTC192OUTGET /rules/rule700751v1s19.xml HTTP/1.1
                        Connection: Keep-Alive
                        Accept-Encoding: gzip
                        User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                        Host: otelrules.azureedge.net
                        2024-10-07 00:52:20 UTC563INHTTP/1.1 200 OK
                        Date: Mon, 07 Oct 2024 00:52:20 GMT
                        Content-Type: text/xml
                        Content-Length: 1414
                        Connection: close
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Vary: Accept-Encoding
                        Cache-Control: public, max-age=604800, immutable
                        Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                        ETag: "0x8DC582BE03B051D"
                        x-ms-request-id: 4543d13f-701e-0050-5a04-176767000000
                        x-ms-version: 2018-03-28
                        x-azure-ref: 20241007T005220Z-1657d5bbd48xsz2nuzq4vfrzg800000002n000000000c1bz
                        x-fd-int-roxy-purgeid: 0
                        X-Cache: TCP_HIT
                        Accept-Ranges: bytes
                        2024-10-07 00:52:20 UTC1414INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 37 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e
                        Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700751" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Outlook.Desktop.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenan


                        Click to jump to process

                        Click to jump to process

                        Click to dive into process behavior distribution

                        Click to jump to process

                        Target ID:0
                        Start time:20:51:05
                        Start date:06/10/2024
                        Path:C:\Users\user\Desktop\file.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\Desktop\file.exe"
                        Imagebase:0xa80000
                        File size:919'040 bytes
                        MD5 hash:86B442EDECE0F1E7D7F46682A4E6B6A6
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:true

                        Target ID:1
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\SysWOW64\taskkill.exe
                        Wow64 process (32bit):true
                        Commandline:taskkill /F /IM chrome.exe /T
                        Imagebase:0xae0000
                        File size:74'240 bytes
                        MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:2
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\System32\conhost.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Imagebase:0x7ff7699e0000
                        File size:862'208 bytes
                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:3
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\SysWOW64\taskkill.exe
                        Wow64 process (32bit):true
                        Commandline:taskkill /F /IM msedge.exe /T
                        Imagebase:0xae0000
                        File size:74'240 bytes
                        MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:4
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\System32\conhost.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Imagebase:0x7ff7699e0000
                        File size:862'208 bytes
                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:5
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\SysWOW64\taskkill.exe
                        Wow64 process (32bit):true
                        Commandline:taskkill /F /IM firefox.exe /T
                        Imagebase:0xae0000
                        File size:74'240 bytes
                        MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:6
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\System32\conhost.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Imagebase:0x7ff7699e0000
                        File size:862'208 bytes
                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:7
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\SysWOW64\taskkill.exe
                        Wow64 process (32bit):true
                        Commandline:taskkill /F /IM opera.exe /T
                        Imagebase:0xae0000
                        File size:74'240 bytes
                        MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:8
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\System32\conhost.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Imagebase:0x7ff7699e0000
                        File size:862'208 bytes
                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:9
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\SysWOW64\taskkill.exe
                        Wow64 process (32bit):true
                        Commandline:taskkill /F /IM brave.exe /T
                        Imagebase:0xae0000
                        File size:74'240 bytes
                        MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:10
                        Start time:20:51:06
                        Start date:06/10/2024
                        Path:C:\Windows\System32\conhost.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Imagebase:0x7ff7699e0000
                        File size:862'208 bytes
                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:11
                        Start time:20:51:08
                        Start date:06/10/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobars
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:false

                        Target ID:13
                        Start time:20:51:08
                        Start date:06/10/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:false

                        Target ID:14
                        Start time:20:51:20
                        Start date:06/10/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5448 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:false
                        Has administrator privileges:false
                        Programmed in:C, C++ or other language
                        Has exited:false

                        Target ID:15
                        Start time:20:51:20
                        Start date:06/10/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5484 --field-trial-handle=1988,i,9782021070937754405,12549086448229880714,262144 /prefetch:8
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Has exited:true

                        Reset < >

                          Execution Graph

                          Execution Coverage:2.1%
                          Dynamic/Decrypted Code Coverage:0%
                          Signature Coverage:4.5%
                          Total number of Nodes:1630
                          Total number of Limit Nodes:58
                          execution_graph 95094 b12a55 95102 af1ebc 95094->95102 95097 b12a87 95098 b12a70 95104 ae39c0 22 API calls 95098->95104 95100 b12a7c 95105 ae417d 22 API calls __fread_nolock 95100->95105 95103 af1ec3 IsWindow 95102->95103 95103->95097 95103->95098 95104->95100 95105->95097 95106 a81cad SystemParametersInfoW 95107 ab8402 95112 ab81be 95107->95112 95111 ab842a 95117 ab81ef try_get_first_available_module 95112->95117 95114 ab83ee 95131 ab27ec 26 API calls __cftof 95114->95131 95116 ab8343 95116->95111 95124 ac0984 95116->95124 95120 ab8338 95117->95120 95127 aa8e0b 40 API calls 2 library calls 95117->95127 95119 ab838c 95119->95120 95128 aa8e0b 40 API calls 2 library calls 95119->95128 95120->95116 95130 aaf2d9 20 API calls _abort 95120->95130 95122 ab83ab 95122->95120 95129 aa8e0b 40 API calls 2 library calls 95122->95129 95132 ac0081 95124->95132 95126 ac099f 95126->95111 95127->95119 95128->95122 95129->95120 95130->95114 95131->95116 95133 ac008d ___BuildCatchObject 95132->95133 95134 ac009b 95133->95134 95137 ac00d4 95133->95137 95189 aaf2d9 20 API calls _abort 95134->95189 95136 ac00a0 95190 ab27ec 26 API calls __cftof 95136->95190 95143 ac065b 95137->95143 95142 ac00aa __wsopen_s 95142->95126 95144 ac0678 95143->95144 95145 ac068d 95144->95145 95146 ac06a6 95144->95146 95206 aaf2c6 20 API calls _abort 95145->95206 95192 ab5221 95146->95192 95149 ac0692 95207 aaf2d9 20 API calls _abort 95149->95207 95150 ac06ab 95151 ac06cb 95150->95151 95152 ac06b4 95150->95152 95205 ac039a CreateFileW 95151->95205 95208 aaf2c6 20 API calls _abort 95152->95208 95156 ac00f8 95191 ac0121 LeaveCriticalSection __wsopen_s 95156->95191 95157 ac06b9 95209 aaf2d9 20 API calls _abort 95157->95209 95158 ac0781 GetFileType 95161 ac078c GetLastError 95158->95161 95162 ac07d3 95158->95162 95160 ac0756 GetLastError 95211 aaf2a3 20 API calls __dosmaperr 95160->95211 95212 aaf2a3 20 API calls __dosmaperr 95161->95212 95214 ab516a 21 API calls 2 library calls 95162->95214 95163 ac0704 95163->95158 95163->95160 95210 ac039a CreateFileW 95163->95210 95167 ac079a CloseHandle 95167->95149 95170 ac07c3 95167->95170 95169 ac0749 95169->95158 95169->95160 95213 aaf2d9 20 API calls _abort 95170->95213 95171 ac07f4 95173 ac0840 95171->95173 95215 ac05ab 72 API calls 3 library calls 95171->95215 95178 ac086d 95173->95178 95216 ac014d 72 API calls 4 library calls 95173->95216 95174 ac07c8 95174->95149 95177 ac0866 95177->95178 95179 ac087e 95177->95179 95217 ab86ae 95178->95217 95179->95156 95181 ac08fc CloseHandle 95179->95181 95232 ac039a CreateFileW 95181->95232 95183 ac0927 95184 ac0931 GetLastError 95183->95184 95185 ac095d 95183->95185 95233 aaf2a3 20 API calls __dosmaperr 95184->95233 95185->95156 95187 ac093d 95234 ab5333 21 API calls 2 library calls 95187->95234 95189->95136 95190->95142 95191->95142 95193 ab522d ___BuildCatchObject 95192->95193 95235 ab2f5e EnterCriticalSection 95193->95235 95195 ab5259 95239 ab5000 95195->95239 95196 ab5234 95196->95195 95201 ab52c7 EnterCriticalSection 95196->95201 95204 ab527b 95196->95204 95199 ab52a4 __wsopen_s 95199->95150 95202 ab52d4 LeaveCriticalSection 95201->95202 95201->95204 95202->95196 95236 ab532a 95204->95236 95205->95163 95206->95149 95207->95156 95208->95157 95209->95149 95210->95169 95211->95149 95212->95167 95213->95174 95214->95171 95215->95173 95216->95177 95265 ab53c4 95217->95265 95219 ab86be 95220 ab86c4 95219->95220 95222 ab86f6 95219->95222 95224 ab53c4 __wsopen_s 26 API calls 95219->95224 95278 ab5333 21 API calls 2 library calls 95220->95278 95222->95220 95225 ab53c4 __wsopen_s 26 API calls 95222->95225 95223 ab871c 95226 ab873e 95223->95226 95279 aaf2a3 20 API calls __dosmaperr 95223->95279 95227 ab86ed 95224->95227 95228 ab8702 CloseHandle 95225->95228 95226->95156 95230 ab53c4 __wsopen_s 26 API calls 95227->95230 95228->95220 95231 ab870e GetLastError 95228->95231 95230->95222 95231->95220 95232->95183 95233->95187 95234->95185 95235->95196 95247 ab2fa6 LeaveCriticalSection 95236->95247 95238 ab5331 95238->95199 95248 ab4c7d 95239->95248 95241 ab5012 95245 ab501f 95241->95245 95255 ab3405 11 API calls 2 library calls 95241->95255 95244 ab5071 95244->95204 95246 ab5147 EnterCriticalSection 95244->95246 95256 ab29c8 95245->95256 95246->95204 95247->95238 95253 ab4c8a _abort 95248->95253 95249 ab4cca 95263 aaf2d9 20 API calls _abort 95249->95263 95250 ab4cb5 RtlAllocateHeap 95251 ab4cc8 95250->95251 95250->95253 95251->95241 95253->95249 95253->95250 95262 aa4ead 7 API calls 2 library calls 95253->95262 95255->95241 95257 ab29d3 RtlFreeHeap 95256->95257 95258 ab29fc __dosmaperr 95256->95258 95257->95258 95259 ab29e8 95257->95259 95258->95244 95264 aaf2d9 20 API calls _abort 95259->95264 95261 ab29ee GetLastError 95261->95258 95262->95253 95263->95251 95264->95261 95266 ab53d1 95265->95266 95267 ab53e6 95265->95267 95280 aaf2c6 20 API calls _abort 95266->95280 95272 ab540b 95267->95272 95282 aaf2c6 20 API calls _abort 95267->95282 95269 ab53d6 95281 aaf2d9 20 API calls _abort 95269->95281 95272->95219 95273 ab5416 95283 aaf2d9 20 API calls _abort 95273->95283 95274 ab53de 95274->95219 95276 ab541e 95284 ab27ec 26 API calls __cftof 95276->95284 95278->95223 95279->95226 95280->95269 95281->95274 95282->95273 95283->95276 95284->95274 95285 ac2ba5 95286 ac2baf 95285->95286 95287 a82b25 95285->95287 95331 a83a5a 95286->95331 95313 a82b83 7 API calls 95287->95313 95291 ac2bb8 95338 a89cb3 95291->95338 95294 a82b2f 95301 a82b44 95294->95301 95317 a83837 95294->95317 95295 ac2bc6 95296 ac2bce 95295->95296 95297 ac2bf5 95295->95297 95344 a833c6 95296->95344 95298 a833c6 22 API calls 95297->95298 95312 ac2bf1 GetForegroundWindow ShellExecuteW 95298->95312 95304 a82b5f 95301->95304 95327 a830f2 95301->95327 95309 a82b66 SetCurrentDirectoryW 95304->95309 95306 ac2c26 95306->95304 95311 a82b7a 95309->95311 95310 a833c6 22 API calls 95310->95312 95312->95306 95362 a82cd4 7 API calls 95313->95362 95315 a82b2a 95316 a82c63 CreateWindowExW CreateWindowExW ShowWindow ShowWindow 95315->95316 95316->95294 95318 a83862 ___scrt_fastfail 95317->95318 95363 a84212 95318->95363 95321 a838e8 95323 ac3386 Shell_NotifyIconW 95321->95323 95324 a83906 Shell_NotifyIconW 95321->95324 95367 a83923 95324->95367 95326 a8391c 95326->95301 95328 a83154 95327->95328 95329 a83104 ___scrt_fastfail 95327->95329 95328->95304 95330 a83123 Shell_NotifyIconW 95329->95330 95330->95328 95454 ac1f50 95331->95454 95334 a89cb3 22 API calls 95335 a83a8d 95334->95335 95456 a83aa2 95335->95456 95337 a83a97 95337->95291 95339 a89cc2 _wcslen 95338->95339 95340 a9fe0b 22 API calls 95339->95340 95341 a89cea __fread_nolock 95340->95341 95342 a9fddb 22 API calls 95341->95342 95343 a89d00 95342->95343 95343->95295 95345 a833dd 95344->95345 95346 ac30bb 95344->95346 95476 a833ee 95345->95476 95347 a9fddb 22 API calls 95346->95347 95350 ac30c5 _wcslen 95347->95350 95349 a833e8 95353 a86350 95349->95353 95351 a9fe0b 22 API calls 95350->95351 95352 ac30fe __fread_nolock 95351->95352 95354 a86362 95353->95354 95355 ac4a51 95353->95355 95491 a86373 95354->95491 95501 a84a88 22 API calls __fread_nolock 95355->95501 95358 a8636e 95358->95310 95359 ac4a5b 95360 ac4a67 95359->95360 95502 a8a8c7 22 API calls __fread_nolock 95359->95502 95362->95315 95364 ac35a4 95363->95364 95365 a838b7 95363->95365 95364->95365 95366 ac35ad DestroyIcon 95364->95366 95365->95321 95389 aec874 42 API calls _strftime 95365->95389 95366->95365 95368 a8393f 95367->95368 95369 a83a13 95367->95369 95390 a86270 95368->95390 95369->95326 95372 a8395a 95395 a86b57 95372->95395 95373 ac3393 LoadStringW 95375 ac33ad 95373->95375 95383 a83994 ___scrt_fastfail 95375->95383 95407 a8a8c7 22 API calls __fread_nolock 95375->95407 95376 a8396f 95377 a8397c 95376->95377 95378 ac33c9 95376->95378 95377->95375 95380 a83986 95377->95380 95381 a86350 22 API calls 95378->95381 95382 a86350 22 API calls 95380->95382 95384 ac33d7 95381->95384 95382->95383 95386 a839f9 Shell_NotifyIconW 95383->95386 95384->95383 95385 a833c6 22 API calls 95384->95385 95387 ac33f9 95385->95387 95386->95369 95388 a833c6 22 API calls 95387->95388 95388->95383 95389->95321 95408 a9fe0b 95390->95408 95392 a86295 95418 a9fddb 95392->95418 95394 a8394d 95394->95372 95394->95373 95396 ac4ba1 95395->95396 95398 a86b67 _wcslen 95395->95398 95444 a893b2 95396->95444 95400 a86b7d 95398->95400 95401 a86ba2 95398->95401 95399 ac4baa 95399->95399 95443 a86f34 22 API calls 95400->95443 95403 a9fddb 22 API calls 95401->95403 95405 a86bae 95403->95405 95404 a86b85 __fread_nolock 95404->95376 95406 a9fe0b 22 API calls 95405->95406 95406->95404 95407->95383 95410 a9fddb 95408->95410 95411 a9fdfa 95410->95411 95414 a9fdfc 95410->95414 95428 aaea0c 95410->95428 95435 aa4ead 7 API calls 2 library calls 95410->95435 95411->95392 95413 aa066d 95437 aa32a4 RaiseException 95413->95437 95414->95413 95436 aa32a4 RaiseException 95414->95436 95417 aa068a 95417->95392 95421 a9fde0 95418->95421 95419 aaea0c ___std_exception_copy 21 API calls 95419->95421 95420 a9fdfa 95420->95394 95421->95419 95421->95420 95424 a9fdfc 95421->95424 95440 aa4ead 7 API calls 2 library calls 95421->95440 95423 aa066d 95442 aa32a4 RaiseException 95423->95442 95424->95423 95441 aa32a4 RaiseException 95424->95441 95427 aa068a 95427->95394 95430 ab3820 _abort 95428->95430 95429 ab385e 95439 aaf2d9 20 API calls _abort 95429->95439 95430->95429 95431 ab3849 RtlAllocateHeap 95430->95431 95438 aa4ead 7 API calls 2 library calls 95430->95438 95431->95430 95433 ab385c 95431->95433 95433->95410 95435->95410 95436->95413 95437->95417 95438->95430 95439->95433 95440->95421 95441->95423 95442->95427 95443->95404 95445 a893c9 __fread_nolock 95444->95445 95446 a893c0 95444->95446 95445->95399 95446->95445 95448 a8aec9 95446->95448 95449 a8aedc 95448->95449 95453 a8aed9 __fread_nolock 95448->95453 95450 a9fddb 22 API calls 95449->95450 95451 a8aee7 95450->95451 95452 a9fe0b 22 API calls 95451->95452 95452->95453 95453->95445 95455 a83a67 GetModuleFileNameW 95454->95455 95455->95334 95457 ac1f50 __wsopen_s 95456->95457 95458 a83aaf GetFullPathNameW 95457->95458 95459 a83ae9 95458->95459 95460 a83ace 95458->95460 95470 a8a6c3 95459->95470 95461 a86b57 22 API calls 95460->95461 95463 a83ada 95461->95463 95466 a837a0 95463->95466 95467 a837ae 95466->95467 95468 a893b2 22 API calls 95467->95468 95469 a837c2 95468->95469 95469->95337 95471 a8a6dd 95470->95471 95475 a8a6d0 95470->95475 95472 a9fddb 22 API calls 95471->95472 95473 a8a6e7 95472->95473 95474 a9fe0b 22 API calls 95473->95474 95474->95475 95475->95463 95477 a833fe _wcslen 95476->95477 95478 ac311d 95477->95478 95479 a83411 95477->95479 95481 a9fddb 22 API calls 95478->95481 95486 a8a587 95479->95486 95483 ac3127 95481->95483 95482 a8341e __fread_nolock 95482->95349 95484 a9fe0b 22 API calls 95483->95484 95485 ac3157 __fread_nolock 95484->95485 95487 a8a59d 95486->95487 95490 a8a598 __fread_nolock 95486->95490 95488 a9fe0b 22 API calls 95487->95488 95489 acf80f 95487->95489 95488->95490 95489->95489 95490->95482 95492 a863b6 __fread_nolock 95491->95492 95493 a86382 95491->95493 95492->95358 95493->95492 95494 ac4a82 95493->95494 95495 a863a9 95493->95495 95496 a9fddb 22 API calls 95494->95496 95497 a8a587 22 API calls 95495->95497 95498 ac4a91 95496->95498 95497->95492 95499 a9fe0b 22 API calls 95498->95499 95500 ac4ac5 __fread_nolock 95499->95500 95501->95359 95502->95360 95503 a82de3 95504 a82df0 __wsopen_s 95503->95504 95505 a82e09 95504->95505 95506 ac2c2b ___scrt_fastfail 95504->95506 95507 a83aa2 23 API calls 95505->95507 95509 ac2c47 GetOpenFileNameW 95506->95509 95508 a82e12 95507->95508 95519 a82da5 95508->95519 95511 ac2c96 95509->95511 95513 a86b57 22 API calls 95511->95513 95515 ac2cab 95513->95515 95515->95515 95516 a82e27 95537 a844a8 95516->95537 95520 ac1f50 __wsopen_s 95519->95520 95521 a82db2 GetLongPathNameW 95520->95521 95522 a86b57 22 API calls 95521->95522 95523 a82dda 95522->95523 95524 a83598 95523->95524 95566 a8a961 95524->95566 95527 a83aa2 23 API calls 95528 a835b5 95527->95528 95529 ac32eb 95528->95529 95530 a835c0 95528->95530 95535 ac330d 95529->95535 95583 a9ce60 41 API calls 95529->95583 95571 a8515f 95530->95571 95536 a835df 95536->95516 95584 a84ecb 95537->95584 95540 ac3833 95606 af2cf9 95540->95606 95541 a84ecb 94 API calls 95543 a844e1 95541->95543 95543->95540 95545 a844e9 95543->95545 95544 ac3848 95546 ac384c 95544->95546 95547 ac3869 95544->95547 95549 ac3854 95545->95549 95550 a844f5 95545->95550 95633 a84f39 95546->95633 95548 a9fe0b 22 API calls 95547->95548 95557 ac38ae 95548->95557 95639 aeda5a 82 API calls 95549->95639 95632 a8940c 136 API calls 2 library calls 95550->95632 95554 a82e31 95555 ac3862 95555->95547 95556 a84f39 68 API calls 95560 ac3a5f 95556->95560 95557->95560 95563 a89cb3 22 API calls 95557->95563 95640 ae967e 22 API calls __fread_nolock 95557->95640 95641 ae95ad 42 API calls _wcslen 95557->95641 95642 af0b5a 22 API calls 95557->95642 95643 a8a4a1 22 API calls __fread_nolock 95557->95643 95644 a83ff7 22 API calls 95557->95644 95560->95556 95645 ae989b 82 API calls __wsopen_s 95560->95645 95563->95557 95567 a9fe0b 22 API calls 95566->95567 95568 a8a976 95567->95568 95569 a9fddb 22 API calls 95568->95569 95570 a835aa 95569->95570 95570->95527 95572 a8516e 95571->95572 95576 a8518f __fread_nolock 95571->95576 95574 a9fe0b 22 API calls 95572->95574 95573 a9fddb 22 API calls 95575 a835cc 95573->95575 95574->95576 95577 a835f3 95575->95577 95576->95573 95578 a83605 95577->95578 95582 a83624 __fread_nolock 95577->95582 95580 a9fe0b 22 API calls 95578->95580 95579 a9fddb 22 API calls 95581 a8363b 95579->95581 95580->95582 95581->95536 95582->95579 95583->95529 95646 a84e90 LoadLibraryA 95584->95646 95589 ac3ccf 95591 a84f39 68 API calls 95589->95591 95590 a84ef6 LoadLibraryExW 95654 a84e59 LoadLibraryA 95590->95654 95593 ac3cd6 95591->95593 95595 a84e59 3 API calls 95593->95595 95597 ac3cde 95595->95597 95676 a850f5 40 API calls __fread_nolock 95597->95676 95598 a84f20 95598->95597 95599 a84f2c 95598->95599 95601 a84f39 68 API calls 95599->95601 95603 a844cd 95601->95603 95602 ac3cf5 95677 af28fe 27 API calls 95602->95677 95603->95540 95603->95541 95605 ac3d05 95607 af2d15 95606->95607 95744 a8511f 64 API calls 95607->95744 95609 af2d29 95745 af2e66 75 API calls 95609->95745 95611 af2d3b 95612 af2d3f 95611->95612 95746 a850f5 40 API calls __fread_nolock 95611->95746 95612->95544 95614 af2d56 95747 a850f5 40 API calls __fread_nolock 95614->95747 95616 af2d66 95748 a850f5 40 API calls __fread_nolock 95616->95748 95618 af2d81 95749 a850f5 40 API calls __fread_nolock 95618->95749 95620 af2d9c 95750 a8511f 64 API calls 95620->95750 95622 af2db3 95623 aaea0c ___std_exception_copy 21 API calls 95622->95623 95624 af2dba 95623->95624 95625 aaea0c ___std_exception_copy 21 API calls 95624->95625 95626 af2dc4 95625->95626 95751 a850f5 40 API calls __fread_nolock 95626->95751 95628 af2dd8 95752 af28fe 27 API calls 95628->95752 95630 af2dee 95630->95612 95753 af22ce 95630->95753 95632->95554 95634 a84f43 95633->95634 95636 a84f4a 95633->95636 95635 aae678 67 API calls 95634->95635 95635->95636 95637 a84f59 95636->95637 95638 a84f6a FreeLibrary 95636->95638 95637->95549 95638->95637 95639->95555 95640->95557 95641->95557 95642->95557 95643->95557 95644->95557 95645->95560 95647 a84ea8 GetProcAddress 95646->95647 95648 a84ec6 95646->95648 95649 a84eb8 95647->95649 95651 aae5eb 95648->95651 95649->95648 95650 a84ebf FreeLibrary 95649->95650 95650->95648 95678 aae52a 95651->95678 95653 a84eea 95653->95589 95653->95590 95655 a84e8d 95654->95655 95656 a84e6e GetProcAddress 95654->95656 95659 a84f80 95655->95659 95657 a84e7e 95656->95657 95657->95655 95658 a84e86 FreeLibrary 95657->95658 95658->95655 95660 a9fe0b 22 API calls 95659->95660 95661 a84f95 95660->95661 95730 a85722 95661->95730 95663 a84fa1 __fread_nolock 95664 ac3d1d 95663->95664 95665 a850a5 95663->95665 95675 a84fdc 95663->95675 95741 af304d 74 API calls 95664->95741 95733 a842a2 CreateStreamOnHGlobal 95665->95733 95668 ac3d22 95742 a8511f 64 API calls 95668->95742 95671 ac3d45 95743 a850f5 40 API calls __fread_nolock 95671->95743 95673 a8506e ISource 95673->95598 95675->95668 95675->95673 95739 a850f5 40 API calls __fread_nolock 95675->95739 95740 a8511f 64 API calls 95675->95740 95676->95602 95677->95605 95680 aae536 ___BuildCatchObject 95678->95680 95679 aae544 95703 aaf2d9 20 API calls _abort 95679->95703 95680->95679 95683 aae574 95680->95683 95682 aae549 95704 ab27ec 26 API calls __cftof 95682->95704 95685 aae579 95683->95685 95686 aae586 95683->95686 95705 aaf2d9 20 API calls _abort 95685->95705 95695 ab8061 95686->95695 95689 aae58f 95690 aae5a2 95689->95690 95691 aae595 95689->95691 95707 aae5d4 LeaveCriticalSection __fread_nolock 95690->95707 95706 aaf2d9 20 API calls _abort 95691->95706 95692 aae554 __wsopen_s 95692->95653 95696 ab806d ___BuildCatchObject 95695->95696 95708 ab2f5e EnterCriticalSection 95696->95708 95698 ab807b 95709 ab80fb 95698->95709 95702 ab80ac __wsopen_s 95702->95689 95703->95682 95704->95692 95705->95692 95706->95692 95707->95692 95708->95698 95716 ab811e 95709->95716 95710 ab8088 95722 ab80b7 95710->95722 95711 ab8177 95712 ab4c7d _abort 20 API calls 95711->95712 95713 ab8180 95712->95713 95715 ab29c8 _free 20 API calls 95713->95715 95717 ab8189 95715->95717 95716->95710 95716->95711 95725 aa918d EnterCriticalSection 95716->95725 95726 aa91a1 LeaveCriticalSection 95716->95726 95717->95710 95727 ab3405 11 API calls 2 library calls 95717->95727 95719 ab81a8 95728 aa918d EnterCriticalSection 95719->95728 95729 ab2fa6 LeaveCriticalSection 95722->95729 95724 ab80be 95724->95702 95725->95716 95726->95716 95727->95719 95728->95710 95729->95724 95731 a9fddb 22 API calls 95730->95731 95732 a85734 95731->95732 95732->95663 95734 a842bc FindResourceExW 95733->95734 95735 a842d9 95733->95735 95734->95735 95736 ac35ba LoadResource 95734->95736 95735->95675 95736->95735 95737 ac35cf SizeofResource 95736->95737 95737->95735 95738 ac35e3 LockResource 95737->95738 95738->95735 95739->95675 95740->95675 95741->95668 95742->95671 95743->95673 95744->95609 95745->95611 95746->95614 95747->95616 95748->95618 95749->95620 95750->95622 95751->95628 95752->95630 95754 af22d9 95753->95754 95755 af22e7 95753->95755 95756 aae5eb 29 API calls 95754->95756 95757 af232c 95755->95757 95758 aae5eb 29 API calls 95755->95758 95776 af22f0 95755->95776 95756->95755 95782 af2557 40 API calls __fread_nolock 95757->95782 95759 af2311 95758->95759 95759->95757 95761 af231a 95759->95761 95761->95776 95790 aae678 95761->95790 95762 af2370 95763 af2395 95762->95763 95764 af2374 95762->95764 95783 af2171 95763->95783 95767 af2381 95764->95767 95768 aae678 67 API calls 95764->95768 95770 aae678 67 API calls 95767->95770 95767->95776 95768->95767 95769 af239d 95771 af23c3 95769->95771 95772 af23a3 95769->95772 95770->95776 95803 af23f3 74 API calls 95771->95803 95774 af23b0 95772->95774 95775 aae678 67 API calls 95772->95775 95774->95776 95777 aae678 67 API calls 95774->95777 95775->95774 95776->95612 95777->95776 95778 af23ca 95779 aae678 67 API calls 95778->95779 95780 af23de 95778->95780 95779->95780 95780->95776 95781 aae678 67 API calls 95780->95781 95781->95776 95782->95762 95784 aaea0c ___std_exception_copy 21 API calls 95783->95784 95785 af217f 95784->95785 95786 aaea0c ___std_exception_copy 21 API calls 95785->95786 95787 af2190 95786->95787 95788 aaea0c ___std_exception_copy 21 API calls 95787->95788 95789 af219c 95788->95789 95789->95769 95791 aae684 ___BuildCatchObject 95790->95791 95792 aae695 95791->95792 95794 aae6aa 95791->95794 95821 aaf2d9 20 API calls _abort 95792->95821 95802 aae6a5 __wsopen_s 95794->95802 95804 aa918d EnterCriticalSection 95794->95804 95796 aae69a 95822 ab27ec 26 API calls __cftof 95796->95822 95797 aae6c6 95805 aae602 95797->95805 95800 aae6d1 95823 aae6ee LeaveCriticalSection __fread_nolock 95800->95823 95802->95776 95803->95778 95804->95797 95806 aae60f 95805->95806 95807 aae624 95805->95807 95856 aaf2d9 20 API calls _abort 95806->95856 95813 aae61f 95807->95813 95824 aadc0b 95807->95824 95809 aae614 95857 ab27ec 26 API calls __cftof 95809->95857 95813->95800 95817 aae646 95841 ab862f 95817->95841 95820 ab29c8 _free 20 API calls 95820->95813 95821->95796 95822->95802 95823->95802 95825 aadc23 95824->95825 95829 aadc1f 95824->95829 95826 aad955 __fread_nolock 26 API calls 95825->95826 95825->95829 95827 aadc43 95826->95827 95858 ab59be 62 API calls 4 library calls 95827->95858 95830 ab4d7a 95829->95830 95831 ab4d90 95830->95831 95832 aae640 95830->95832 95831->95832 95833 ab29c8 _free 20 API calls 95831->95833 95834 aad955 95832->95834 95833->95832 95835 aad961 95834->95835 95836 aad976 95834->95836 95859 aaf2d9 20 API calls _abort 95835->95859 95836->95817 95838 aad966 95860 ab27ec 26 API calls __cftof 95838->95860 95840 aad971 95840->95817 95842 ab863e 95841->95842 95843 ab8653 95841->95843 95864 aaf2c6 20 API calls _abort 95842->95864 95845 ab868e 95843->95845 95849 ab867a 95843->95849 95866 aaf2c6 20 API calls _abort 95845->95866 95846 ab8643 95865 aaf2d9 20 API calls _abort 95846->95865 95861 ab8607 95849->95861 95850 ab8693 95867 aaf2d9 20 API calls _abort 95850->95867 95853 ab869b 95868 ab27ec 26 API calls __cftof 95853->95868 95854 aae64c 95854->95813 95854->95820 95856->95809 95857->95813 95858->95829 95859->95838 95860->95840 95869 ab8585 95861->95869 95863 ab862b 95863->95854 95864->95846 95865->95854 95866->95850 95867->95853 95868->95854 95870 ab8591 ___BuildCatchObject 95869->95870 95880 ab5147 EnterCriticalSection 95870->95880 95872 ab859f 95873 ab85d1 95872->95873 95874 ab85c6 95872->95874 95881 aaf2d9 20 API calls _abort 95873->95881 95875 ab86ae __wsopen_s 29 API calls 95874->95875 95877 ab85cc 95875->95877 95882 ab85fb LeaveCriticalSection __wsopen_s 95877->95882 95879 ab85ee __wsopen_s 95879->95863 95880->95872 95881->95877 95882->95879 95883 a81044 95888 a810f3 95883->95888 95885 a8104a 95924 aa00a3 29 API calls __onexit 95885->95924 95887 a81054 95925 a81398 95888->95925 95892 a8116a 95893 a8a961 22 API calls 95892->95893 95894 a81174 95893->95894 95895 a8a961 22 API calls 95894->95895 95896 a8117e 95895->95896 95897 a8a961 22 API calls 95896->95897 95898 a81188 95897->95898 95899 a8a961 22 API calls 95898->95899 95900 a811c6 95899->95900 95901 a8a961 22 API calls 95900->95901 95902 a81292 95901->95902 95935 a8171c 95902->95935 95906 a812c4 95907 a8a961 22 API calls 95906->95907 95908 a812ce 95907->95908 95956 a91940 95908->95956 95910 a812f9 95966 a81aab 95910->95966 95912 a81315 95913 a81325 GetStdHandle 95912->95913 95914 a8137a 95913->95914 95915 ac2485 95913->95915 95918 a81387 OleInitialize 95914->95918 95915->95914 95916 ac248e 95915->95916 95917 a9fddb 22 API calls 95916->95917 95919 ac2495 95917->95919 95918->95885 95973 af011d InitializeCriticalSectionAndSpinCount InterlockedExchange GetCurrentProcess GetCurrentProcess DuplicateHandle 95919->95973 95921 ac249e 95974 af0944 CreateThread 95921->95974 95923 ac24aa CloseHandle 95923->95914 95924->95887 95975 a813f1 95925->95975 95928 a813f1 22 API calls 95929 a813d0 95928->95929 95930 a8a961 22 API calls 95929->95930 95931 a813dc 95930->95931 95932 a86b57 22 API calls 95931->95932 95933 a81129 95932->95933 95934 a81bc3 6 API calls 95933->95934 95934->95892 95936 a8a961 22 API calls 95935->95936 95937 a8172c 95936->95937 95938 a8a961 22 API calls 95937->95938 95939 a81734 95938->95939 95940 a8a961 22 API calls 95939->95940 95941 a8174f 95940->95941 95942 a9fddb 22 API calls 95941->95942 95943 a8129c 95942->95943 95944 a81b4a 95943->95944 95945 a81b58 95944->95945 95946 a8a961 22 API calls 95945->95946 95947 a81b63 95946->95947 95948 a8a961 22 API calls 95947->95948 95949 a81b6e 95948->95949 95950 a8a961 22 API calls 95949->95950 95951 a81b79 95950->95951 95952 a8a961 22 API calls 95951->95952 95953 a81b84 95952->95953 95954 a9fddb 22 API calls 95953->95954 95955 a81b96 RegisterWindowMessageW 95954->95955 95955->95906 95957 a91981 95956->95957 95964 a9195d 95956->95964 95982 aa0242 5 API calls __Init_thread_wait 95957->95982 95958 a9196e 95958->95910 95960 a9198b 95960->95964 95983 aa01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent 95960->95983 95962 a98727 95962->95958 95985 aa01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent 95962->95985 95964->95958 95984 aa0242 5 API calls __Init_thread_wait 95964->95984 95967 ac272d 95966->95967 95968 a81abb 95966->95968 95986 af3209 23 API calls 95967->95986 95969 a9fddb 22 API calls 95968->95969 95971 a81ac3 95969->95971 95971->95912 95972 ac2738 95973->95921 95974->95923 95987 af092a 28 API calls 95974->95987 95976 a8a961 22 API calls 95975->95976 95977 a813fc 95976->95977 95978 a8a961 22 API calls 95977->95978 95979 a81404 95978->95979 95980 a8a961 22 API calls 95979->95980 95981 a813c6 95980->95981 95981->95928 95982->95960 95983->95964 95984->95962 95985->95958 95986->95972 95988 ad2a00 96004 a8d7b0 ISource 95988->96004 95989 a8db11 PeekMessageW 95989->96004 95990 a8d807 GetInputState 95990->95989 95990->96004 95992 ad1cbe TranslateAcceleratorW 95992->96004 95993 a8da04 timeGetTime 95993->96004 95994 a8db8f PeekMessageW 95994->96004 95995 a8db73 TranslateMessage DispatchMessageW 95995->95994 95996 a8dbaf Sleep 95996->96004 95997 ad2b74 Sleep 96010 ad2ae5 95997->96010 96000 ad1dda timeGetTime 96148 a9e300 23 API calls 96000->96148 96003 ad2c0b GetExitCodeProcess 96007 ad2c37 CloseHandle 96003->96007 96008 ad2c21 WaitForSingleObject 96003->96008 96004->95989 96004->95990 96004->95992 96004->95993 96004->95994 96004->95995 96004->95996 96004->95997 96004->96000 96005 b129bf GetForegroundWindow 96004->96005 96009 a8d9d5 96004->96009 96004->96010 96020 a8dd50 96004->96020 96027 a91310 96004->96027 96083 a8bf40 96004->96083 96141 a9edf6 96004->96141 96146 a8dfd0 349 API calls 3 library calls 96004->96146 96147 a9e551 timeGetTime 96004->96147 96149 af3a2a 23 API calls 96004->96149 96150 a8ec40 96004->96150 96174 af359c 82 API calls __wsopen_s 96004->96174 96005->96004 96007->96010 96008->96004 96008->96007 96010->96003 96010->96004 96010->96009 96011 ad2ca9 Sleep 96010->96011 96175 b05658 23 API calls 96010->96175 96176 aee97b QueryPerformanceCounter QueryPerformanceFrequency Sleep QueryPerformanceCounter Sleep 96010->96176 96177 a9e551 timeGetTime 96010->96177 96178 aed4dc 47 API calls 96010->96178 96011->96004 96021 a8dd6f 96020->96021 96022 a8dd83 96020->96022 96179 a8d260 96021->96179 96211 af359c 82 API calls __wsopen_s 96022->96211 96024 a8dd7a 96024->96004 96026 ad2f75 96026->96026 96028 a917b0 96027->96028 96029 a91376 96027->96029 96267 aa0242 5 API calls __Init_thread_wait 96028->96267 96031 a91390 96029->96031 96032 ad6331 96029->96032 96036 a91940 9 API calls 96031->96036 96033 ad633d 96032->96033 96281 b0709c 349 API calls 96032->96281 96033->96004 96035 a917ba 96038 a917fb 96035->96038 96040 a89cb3 22 API calls 96035->96040 96037 a913a0 96036->96037 96039 a91940 9 API calls 96037->96039 96042 ad6346 96038->96042 96044 a9182c 96038->96044 96041 a913b6 96039->96041 96048 a917d4 96040->96048 96041->96038 96043 a913ec 96041->96043 96282 af359c 82 API calls __wsopen_s 96042->96282 96043->96042 96068 a91408 __fread_nolock 96043->96068 96269 a8aceb 96044->96269 96047 a91839 96279 a9d217 349 API calls 96047->96279 96268 aa01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent 96048->96268 96051 ad636e 96283 af359c 82 API calls __wsopen_s 96051->96283 96052 a9152f 96054 a9153c 96052->96054 96055 ad63d1 96052->96055 96056 a91940 9 API calls 96054->96056 96285 b05745 54 API calls _wcslen 96055->96285 96058 a91549 96056->96058 96062 a91940 9 API calls 96058->96062 96073 a915c7 ISource 96058->96073 96059 a9fddb 22 API calls 96059->96068 96060 a9fe0b 22 API calls 96060->96068 96061 a91872 96280 a9faeb 23 API calls 96061->96280 96069 a91563 96062->96069 96063 a9171d 96063->96004 96066 a8ec40 349 API calls 96066->96068 96067 a9167b ISource 96067->96063 96266 a9ce17 22 API calls ISource 96067->96266 96068->96047 96068->96051 96068->96052 96068->96059 96068->96060 96068->96066 96070 ad63b2 96068->96070 96068->96073 96069->96073 96286 a8a8c7 22 API calls __fread_nolock 96069->96286 96284 af359c 82 API calls __wsopen_s 96070->96284 96072 a91940 9 API calls 96072->96073 96073->96061 96073->96067 96073->96072 96219 b0abf7 96073->96219 96224 af5c5a 96073->96224 96229 b0a67c CreateToolhelp32Snapshot Process32FirstW 96073->96229 96249 b0ab67 96073->96249 96252 b119bc 96073->96252 96255 a9f645 96073->96255 96262 b129bf 96073->96262 96287 af359c 82 API calls __wsopen_s 96073->96287 96538 a8adf0 96083->96538 96085 a8bf9d 96086 a8bfa9 96085->96086 96087 ad04b6 96085->96087 96089 ad04c6 96086->96089 96090 a8c01e 96086->96090 96556 af359c 82 API calls __wsopen_s 96087->96556 96557 af359c 82 API calls __wsopen_s 96089->96557 96543 a8ac91 96090->96543 96093 a8c7da 96097 a9fe0b 22 API calls 96093->96097 96103 a8c808 __fread_nolock 96097->96103 96100 ad04f5 96102 ad055a 96100->96102 96558 a9d217 349 API calls 96100->96558 96128 a8c603 96102->96128 96559 af359c 82 API calls __wsopen_s 96102->96559 96106 a9fe0b 22 API calls 96103->96106 96104 ae7120 22 API calls 96138 a8c039 ISource __fread_nolock 96104->96138 96105 ad091a 96568 af3209 23 API calls 96105->96568 96139 a8c350 ISource __fread_nolock 96106->96139 96107 a8af8a 22 API calls 96107->96138 96108 a9fddb 22 API calls 96108->96138 96111 a8ec40 349 API calls 96111->96138 96112 ad08a5 96113 a8ec40 349 API calls 96112->96113 96115 ad08cf 96113->96115 96115->96128 96566 a8a81b 41 API calls 96115->96566 96116 ad0591 96560 af359c 82 API calls __wsopen_s 96116->96560 96117 ad08f6 96567 af359c 82 API calls __wsopen_s 96117->96567 96122 a8bbe0 40 API calls 96122->96138 96123 a8aceb 23 API calls 96123->96138 96124 a8c237 96125 a8c253 96124->96125 96569 a8a8c7 22 API calls __fread_nolock 96124->96569 96129 ad0976 96125->96129 96133 a8c297 ISource 96125->96133 96126 a9fe0b 22 API calls 96126->96138 96128->96004 96131 a8aceb 23 API calls 96129->96131 96132 ad09bf 96131->96132 96132->96128 96570 af359c 82 API calls __wsopen_s 96132->96570 96133->96132 96134 a8aceb 23 API calls 96133->96134 96135 a8c335 96134->96135 96135->96132 96136 a8c342 96135->96136 96554 a8a704 22 API calls ISource 96136->96554 96138->96093 96138->96100 96138->96102 96138->96103 96138->96104 96138->96105 96138->96107 96138->96108 96138->96111 96138->96112 96138->96116 96138->96117 96138->96122 96138->96123 96138->96124 96138->96126 96138->96128 96138->96132 96547 a8ad81 96138->96547 96561 ae7099 22 API calls __fread_nolock 96138->96561 96562 b05745 54 API calls _wcslen 96138->96562 96563 a9aa42 22 API calls ISource 96138->96563 96564 aef05c 40 API calls 96138->96564 96565 a8a993 41 API calls 96138->96565 96140 a8c3ac 96139->96140 96555 a9ce17 22 API calls ISource 96139->96555 96140->96004 96142 a9ee09 96141->96142 96143 a9ee12 96141->96143 96142->96004 96143->96142 96144 a9ee36 IsDialogMessageW 96143->96144 96145 adefaf GetClassLongW 96143->96145 96144->96142 96144->96143 96145->96143 96145->96144 96146->96004 96147->96004 96148->96004 96149->96004 96170 a8ec76 ISource 96150->96170 96151 aa00a3 29 API calls pre_c_initialization 96151->96170 96152 ad4beb 96587 af359c 82 API calls __wsopen_s 96152->96587 96153 a8fef7 96167 a8ed9d ISource 96153->96167 96583 a8a8c7 22 API calls __fread_nolock 96153->96583 96156 a9fddb 22 API calls 96156->96170 96157 ad4b0b 96585 af359c 82 API calls __wsopen_s 96157->96585 96158 a8f3ae ISource 96158->96167 96584 af359c 82 API calls __wsopen_s 96158->96584 96159 ad4600 96159->96167 96582 a8a8c7 22 API calls __fread_nolock 96159->96582 96163 a8a8c7 22 API calls 96163->96170 96166 aa0242 EnterCriticalSection LeaveCriticalSection LeaveCriticalSection WaitForSingleObjectEx EnterCriticalSection 96166->96170 96167->96004 96168 a8fbe3 96168->96158 96168->96167 96171 ad4bdc 96168->96171 96169 a8a961 22 API calls 96169->96170 96170->96151 96170->96152 96170->96153 96170->96156 96170->96157 96170->96158 96170->96159 96170->96163 96170->96166 96170->96167 96170->96168 96170->96169 96173 aa01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent __Init_thread_footer 96170->96173 96580 a901e0 349 API calls 2 library calls 96170->96580 96581 a906a0 41 API calls ISource 96170->96581 96586 af359c 82 API calls __wsopen_s 96171->96586 96173->96170 96174->96004 96175->96010 96176->96010 96177->96010 96178->96010 96180 a8ec40 349 API calls 96179->96180 96185 a8d29d 96180->96185 96181 ad1bc4 96218 af359c 82 API calls __wsopen_s 96181->96218 96183 a8d30b ISource 96183->96024 96184 a8d6d5 96184->96183 96196 a9fe0b 22 API calls 96184->96196 96185->96181 96185->96183 96185->96184 96186 a8d3c3 96185->96186 96189 a8d4b8 96185->96189 96195 a9fddb 22 API calls 96185->96195 96206 a8d429 ISource __fread_nolock 96185->96206 96186->96184 96188 a8d3ce 96186->96188 96187 a8d5ff 96191 ad1bb5 96187->96191 96192 a8d614 96187->96192 96190 a9fddb 22 API calls 96188->96190 96198 a9fe0b 22 API calls 96189->96198 96197 a8d3d5 __fread_nolock 96190->96197 96217 b05705 23 API calls 96191->96217 96194 a9fddb 22 API calls 96192->96194 96204 a8d46a 96194->96204 96195->96185 96196->96197 96199 a8d3f6 96197->96199 96200 a9fddb 22 API calls 96197->96200 96198->96206 96199->96206 96212 a8bec0 349 API calls 96199->96212 96200->96199 96202 ad1ba4 96216 af359c 82 API calls __wsopen_s 96202->96216 96204->96024 96206->96187 96206->96202 96206->96204 96207 ad1b7f 96206->96207 96209 ad1b5d 96206->96209 96213 a81f6f 349 API calls 96206->96213 96215 af359c 82 API calls __wsopen_s 96207->96215 96214 af359c 82 API calls __wsopen_s 96209->96214 96211->96026 96212->96206 96213->96206 96214->96204 96215->96204 96216->96204 96217->96181 96218->96183 96288 b0aff9 96219->96288 96221 b0ac54 96221->96073 96222 b0ac0c 96222->96221 96223 a8aceb 23 API calls 96222->96223 96223->96221 96225 a87510 53 API calls 96224->96225 96226 af5c6d 96225->96226 96443 aedbbe lstrlenW 96226->96443 96228 af5c77 96228->96073 96237 b0a6c3 96229->96237 96230 a8a961 22 API calls 96230->96237 96231 a89cb3 22 API calls 96231->96237 96233 a86350 22 API calls 96233->96237 96235 a87510 53 API calls 96235->96237 96237->96230 96237->96231 96237->96233 96237->96235 96238 b0a796 Process32NextW 96237->96238 96448 a8525f 96237->96448 96496 a9ce60 41 API calls 96237->96496 96497 b0b574 22 API calls __fread_nolock 96237->96497 96238->96237 96239 b0a7aa CloseHandle 96238->96239 96490 a863eb 96239->96490 96243 b0a7cd 96499 a904f0 22 API calls 96243->96499 96245 b0a87d 96245->96073 96246 a904f0 22 API calls 96248 b0a7d9 96246->96248 96248->96245 96248->96246 96500 a862b5 22 API calls 96248->96500 96250 b0aff9 217 API calls 96249->96250 96251 b0ab79 96250->96251 96251->96073 96525 b12ad8 96252->96525 96254 b119cb 96254->96073 96256 a8b567 39 API calls 96255->96256 96257 a9f659 96256->96257 96258 adf2dc Sleep 96257->96258 96259 a9f661 timeGetTime 96257->96259 96260 a8b567 39 API calls 96259->96260 96261 a9f677 96260->96261 96261->96073 96263 b129cb 96262->96263 96264 b12a01 GetForegroundWindow 96263->96264 96265 b129d1 96263->96265 96264->96265 96265->96073 96266->96067 96267->96035 96268->96038 96270 a8acf9 96269->96270 96272 a8ad2a ISource 96269->96272 96271 a8ad55 96270->96271 96274 a8ad01 ISource 96270->96274 96271->96272 96536 a8a8c7 22 API calls __fread_nolock 96271->96536 96272->96047 96274->96272 96275 acfa48 96274->96275 96276 a8ad21 96274->96276 96275->96272 96537 a9ce17 22 API calls ISource 96275->96537 96276->96272 96277 acfa3a VariantClear 96276->96277 96277->96272 96279->96061 96280->96061 96281->96033 96282->96073 96283->96073 96284->96073 96285->96069 96286->96073 96287->96073 96289 b0b01d ___scrt_fastfail 96288->96289 96290 b0b094 96289->96290 96291 b0b058 96289->96291 96293 a8b567 39 API calls 96290->96293 96298 b0b08b 96290->96298 96409 a8b567 96291->96409 96297 b0b0a5 96293->96297 96294 b0b063 96294->96298 96302 a8b567 39 API calls 96294->96302 96295 b0b0ed 96379 a87510 96295->96379 96301 a8b567 39 API calls 96297->96301 96298->96295 96299 a8b567 39 API calls 96298->96299 96299->96295 96301->96298 96304 b0b078 96302->96304 96305 a8b567 39 API calls 96304->96305 96305->96298 96306 b0b115 96307 b0b1d8 96306->96307 96308 b0b11f 96306->96308 96309 b0b20a GetCurrentDirectoryW 96307->96309 96311 a87510 53 API calls 96307->96311 96310 a87510 53 API calls 96308->96310 96312 a9fe0b 22 API calls 96309->96312 96313 b0b130 96310->96313 96314 b0b1ef 96311->96314 96315 b0b22f GetCurrentDirectoryW 96312->96315 96316 a87620 22 API calls 96313->96316 96317 a87620 22 API calls 96314->96317 96318 b0b23c 96315->96318 96319 b0b13a 96316->96319 96320 b0b1f9 _wcslen 96317->96320 96322 b0b275 96318->96322 96414 a89c6e 22 API calls 96318->96414 96321 a87510 53 API calls 96319->96321 96320->96309 96320->96322 96323 b0b14b 96321->96323 96330 b0b287 96322->96330 96331 b0b28b 96322->96331 96325 a87620 22 API calls 96323->96325 96327 b0b155 96325->96327 96326 b0b255 96415 a89c6e 22 API calls 96326->96415 96329 a87510 53 API calls 96327->96329 96333 b0b166 96329->96333 96335 b0b2f8 96330->96335 96336 b0b39a CreateProcessW 96330->96336 96417 af07c0 10 API calls 96331->96417 96332 b0b265 96416 a89c6e 22 API calls 96332->96416 96338 a87620 22 API calls 96333->96338 96420 ae11c8 39 API calls 96335->96420 96378 b0b32f _wcslen 96336->96378 96341 b0b170 96338->96341 96339 b0b294 96418 af06e6 10 API calls 96339->96418 96344 b0b1a6 GetSystemDirectoryW 96341->96344 96348 a87510 53 API calls 96341->96348 96343 b0b2fd 96346 b0b323 96343->96346 96347 b0b32a 96343->96347 96350 a9fe0b 22 API calls 96344->96350 96345 b0b2aa 96419 af05a7 8 API calls 96345->96419 96421 ae1201 128 API calls 2 library calls 96346->96421 96422 ae14ce 6 API calls 96347->96422 96352 b0b187 96348->96352 96355 b0b1cb GetSystemDirectoryW 96350->96355 96357 a87620 22 API calls 96352->96357 96354 b0b2d0 96354->96330 96355->96318 96356 b0b328 96356->96378 96360 b0b191 _wcslen 96357->96360 96358 b0b3d6 GetLastError 96370 b0b41a 96358->96370 96359 b0b42f CloseHandle 96361 b0b43f 96359->96361 96371 b0b49a 96359->96371 96360->96318 96360->96344 96363 b0b451 96361->96363 96364 b0b446 CloseHandle 96361->96364 96366 b0b463 96363->96366 96367 b0b458 CloseHandle 96363->96367 96364->96363 96365 b0b4a6 96365->96370 96368 b0b475 96366->96368 96369 b0b46a CloseHandle 96366->96369 96367->96366 96423 af09d9 34 API calls 96368->96423 96369->96368 96406 af0175 96370->96406 96371->96365 96376 b0b4d2 CloseHandle 96371->96376 96375 b0b486 96424 b0b536 25 API calls 96375->96424 96376->96370 96378->96358 96378->96359 96380 a87525 96379->96380 96397 a87522 96379->96397 96381 a8755b 96380->96381 96382 a8752d 96380->96382 96385 ac500f 96381->96385 96386 a8756d 96381->96386 96393 ac50f6 96381->96393 96425 aa51c6 26 API calls 96382->96425 96387 ac5088 96385->96387 96396 a9fe0b 22 API calls 96385->96396 96426 a9fb21 51 API calls 96386->96426 96427 a9fb21 51 API calls 96387->96427 96388 ac510e 96388->96388 96391 a9fddb 22 API calls 96394 a87547 96391->96394 96392 a8753d 96392->96391 96428 aa5183 26 API calls 96393->96428 96395 a89cb3 22 API calls 96394->96395 96395->96397 96398 ac5058 96396->96398 96402 a87620 96397->96402 96399 a9fddb 22 API calls 96398->96399 96400 ac507f 96399->96400 96401 a89cb3 22 API calls 96400->96401 96401->96387 96403 a8762a _wcslen 96402->96403 96404 a9fe0b 22 API calls 96403->96404 96405 a8763f 96404->96405 96405->96306 96429 af030f 96406->96429 96410 a8b57f 96409->96410 96411 a8b578 96409->96411 96410->96294 96411->96410 96442 aa62d1 39 API calls 96411->96442 96413 a8b5c2 96413->96294 96414->96326 96415->96332 96416->96322 96417->96339 96418->96345 96419->96354 96420->96343 96421->96356 96422->96378 96423->96375 96424->96371 96425->96392 96426->96392 96427->96393 96428->96388 96430 af0329 96429->96430 96431 af0321 CloseHandle 96429->96431 96432 af032e CloseHandle 96430->96432 96433 af0336 96430->96433 96431->96430 96432->96433 96434 af033b CloseHandle 96433->96434 96435 af0343 96433->96435 96434->96435 96436 af0348 CloseHandle 96435->96436 96437 af0350 96435->96437 96436->96437 96438 af035d 96437->96438 96439 af0355 CloseHandle 96437->96439 96440 af017d 96438->96440 96441 af0362 CloseHandle 96438->96441 96439->96438 96440->96222 96441->96440 96442->96413 96444 aedbdc GetFileAttributesW 96443->96444 96445 aedc06 96443->96445 96444->96445 96446 aedbe8 FindFirstFileW 96444->96446 96445->96228 96446->96445 96447 aedbf9 FindClose 96446->96447 96447->96445 96449 a8a961 22 API calls 96448->96449 96450 a85275 96449->96450 96451 a8a961 22 API calls 96450->96451 96452 a8527d 96451->96452 96453 a8a961 22 API calls 96452->96453 96454 a85285 96453->96454 96455 a8a961 22 API calls 96454->96455 96456 a8528d 96455->96456 96457 ac3df5 96456->96457 96458 a852c1 96456->96458 96519 a8a8c7 22 API calls __fread_nolock 96457->96519 96460 a86d25 22 API calls 96458->96460 96462 a852cf 96460->96462 96461 ac3dfe 96463 a8a6c3 22 API calls 96461->96463 96464 a893b2 22 API calls 96462->96464 96466 a85304 96463->96466 96465 a852d9 96464->96465 96465->96466 96467 a86d25 22 API calls 96465->96467 96468 a85349 96466->96468 96469 a85325 96466->96469 96485 ac3e20 96466->96485 96471 a852fa 96467->96471 96501 a86d25 96468->96501 96469->96468 96514 a84c6d 96469->96514 96473 a893b2 22 API calls 96471->96473 96472 a8535a 96474 a85370 96472->96474 96517 a8a8c7 22 API calls __fread_nolock 96472->96517 96473->96466 96476 a85384 96474->96476 96518 a8a8c7 22 API calls __fread_nolock 96474->96518 96480 a8538f 96476->96480 96521 a8a8c7 22 API calls __fread_nolock 96476->96521 96478 a86b57 22 API calls 96487 ac3ee0 96478->96487 96488 a8539a 96480->96488 96522 a8a8c7 22 API calls __fread_nolock 96480->96522 96482 a86d25 22 API calls 96482->96468 96485->96478 96486 a84c6d 22 API calls 96486->96487 96487->96468 96487->96486 96520 a849bd 22 API calls __fread_nolock 96487->96520 96488->96237 96491 a863f3 96490->96491 96492 a9fddb 22 API calls 96491->96492 96493 a86401 96492->96493 96524 a86a26 22 API calls 96493->96524 96495 a86409 96498 a86a50 22 API calls 96495->96498 96496->96237 96497->96237 96498->96243 96499->96248 96500->96248 96502 a86d91 96501->96502 96503 a86d34 96501->96503 96504 a893b2 22 API calls 96502->96504 96503->96502 96505 a86d3f 96503->96505 96511 a86d62 __fread_nolock 96504->96511 96506 ac4c9d 96505->96506 96507 a86d5a 96505->96507 96508 a9fddb 22 API calls 96506->96508 96523 a86f34 22 API calls 96507->96523 96510 ac4ca7 96508->96510 96512 a9fe0b 22 API calls 96510->96512 96511->96472 96513 ac4cda 96512->96513 96515 a8aec9 22 API calls 96514->96515 96516 a84c78 96515->96516 96516->96468 96516->96482 96517->96474 96518->96476 96519->96461 96520->96487 96521->96480 96522->96488 96523->96511 96524->96495 96526 a8aceb 23 API calls 96525->96526 96527 b12af3 96526->96527 96528 b12b1d 96527->96528 96529 b12aff 96527->96529 96530 a86b57 22 API calls 96528->96530 96531 a87510 53 API calls 96529->96531 96532 b12b1b 96530->96532 96533 b12b0c 96531->96533 96532->96254 96533->96532 96535 a8a8c7 22 API calls __fread_nolock 96533->96535 96535->96532 96536->96272 96537->96272 96539 a8ae01 96538->96539 96542 a8ae1c ISource 96538->96542 96540 a8aec9 22 API calls 96539->96540 96541 a8ae09 CharUpperBuffW 96540->96541 96541->96542 96542->96085 96544 a8acae 96543->96544 96545 a8acd1 96544->96545 96571 af359c 82 API calls __wsopen_s 96544->96571 96545->96138 96548 acfadb 96547->96548 96549 a8ad92 96547->96549 96550 a9fddb 22 API calls 96549->96550 96551 a8ad99 96550->96551 96572 a8adcd 96551->96572 96554->96139 96555->96139 96556->96089 96557->96128 96558->96102 96559->96128 96560->96128 96561->96138 96562->96138 96563->96138 96564->96138 96565->96138 96566->96117 96567->96128 96568->96124 96569->96125 96570->96128 96571->96545 96576 a8addd 96572->96576 96573 a8adb6 96573->96138 96574 a9fddb 22 API calls 96574->96576 96575 a8a961 22 API calls 96575->96576 96576->96573 96576->96574 96576->96575 96578 a8adcd 22 API calls 96576->96578 96579 a8a8c7 22 API calls __fread_nolock 96576->96579 96578->96576 96579->96576 96580->96170 96581->96170 96582->96167 96583->96167 96584->96167 96585->96167 96586->96152 96587->96167 96588 ac2402 96591 a81410 96588->96591 96592 ac24b8 DestroyWindow 96591->96592 96593 a8144f mciSendStringW 96591->96593 96606 ac24c4 96592->96606 96594 a8146b 96593->96594 96595 a816c6 96593->96595 96596 a81479 96594->96596 96594->96606 96595->96594 96597 a816d5 UnregisterHotKey 96595->96597 96624 a8182e 96596->96624 96597->96595 96600 ac2509 96605 ac252d 96600->96605 96607 ac251c FreeLibrary 96600->96607 96601 ac24d8 96601->96606 96630 a86246 CloseHandle 96601->96630 96602 ac24e2 FindClose 96602->96606 96604 a8148e 96604->96605 96613 a8149c 96604->96613 96608 ac2541 VirtualFree 96605->96608 96615 a81509 96605->96615 96606->96600 96606->96601 96606->96602 96607->96600 96608->96605 96609 a814f8 CoUninitialize 96609->96615 96610 ac2589 96617 ac2598 ISource 96610->96617 96631 af32eb 6 API calls ISource 96610->96631 96611 a81514 96612 a81524 96611->96612 96628 a81944 VirtualFreeEx CloseHandle 96612->96628 96613->96609 96615->96610 96615->96611 96620 ac2627 96617->96620 96632 ae64d4 22 API calls ISource 96617->96632 96619 a8153a 96619->96617 96621 a8161f 96619->96621 96620->96620 96621->96620 96629 a81876 CloseHandle InternetCloseHandle InternetCloseHandle WaitForSingleObject 96621->96629 96623 a816c1 96626 a8183b 96624->96626 96625 a81480 96625->96600 96625->96604 96626->96625 96633 ae702a 22 API calls 96626->96633 96628->96619 96629->96623 96630->96601 96631->96610 96632->96617 96633->96626 96634 a81098 96639 a842de 96634->96639 96638 a810a7 96640 a8a961 22 API calls 96639->96640 96641 a842f5 GetVersionExW 96640->96641 96642 a86b57 22 API calls 96641->96642 96643 a84342 96642->96643 96644 a893b2 22 API calls 96643->96644 96656 a84378 96643->96656 96645 a8436c 96644->96645 96647 a837a0 22 API calls 96645->96647 96646 a8441b GetCurrentProcess IsWow64Process 96648 a84437 96646->96648 96647->96656 96649 a8444f LoadLibraryA 96648->96649 96650 ac3824 GetSystemInfo 96648->96650 96651 a8449c GetSystemInfo 96649->96651 96652 a84460 GetProcAddress 96649->96652 96653 a84476 96651->96653 96652->96651 96655 a84470 GetNativeSystemInfo 96652->96655 96657 a8447a FreeLibrary 96653->96657 96658 a8109d 96653->96658 96654 ac37df 96655->96653 96656->96646 96656->96654 96657->96658 96659 aa00a3 29 API calls __onexit 96658->96659 96659->96638 96660 aa03fb 96661 aa0407 ___BuildCatchObject 96660->96661 96689 a9feb1 96661->96689 96663 aa040e 96664 aa0561 96663->96664 96667 aa0438 96663->96667 96719 aa083f IsProcessorFeaturePresent IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter ___scrt_fastfail 96664->96719 96666 aa0568 96712 aa4e52 96666->96712 96678 aa0477 ___scrt_is_nonwritable_in_current_image ___scrt_release_startup_lock 96667->96678 96700 ab247d 96667->96700 96674 aa0457 96676 aa04d8 96708 aa0959 96676->96708 96678->96676 96715 aa4e1a 38 API calls 3 library calls 96678->96715 96680 aa04de 96681 aa04f3 96680->96681 96716 aa0992 GetModuleHandleW 96681->96716 96683 aa04fa 96683->96666 96684 aa04fe 96683->96684 96685 aa0507 96684->96685 96717 aa4df5 28 API calls _abort 96684->96717 96718 aa0040 13 API calls 2 library calls 96685->96718 96688 aa050f 96688->96674 96690 a9feba 96689->96690 96721 aa0698 IsProcessorFeaturePresent 96690->96721 96692 a9fec6 96722 aa2c94 10 API calls 3 library calls 96692->96722 96694 a9fecb 96695 a9fecf 96694->96695 96723 ab2317 96694->96723 96695->96663 96698 a9fee6 96698->96663 96701 ab2494 96700->96701 96702 aa0a8c __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 96701->96702 96703 aa0451 96702->96703 96703->96674 96704 ab2421 96703->96704 96705 ab2450 96704->96705 96706 aa0a8c __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 96705->96706 96707 ab2479 96706->96707 96707->96678 96774 aa2340 96708->96774 96711 aa097f 96711->96680 96776 aa4bcf 96712->96776 96715->96676 96716->96683 96717->96685 96718->96688 96719->96666 96721->96692 96722->96694 96727 abd1f6 96723->96727 96726 aa2cbd 8 API calls 3 library calls 96726->96695 96730 abd213 96727->96730 96731 abd20f 96727->96731 96729 a9fed8 96729->96698 96729->96726 96730->96731 96733 ab4bfb 96730->96733 96745 aa0a8c 96731->96745 96734 ab4c07 ___BuildCatchObject 96733->96734 96752 ab2f5e EnterCriticalSection 96734->96752 96736 ab4c0e 96753 ab50af 96736->96753 96738 ab4c1d 96739 ab4c2c 96738->96739 96766 ab4a8f 29 API calls 96738->96766 96768 ab4c48 LeaveCriticalSection _abort 96739->96768 96742 ab4c3d __wsopen_s 96742->96730 96743 ab4c27 96767 ab4b45 GetStdHandle GetFileType 96743->96767 96746 aa0a97 IsProcessorFeaturePresent 96745->96746 96747 aa0a95 96745->96747 96749 aa0c5d 96746->96749 96747->96729 96773 aa0c21 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 96749->96773 96751 aa0d40 96751->96729 96752->96736 96754 ab50bb ___BuildCatchObject 96753->96754 96755 ab50c8 96754->96755 96756 ab50df 96754->96756 96770 aaf2d9 20 API calls _abort 96755->96770 96769 ab2f5e EnterCriticalSection 96756->96769 96759 ab50cd 96771 ab27ec 26 API calls __cftof 96759->96771 96761 ab5117 96772 ab513e LeaveCriticalSection _abort 96761->96772 96762 ab50d7 __wsopen_s 96762->96738 96763 ab50eb 96763->96761 96765 ab5000 __wsopen_s 21 API calls 96763->96765 96765->96763 96766->96743 96767->96739 96768->96742 96769->96763 96770->96759 96771->96762 96772->96762 96773->96751 96775 aa096c GetStartupInfoW 96774->96775 96775->96711 96777 aa4bdb _unexpected 96776->96777 96778 aa4be2 96777->96778 96779 aa4bf4 96777->96779 96815 aa4d29 GetModuleHandleW 96778->96815 96800 ab2f5e EnterCriticalSection 96779->96800 96782 aa4be7 96782->96779 96816 aa4d6d GetModuleHandleExW 96782->96816 96783 aa4c99 96804 aa4cd9 96783->96804 96786 aa4bfb 96786->96783 96788 aa4c70 96786->96788 96801 ab21a8 96786->96801 96790 aa4c88 96788->96790 96794 ab2421 _abort 5 API calls 96788->96794 96795 ab2421 _abort 5 API calls 96790->96795 96791 aa4ce2 96824 ac1d29 5 API calls __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 96791->96824 96792 aa4cb6 96807 aa4ce8 96792->96807 96794->96790 96795->96783 96800->96786 96825 ab1ee1 96801->96825 96844 ab2fa6 LeaveCriticalSection 96804->96844 96806 aa4cb2 96806->96791 96806->96792 96845 ab360c 96807->96845 96810 aa4d16 96813 aa4d6d _abort 8 API calls 96810->96813 96811 aa4cf6 GetPEB 96811->96810 96812 aa4d06 GetCurrentProcess TerminateProcess 96811->96812 96812->96810 96814 aa4d1e ExitProcess 96813->96814 96815->96782 96817 aa4dba 96816->96817 96818 aa4d97 GetProcAddress 96816->96818 96820 aa4dc9 96817->96820 96821 aa4dc0 FreeLibrary 96817->96821 96819 aa4dac 96818->96819 96819->96817 96822 aa0a8c __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 96820->96822 96821->96820 96823 aa4bf3 96822->96823 96823->96779 96828 ab1e90 96825->96828 96827 ab1f05 96827->96788 96829 ab1e9c ___BuildCatchObject 96828->96829 96836 ab2f5e EnterCriticalSection 96829->96836 96831 ab1eaa 96837 ab1f31 96831->96837 96835 ab1ec8 __wsopen_s 96835->96827 96836->96831 96840 ab1f59 96837->96840 96841 ab1f51 96837->96841 96838 aa0a8c __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 96839 ab1eb7 96838->96839 96843 ab1ed5 LeaveCriticalSection _abort 96839->96843 96840->96841 96842 ab29c8 _free 20 API calls 96840->96842 96841->96838 96842->96841 96843->96835 96844->96806 96846 ab3631 96845->96846 96847 ab3627 96845->96847 96852 ab2fd7 5 API calls 2 library calls 96846->96852 96849 aa0a8c __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 96847->96849 96850 aa4cf2 96849->96850 96850->96810 96850->96811 96851 ab3648 96851->96847 96852->96851 96853 a8105b 96858 a8344d 96853->96858 96855 a8106a 96889 aa00a3 29 API calls __onexit 96855->96889 96857 a81074 96859 a8345d __wsopen_s 96858->96859 96860 a8a961 22 API calls 96859->96860 96861 a83513 96860->96861 96862 a83a5a 24 API calls 96861->96862 96863 a8351c 96862->96863 96890 a83357 96863->96890 96866 a833c6 22 API calls 96867 a83535 96866->96867 96868 a8515f 22 API calls 96867->96868 96869 a83544 96868->96869 96870 a8a961 22 API calls 96869->96870 96871 a8354d 96870->96871 96872 a8a6c3 22 API calls 96871->96872 96873 a83556 RegOpenKeyExW 96872->96873 96874 ac3176 RegQueryValueExW 96873->96874 96878 a83578 96873->96878 96875 ac320c RegCloseKey 96874->96875 96876 ac3193 96874->96876 96875->96878 96886 ac321e _wcslen 96875->96886 96877 a9fe0b 22 API calls 96876->96877 96879 ac31ac 96877->96879 96878->96855 96880 a85722 22 API calls 96879->96880 96882 ac31b7 RegQueryValueExW 96880->96882 96881 a84c6d 22 API calls 96881->96886 96883 ac31d4 96882->96883 96885 ac31ee ISource 96882->96885 96884 a86b57 22 API calls 96883->96884 96884->96885 96885->96875 96886->96878 96886->96881 96887 a89cb3 22 API calls 96886->96887 96888 a8515f 22 API calls 96886->96888 96887->96886 96888->96886 96889->96857 96891 ac1f50 __wsopen_s 96890->96891 96892 a83364 GetFullPathNameW 96891->96892 96893 a83386 96892->96893 96894 a86b57 22 API calls 96893->96894 96895 a833a4 96894->96895 96895->96866 96896 a8dddc 96899 a8b710 96896->96899 96900 a8b72b 96899->96900 96901 ad00f8 96900->96901 96902 ad0146 96900->96902 96929 a8b750 96900->96929 96905 ad0102 96901->96905 96908 ad010f 96901->96908 96901->96929 96941 b058a2 349 API calls 2 library calls 96902->96941 96939 b05d33 349 API calls 96905->96939 96920 a8ba20 96908->96920 96940 b061d0 349 API calls 2 library calls 96908->96940 96911 ad03d9 96911->96911 96915 a8ba4e 96916 ad0322 96944 b05c0c 82 API calls 96916->96944 96920->96915 96945 af359c 82 API calls __wsopen_s 96920->96945 96923 a8aceb 23 API calls 96923->96929 96924 a8bbe0 40 API calls 96924->96929 96925 a9d336 40 API calls 96925->96929 96926 a8ec40 349 API calls 96926->96929 96929->96915 96929->96916 96929->96920 96929->96923 96929->96924 96929->96925 96929->96926 96930 a8a81b 41 API calls 96929->96930 96931 a9d2f0 40 API calls 96929->96931 96932 a9a01b 349 API calls 96929->96932 96933 aa0242 5 API calls __Init_thread_wait 96929->96933 96934 a9edcd 22 API calls 96929->96934 96935 aa00a3 29 API calls __onexit 96929->96935 96936 aa01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent 96929->96936 96937 a9ee53 82 API calls 96929->96937 96938 a9e5ca 349 API calls 96929->96938 96942 adf6bf 23 API calls 96929->96942 96943 a8a8c7 22 API calls __fread_nolock 96929->96943 96930->96929 96931->96929 96932->96929 96933->96929 96934->96929 96935->96929 96936->96929 96937->96929 96938->96929 96939->96908 96940->96920 96941->96929 96942->96929 96943->96929 96944->96920 96945->96911 96946 a8f7bf 96947 a8f7d3 96946->96947 96948 a8fcb6 96946->96948 96949 a8fcc2 96947->96949 96951 a9fddb 22 API calls 96947->96951 96950 a8aceb 23 API calls 96948->96950 96952 a8aceb 23 API calls 96949->96952 96950->96949 96953 a8f7e5 96951->96953 96955 a8fd3d 96952->96955 96953->96949 96954 a8f83e 96953->96954 96953->96955 96957 a91310 349 API calls 96954->96957 96972 a8ed9d ISource 96954->96972 96983 af1155 22 API calls 96955->96983 96963 a8ec76 ISource 96957->96963 96958 a9fddb 22 API calls 96958->96963 96959 ad4beb 96989 af359c 82 API calls __wsopen_s 96959->96989 96960 a8fef7 96960->96972 96985 a8a8c7 22 API calls __fread_nolock 96960->96985 96963->96958 96963->96959 96963->96960 96964 ad4b0b 96963->96964 96965 a8a8c7 22 API calls 96963->96965 96966 a8f3ae ISource 96963->96966 96967 ad4600 96963->96967 96963->96972 96974 aa0242 EnterCriticalSection LeaveCriticalSection LeaveCriticalSection WaitForSingleObjectEx EnterCriticalSection 96963->96974 96975 a8fbe3 96963->96975 96976 a8a961 22 API calls 96963->96976 96978 aa00a3 29 API calls pre_c_initialization 96963->96978 96980 aa01f8 EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent __Init_thread_footer 96963->96980 96981 a901e0 349 API calls 2 library calls 96963->96981 96982 a906a0 41 API calls ISource 96963->96982 96987 af359c 82 API calls __wsopen_s 96964->96987 96965->96963 96966->96972 96986 af359c 82 API calls __wsopen_s 96966->96986 96967->96972 96984 a8a8c7 22 API calls __fread_nolock 96967->96984 96974->96963 96975->96966 96975->96972 96977 ad4bdc 96975->96977 96976->96963 96988 af359c 82 API calls __wsopen_s 96977->96988 96978->96963 96980->96963 96981->96963 96982->96963 96983->96972 96984->96972 96985->96972 96986->96972 96987->96972 96988->96959 96989->96972 96990 ad3f75 97001 a9ceb1 96990->97001 96992 ad3f8b 96993 ad4006 96992->96993 97010 a9e300 23 API calls 96992->97010 96996 a8bf40 349 API calls 96993->96996 96995 ad3fe6 96998 ad4052 96995->96998 97011 af1abf 22 API calls 96995->97011 96996->96998 97000 ad4a88 96998->97000 97012 af359c 82 API calls __wsopen_s 96998->97012 97002 a9cebf 97001->97002 97003 a9ced2 97001->97003 97004 a8aceb 23 API calls 97002->97004 97005 a9cf05 97003->97005 97006 a9ced7 97003->97006 97009 a9cec9 97004->97009 97008 a8aceb 23 API calls 97005->97008 97007 a9fddb 22 API calls 97006->97007 97007->97009 97008->97009 97009->96992 97010->96995 97011->96993 97012->97000 97013 a81033 97018 a84c91 97013->97018 97017 a81042 97019 a8a961 22 API calls 97018->97019 97020 a84cff 97019->97020 97026 a83af0 97020->97026 97023 a84d9c 97024 a81038 97023->97024 97029 a851f7 22 API calls __fread_nolock 97023->97029 97025 aa00a3 29 API calls __onexit 97024->97025 97025->97017 97030 a83b1c 97026->97030 97029->97023 97031 a83b0f 97030->97031 97032 a83b29 97030->97032 97031->97023 97032->97031 97033 a83b30 RegOpenKeyExW 97032->97033 97033->97031 97034 a83b4a RegQueryValueExW 97033->97034 97035 a83b6b 97034->97035 97036 a83b80 RegCloseKey 97034->97036 97035->97036 97036->97031 97037 a83156 97040 a83170 97037->97040 97041 a83187 97040->97041 97042 a831eb 97041->97042 97043 a8318c 97041->97043 97044 a831e9 97041->97044 97048 ac2dfb 97042->97048 97049 a831f1 97042->97049 97045 a83199 97043->97045 97046 a83265 PostQuitMessage 97043->97046 97047 a831d0 DefWindowProcW 97044->97047 97051 ac2e7c 97045->97051 97052 a831a4 97045->97052 97053 a8316a 97046->97053 97047->97053 97095 a818e2 10 API calls 97048->97095 97054 a831f8 97049->97054 97055 a8321d SetTimer RegisterWindowMessageW 97049->97055 97098 aebf30 34 API calls ___scrt_fastfail 97051->97098 97057 ac2e68 97052->97057 97058 a831ae 97052->97058 97061 ac2d9c 97054->97061 97062 a83201 KillTimer 97054->97062 97055->97053 97059 a83246 CreatePopupMenu 97055->97059 97056 ac2e1c 97096 a9e499 42 API calls 97056->97096 97085 aec161 97057->97085 97065 ac2e4d 97058->97065 97066 a831b9 97058->97066 97059->97053 97068 ac2dd7 MoveWindow 97061->97068 97069 ac2da1 97061->97069 97070 a830f2 Shell_NotifyIconW 97062->97070 97065->97047 97097 ae0ad7 22 API calls 97065->97097 97072 a831c4 97066->97072 97073 a83253 97066->97073 97067 ac2e8e 97067->97047 97067->97053 97068->97053 97074 ac2dc6 SetFocus 97069->97074 97075 ac2da7 97069->97075 97071 a83214 97070->97071 97092 a83c50 DeleteObject DestroyWindow 97071->97092 97072->97047 97082 a830f2 Shell_NotifyIconW 97072->97082 97093 a8326f 44 API calls ___scrt_fastfail 97073->97093 97074->97053 97075->97072 97078 ac2db0 97075->97078 97094 a818e2 10 API calls 97078->97094 97080 a83263 97080->97053 97083 ac2e41 97082->97083 97084 a83837 49 API calls 97083->97084 97084->97044 97086 aec179 ___scrt_fastfail 97085->97086 97087 aec276 97085->97087 97088 a83923 24 API calls 97086->97088 97087->97053 97090 aec1a0 97088->97090 97089 aec25f KillTimer SetTimer 97089->97087 97090->97089 97091 aec251 Shell_NotifyIconW 97090->97091 97091->97089 97092->97053 97093->97080 97094->97053 97095->97056 97096->97072 97097->97044 97098->97067 97099 a82e37 97100 a8a961 22 API calls 97099->97100 97101 a82e4d 97100->97101 97178 a84ae3 97101->97178 97103 a82e6b 97104 a83a5a 24 API calls 97103->97104 97105 a82e7f 97104->97105 97106 a89cb3 22 API calls 97105->97106 97107 a82e8c 97106->97107 97108 a84ecb 94 API calls 97107->97108 97109 a82ea5 97108->97109 97110 a82ead 97109->97110 97111 ac2cb0 97109->97111 97192 a8a8c7 22 API calls __fread_nolock 97110->97192 97112 af2cf9 80 API calls 97111->97112 97113 ac2cc3 97112->97113 97114 ac2ccf 97113->97114 97116 a84f39 68 API calls 97113->97116 97119 a84f39 68 API calls 97114->97119 97116->97114 97117 a82ec3 97193 a86f88 22 API calls 97117->97193 97122 ac2ce5 97119->97122 97120 a82ecf 97121 a89cb3 22 API calls 97120->97121 97123 a82edc 97121->97123 97209 a83084 22 API calls 97122->97209 97194 a8a81b 41 API calls 97123->97194 97125 a82eec 97128 a89cb3 22 API calls 97125->97128 97127 ac2d02 97210 a83084 22 API calls 97127->97210 97130 a82f12 97128->97130 97195 a8a81b 41 API calls 97130->97195 97131 ac2d1e 97133 a83a5a 24 API calls 97131->97133 97134 ac2d44 97133->97134 97211 a83084 22 API calls 97134->97211 97135 a82f21 97138 a8a961 22 API calls 97135->97138 97137 ac2d50 97212 a8a8c7 22 API calls __fread_nolock 97137->97212 97140 a82f3f 97138->97140 97196 a83084 22 API calls 97140->97196 97142 ac2d5e 97213 a83084 22 API calls 97142->97213 97143 a82f4b 97197 aa4a28 40 API calls 3 library calls 97143->97197 97146 ac2d6d 97214 a8a8c7 22 API calls __fread_nolock 97146->97214 97147 a82f59 97147->97122 97148 a82f63 97147->97148 97198 aa4a28 40 API calls 3 library calls 97148->97198 97151 ac2d83 97215 a83084 22 API calls 97151->97215 97152 a82f6e 97152->97127 97154 a82f78 97152->97154 97199 aa4a28 40 API calls 3 library calls 97154->97199 97155 ac2d90 97157 a82f83 97157->97131 97158 a82f8d 97157->97158 97200 aa4a28 40 API calls 3 library calls 97158->97200 97160 a82fdc 97160->97146 97161 a82fe8 97160->97161 97161->97155 97165 a863eb 22 API calls 97161->97165 97162 a82f98 97162->97160 97201 a83084 22 API calls 97162->97201 97164 a82fbf 97202 a8a8c7 22 API calls __fread_nolock 97164->97202 97167 a82ff8 97165->97167 97204 a86a50 22 API calls 97167->97204 97168 a82fcd 97203 a83084 22 API calls 97168->97203 97171 a83006 97205 a870b0 23 API calls 97171->97205 97175 a83021 97176 a83065 97175->97176 97206 a86f88 22 API calls 97175->97206 97207 a870b0 23 API calls 97175->97207 97208 a83084 22 API calls 97175->97208 97179 a84af0 __wsopen_s 97178->97179 97180 a86b57 22 API calls 97179->97180 97181 a84b22 97179->97181 97180->97181 97182 a84c6d 22 API calls 97181->97182 97191 a84b58 97181->97191 97182->97181 97183 a89cb3 22 API calls 97185 a84c52 97183->97185 97184 a89cb3 22 API calls 97184->97191 97187 a8515f 22 API calls 97185->97187 97186 a84c6d 22 API calls 97186->97191 97189 a84c5e 97187->97189 97188 a8515f 22 API calls 97188->97191 97189->97103 97190 a84c29 97190->97183 97190->97189 97191->97184 97191->97186 97191->97188 97191->97190 97192->97117 97193->97120 97194->97125 97195->97135 97196->97143 97197->97147 97198->97152 97199->97157 97200->97162 97201->97164 97202->97168 97203->97160 97204->97171 97205->97175 97206->97175 97207->97175 97208->97175 97209->97127 97210->97131 97211->97137 97212->97142 97213->97146 97214->97151 97215->97155

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 389 a842de-a8434d call a8a961 GetVersionExW call a86b57 394 ac3617-ac362a 389->394 395 a84353 389->395 396 ac362b-ac362f 394->396 397 a84355-a84357 395->397 398 ac3631 396->398 399 ac3632-ac363e 396->399 400 a8435d-a843bc call a893b2 call a837a0 397->400 401 ac3656 397->401 398->399 399->396 402 ac3640-ac3642 399->402 415 ac37df-ac37e6 400->415 416 a843c2-a843c4 400->416 405 ac365d-ac3660 401->405 402->397 404 ac3648-ac364f 402->404 404->394 407 ac3651 404->407 408 a8441b-a84435 GetCurrentProcess IsWow64Process 405->408 409 ac3666-ac36a8 405->409 407->401 412 a84494-a8449a 408->412 413 a84437 408->413 409->408 414 ac36ae-ac36b1 409->414 417 a8443d-a84449 412->417 413->417 418 ac36db-ac36e5 414->418 419 ac36b3-ac36bd 414->419 423 ac37e8 415->423 424 ac3806-ac3809 415->424 416->405 422 a843ca-a843dd 416->422 427 a8444f-a8445e LoadLibraryA 417->427 428 ac3824-ac3828 GetSystemInfo 417->428 425 ac36f8-ac3702 418->425 426 ac36e7-ac36f3 418->426 420 ac36bf-ac36c5 419->420 421 ac36ca-ac36d6 419->421 420->408 421->408 429 ac3726-ac372f 422->429 430 a843e3-a843e5 422->430 431 ac37ee 423->431 434 ac380b-ac381a 424->434 435 ac37f4-ac37fc 424->435 432 ac3704-ac3710 425->432 433 ac3715-ac3721 425->433 426->408 436 a8449c-a844a6 GetSystemInfo 427->436 437 a84460-a8446e GetProcAddress 427->437 441 ac373c-ac3748 429->441 442 ac3731-ac3737 429->442 439 ac374d-ac3762 430->439 440 a843eb-a843ee 430->440 431->435 432->408 433->408 434->431 443 ac381c-ac3822 434->443 435->424 438 a84476-a84478 436->438 437->436 444 a84470-a84474 GetNativeSystemInfo 437->444 449 a8447a-a8447b FreeLibrary 438->449 450 a84481-a84493 438->450 447 ac376f-ac377b 439->447 448 ac3764-ac376a 439->448 445 a843f4-a8440f 440->445 446 ac3791-ac3794 440->446 441->408 442->408 443->435 444->438 451 ac3780-ac378c 445->451 452 a84415 445->452 446->408 453 ac379a-ac37c1 446->453 447->408 448->408 449->450 451->408 452->408 454 ac37ce-ac37da 453->454 455 ac37c3-ac37c9 453->455 454->408 455->408
                          APIs
                          • GetVersionExW.KERNEL32(?), ref: 00A8430D
                            • Part of subcall function 00A86B57: _wcslen.LIBCMT ref: 00A86B6A
                          • GetCurrentProcess.KERNEL32(?,00B1CB64,00000000,?,?), ref: 00A84422
                          • IsWow64Process.KERNEL32(00000000,?,?), ref: 00A84429
                          • LoadLibraryA.KERNEL32(kernel32.dll,?,?), ref: 00A84454
                          • GetProcAddress.KERNEL32(00000000,GetNativeSystemInfo), ref: 00A84466
                          • GetNativeSystemInfo.KERNELBASE(?,?,?), ref: 00A84474
                          • FreeLibrary.KERNEL32(00000000,?,?), ref: 00A8447B
                          • GetSystemInfo.KERNEL32(?,?,?), ref: 00A844A0
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: InfoLibraryProcessSystem$AddressCurrentFreeLoadNativeProcVersionWow64_wcslen
                          • String ID: GetNativeSystemInfo$kernel32.dll$|O
                          • API String ID: 3290436268-3101561225
                          • Opcode ID: 2daba40f0f0c45baea59a0b80a4b7fa19e3ffb0d23ab8f6025bdc8844bd563d3
                          • Instruction ID: a12c3e87b76067585a16437cf56908e7bcbcdc7b61620875501a7d32c3e0d904
                          • Opcode Fuzzy Hash: 2daba40f0f0c45baea59a0b80a4b7fa19e3ffb0d23ab8f6025bdc8844bd563d3
                          • Instruction Fuzzy Hash: B1A1A17294A3C0FFDB11D76DBC657957FE46F3A346B088CEDD08197A22DA204908CB29

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 793 a842a2-a842ba CreateStreamOnHGlobal 794 a842da-a842dd 793->794 795 a842bc-a842d3 FindResourceExW 793->795 796 a842d9 795->796 797 ac35ba-ac35c9 LoadResource 795->797 796->794 797->796 798 ac35cf-ac35dd SizeofResource 797->798 798->796 799 ac35e3-ac35ee LockResource 798->799 799->796 800 ac35f4-ac3612 799->800 800->796
                          APIs
                          • CreateStreamOnHGlobal.COMBASE(00000000,00000001,?,?,?,?,?,00A850AA,?,?,00000000,00000000), ref: 00A842B2
                          • FindResourceExW.KERNEL32(?,0000000A,SCRIPT,00000000,?,?,00A850AA,?,?,00000000,00000000), ref: 00A842C9
                          • LoadResource.KERNEL32(?,00000000,?,?,00A850AA,?,?,00000000,00000000,?,?,?,?,?,?,00A84F20), ref: 00AC35BE
                          • SizeofResource.KERNEL32(?,00000000,?,?,00A850AA,?,?,00000000,00000000,?,?,?,?,?,?,00A84F20), ref: 00AC35D3
                          • LockResource.KERNEL32(00A850AA,?,?,00A850AA,?,?,00000000,00000000,?,?,?,?,?,?,00A84F20,?), ref: 00AC35E6
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Resource$CreateFindGlobalLoadLockSizeofStream
                          • String ID: SCRIPT
                          • API String ID: 3051347437-3967369404
                          • Opcode ID: 85003a10613887bc30d01d000a1da82b790a424821b6cf3e3bfc74526d3fd07f
                          • Instruction ID: 0fcefbf236babf106bca2f7f340c77b995cc1ead9adf08d4614e01a0338017dd
                          • Opcode Fuzzy Hash: 85003a10613887bc30d01d000a1da82b790a424821b6cf3e3bfc74526d3fd07f
                          • Instruction Fuzzy Hash: 20117C75244705BFDB219B65DC48FA77FB9EBC9B55F208169B402D7260EB71D8008A60

                          Control-flow Graph

                          APIs
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00A82B6B
                            • Part of subcall function 00A83A5A: GetModuleFileNameW.KERNEL32(00000000,?,00007FFF,00B51418,?,00A82E7F,?,?,?,00000000), ref: 00A83A78
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • GetForegroundWindow.USER32(runas,?,?,?,?,?,00B42224), ref: 00AC2C10
                          • ShellExecuteW.SHELL32(00000000,?,?,00B42224), ref: 00AC2C17
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CurrentDirectoryExecuteFileForegroundModuleNameShellWindow_wcslen
                          • String ID: runas
                          • API String ID: 448630720-4000483414
                          • Opcode ID: acde094dd9ac3a445ea1b35529ee2aca92c0824e3871f04c41441cde9796c78d
                          • Instruction ID: 77275fc940becdd42289214fbc3637cd40777a5e6ff395e1c817d7f5a335feca
                          • Opcode Fuzzy Hash: acde094dd9ac3a445ea1b35529ee2aca92c0824e3871f04c41441cde9796c78d
                          • Instruction Fuzzy Hash: 3A11E6322083016ACB15FF64DA56FBEBBE8EF91741F44186DF082571A3CF218A4AD712

                          Control-flow Graph

                          APIs
                          • CreateToolhelp32Snapshot.KERNEL32 ref: 00B0A6AC
                          • Process32FirstW.KERNEL32(00000000,?), ref: 00B0A6BA
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • Process32NextW.KERNEL32(00000000,?), ref: 00B0A79C
                          • CloseHandle.KERNELBASE(00000000), ref: 00B0A7AB
                            • Part of subcall function 00A9CE60: CompareStringW.KERNEL32(00000409,00000001,?,00000000,00000000,?,?,00000000,?,00AC3303,?), ref: 00A9CE8A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process32$CloseCompareCreateFirstHandleNextSnapshotStringToolhelp32_wcslen
                          • String ID:
                          • API String ID: 1991900642-0
                          • Opcode ID: 2082fc9f944e2e1444d1e538cdd4522e50ff4ef95366a4627e1d8f2f9f8a6672
                          • Instruction ID: a30ba309ec37bd2a02fdbf6a6e8c1c2587d784fffce5796201de96cceb5c06c3
                          • Opcode Fuzzy Hash: 2082fc9f944e2e1444d1e538cdd4522e50ff4ef95366a4627e1d8f2f9f8a6672
                          • Instruction Fuzzy Hash: D6518B71508311AFD710EF24C986E6BBBE8FF89754F00892DF589A7291EB30D904CB92

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 1019 aedbbe-aedbda lstrlenW 1020 aedbdc-aedbe6 GetFileAttributesW 1019->1020 1021 aedc06 1019->1021 1022 aedbe8-aedbf7 FindFirstFileW 1020->1022 1023 aedc09-aedc0d 1020->1023 1021->1023 1022->1021 1024 aedbf9-aedc04 FindClose 1022->1024 1024->1023
                          APIs
                          • lstrlenW.KERNEL32(?,00AC5222), ref: 00AEDBCE
                          • GetFileAttributesW.KERNELBASE(?), ref: 00AEDBDD
                          • FindFirstFileW.KERNEL32(?,?), ref: 00AEDBEE
                          • FindClose.KERNEL32(00000000), ref: 00AEDBFA
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FileFind$AttributesCloseFirstlstrlen
                          • String ID:
                          • API String ID: 2695905019-0
                          • Opcode ID: ebc583692d53de2828b80a8887c1e6cae4008d62c028d13602c76f362428763b
                          • Instruction ID: 9f457b526094b801aab967788bd205d82f2437ab4edaf51a0ff85d90e04e75c6
                          • Opcode Fuzzy Hash: ebc583692d53de2828b80a8887c1e6cae4008d62c028d13602c76f362428763b
                          • Instruction Fuzzy Hash: 4FF0E5308509106782206F7CAC0D8EA3B7C9E81374BA08702F836C30F0EFB05D64C6D6
                          APIs
                          • GetCurrentProcess.KERNEL32(00AB28E9,?,00AA4CBE,00AB28E9,00B488B8,0000000C,00AA4E15,00AB28E9,00000002,00000000,?,00AB28E9), ref: 00AA4D09
                          • TerminateProcess.KERNEL32(00000000,?,00AA4CBE,00AB28E9,00B488B8,0000000C,00AA4E15,00AB28E9,00000002,00000000,?,00AB28E9), ref: 00AA4D10
                          • ExitProcess.KERNEL32 ref: 00AA4D22
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process$CurrentExitTerminate
                          • String ID:
                          • API String ID: 1703294689-0
                          • Opcode ID: 5bb1b2a17f3a737aeaf9709c3e781c15dbdb48926b48b5d6991c0faa4ee85e77
                          • Instruction ID: 9ea91281e2ee7e79e986bade2b91d73a2fe7e39e4072a9294b2e9e5b09409ae9
                          • Opcode Fuzzy Hash: 5bb1b2a17f3a737aeaf9709c3e781c15dbdb48926b48b5d6991c0faa4ee85e77
                          • Instruction Fuzzy Hash: A9E0B631040148AFCF11AF54EE09A997F69EB86785B508014FD159B162DB75DE52CA84

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 0 b0aff9-b0b056 call aa2340 3 b0b094-b0b098 0->3 4 b0b058-b0b06b call a8b567 0->4 5 b0b09a-b0b0bb call a8b567 * 2 3->5 6 b0b0dd-b0b0e0 3->6 15 b0b0c8 4->15 16 b0b06d-b0b092 call a8b567 * 2 4->16 30 b0b0bf-b0b0c4 5->30 10 b0b0e2-b0b0e5 6->10 11 b0b0f5-b0b119 call a87510 call a87620 6->11 12 b0b0e8-b0b0ed call a8b567 10->12 32 b0b1d8-b0b1e0 11->32 33 b0b11f-b0b178 call a87510 call a87620 call a87510 call a87620 call a87510 call a87620 11->33 12->11 20 b0b0cb-b0b0cf 15->20 16->30 25 b0b0d1-b0b0d7 20->25 26 b0b0d9-b0b0db 20->26 25->12 26->6 26->11 30->6 34 b0b0c6 30->34 35 b0b1e2-b0b1fd call a87510 call a87620 32->35 36 b0b20a-b0b238 GetCurrentDirectoryW call a9fe0b GetCurrentDirectoryW 32->36 80 b0b1a6-b0b1d6 GetSystemDirectoryW call a9fe0b GetSystemDirectoryW 33->80 81 b0b17a-b0b195 call a87510 call a87620 33->81 34->20 35->36 50 b0b1ff-b0b208 call aa4963 35->50 45 b0b23c 36->45 48 b0b240-b0b244 45->48 51 b0b275-b0b285 call af00d9 48->51 52 b0b246-b0b270 call a89c6e * 3 48->52 50->36 50->51 64 b0b287-b0b289 51->64 65 b0b28b-b0b2e1 call af07c0 call af06e6 call af05a7 51->65 52->51 68 b0b2ee-b0b2f2 64->68 65->68 100 b0b2e3 65->100 70 b0b2f8-b0b321 call ae11c8 68->70 71 b0b39a-b0b3be CreateProcessW 68->71 84 b0b323-b0b328 call ae1201 70->84 85 b0b32a call ae14ce 70->85 78 b0b3c1-b0b3d4 call a9fe14 * 2 71->78 101 b0b3d6-b0b3e8 78->101 102 b0b42f-b0b43d CloseHandle 78->102 80->45 81->80 107 b0b197-b0b1a0 call aa4963 81->107 99 b0b32f-b0b33c call aa4963 84->99 85->99 115 b0b347-b0b357 call aa4963 99->115 116 b0b33e-b0b345 99->116 100->68 105 b0b3ea 101->105 106 b0b3ed-b0b3fc 101->106 109 b0b49c 102->109 110 b0b43f-b0b444 102->110 105->106 111 b0b401-b0b42a GetLastError call a8630c call a8cfa0 106->111 112 b0b3fe 106->112 107->48 107->80 113 b0b4a0-b0b4a4 109->113 117 b0b451-b0b456 110->117 118 b0b446-b0b44c CloseHandle 110->118 129 b0b4e5-b0b4f6 call af0175 111->129 112->111 120 b0b4b2-b0b4bc 113->120 121 b0b4a6-b0b4b0 113->121 134 b0b362-b0b372 call aa4963 115->134 135 b0b359-b0b360 115->135 116->115 116->116 124 b0b463-b0b468 117->124 125 b0b458-b0b45e CloseHandle 117->125 118->117 130 b0b4c4-b0b4e3 call a8cfa0 CloseHandle 120->130 131 b0b4be 120->131 121->129 126 b0b475-b0b49a call af09d9 call b0b536 124->126 127 b0b46a-b0b470 CloseHandle 124->127 125->124 126->113 127->126 130->129 131->130 146 b0b374-b0b37b 134->146 147 b0b37d-b0b398 call a9fe14 * 3 134->147 135->134 135->135 146->146 146->147 147->78
                          APIs
                          • _wcslen.LIBCMT ref: 00B0B198
                          • GetSystemDirectoryW.KERNEL32(00000000,00000000), ref: 00B0B1B0
                          • GetSystemDirectoryW.KERNEL32(00000000,00000000), ref: 00B0B1D4
                          • _wcslen.LIBCMT ref: 00B0B200
                          • GetCurrentDirectoryW.KERNEL32(00000000,00000000), ref: 00B0B214
                          • GetCurrentDirectoryW.KERNEL32(00000000,00000000), ref: 00B0B236
                          • _wcslen.LIBCMT ref: 00B0B332
                            • Part of subcall function 00AF05A7: GetStdHandle.KERNEL32(000000F6), ref: 00AF05C6
                          • _wcslen.LIBCMT ref: 00B0B34B
                          • _wcslen.LIBCMT ref: 00B0B366
                          • CreateProcessW.KERNELBASE(00000000,?,00000000,00000000,?,?,00000000,?,?,?), ref: 00B0B3B6
                          • GetLastError.KERNEL32(00000000), ref: 00B0B407
                          • CloseHandle.KERNEL32(?), ref: 00B0B439
                          • CloseHandle.KERNEL32(00000000), ref: 00B0B44A
                          • CloseHandle.KERNEL32(00000000), ref: 00B0B45C
                          • CloseHandle.KERNEL32(00000000), ref: 00B0B46E
                          • CloseHandle.KERNEL32(?), ref: 00B0B4E3
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Handle$Close_wcslen$Directory$CurrentSystem$CreateErrorLastProcess
                          • String ID:
                          • API String ID: 2178637699-0
                          • Opcode ID: 7fc7702cc444a615eaa6980cb0b717cf7f57b8318f61d9f04f135cf38d364687
                          • Instruction ID: 84a75d669de812250ced9dbcf58219384ea78f269fd4cb75ddc08877523f732b
                          • Opcode Fuzzy Hash: 7fc7702cc444a615eaa6980cb0b717cf7f57b8318f61d9f04f135cf38d364687
                          • Instruction Fuzzy Hash: 8DF179316082409FCB14EF24C991F6EBBE5EF85714F18859DF8969B2A2DB31EC40CB52
                          APIs
                          • GetInputState.USER32 ref: 00A8D807
                          • timeGetTime.WINMM ref: 00A8DA07
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00A8DB28
                          • TranslateMessage.USER32(?), ref: 00A8DB7B
                          • DispatchMessageW.USER32(?), ref: 00A8DB89
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00A8DB9F
                          • Sleep.KERNELBASE(0000000A), ref: 00A8DBB1
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Message$Peek$DispatchInputSleepStateTimeTranslatetime
                          • String ID:
                          • API String ID: 2189390790-0
                          • Opcode ID: 7636c28afd8dff2e40569867f6bb8c346e8396f0ff1d294debea69e2bff7aa58
                          • Instruction ID: 9285d1ac9cbe51205aec4b9fd44bb01f8637e5279b84b84cc65359ee4cfe942d
                          • Opcode Fuzzy Hash: 7636c28afd8dff2e40569867f6bb8c346e8396f0ff1d294debea69e2bff7aa58
                          • Instruction Fuzzy Hash: 5A42B070608341EFDB28EF24C844BAABBF1BF95314F54895AE496873D1DB71E844CB92

                          Control-flow Graph

                          APIs
                          • GetSysColorBrush.USER32(0000000F), ref: 00A82D07
                          • RegisterClassExW.USER32(00000030), ref: 00A82D31
                          • RegisterWindowMessageW.USER32(TaskbarCreated), ref: 00A82D42
                          • InitCommonControlsEx.COMCTL32(?), ref: 00A82D5F
                          • ImageList_Create.COMCTL32(00000010,00000010,00000021,00000001,00000001), ref: 00A82D6F
                          • LoadIconW.USER32(000000A9), ref: 00A82D85
                          • ImageList_ReplaceIcon.COMCTL32(000000FF,00000000), ref: 00A82D94
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: IconImageList_Register$BrushClassColorCommonControlsCreateInitLoadMessageReplaceWindow
                          • String ID: +$0$AutoIt v3 GUI$TaskbarCreated
                          • API String ID: 2914291525-1005189915
                          • Opcode ID: 504febea6c5a04ef5edd32c8cd47d249444efe217b8ebf30bea1df15f7552814
                          • Instruction ID: d8e38f2812a2ba2a49bfd77f8378c0f3c9fcca840cbabab9049218e78158254c
                          • Opcode Fuzzy Hash: 504febea6c5a04ef5edd32c8cd47d249444efe217b8ebf30bea1df15f7552814
                          • Instruction Fuzzy Hash: 6D21E2B5941308AFDB01DFA8EC49BDDBFB8FB08701F00855AE511A72A0DBB14A408F94

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 457 ac065b-ac068b call ac042f 460 ac068d-ac0698 call aaf2c6 457->460 461 ac06a6-ac06b2 call ab5221 457->461 466 ac069a-ac06a1 call aaf2d9 460->466 467 ac06cb-ac0714 call ac039a 461->467 468 ac06b4-ac06c9 call aaf2c6 call aaf2d9 461->468 477 ac097d-ac0983 466->477 475 ac0716-ac071f 467->475 476 ac0781-ac078a GetFileType 467->476 468->466 479 ac0756-ac077c GetLastError call aaf2a3 475->479 480 ac0721-ac0725 475->480 481 ac078c-ac07bd GetLastError call aaf2a3 CloseHandle 476->481 482 ac07d3-ac07d6 476->482 479->466 480->479 486 ac0727-ac0754 call ac039a 480->486 481->466 496 ac07c3-ac07ce call aaf2d9 481->496 484 ac07df-ac07e5 482->484 485 ac07d8-ac07dd 482->485 489 ac07e9-ac0837 call ab516a 484->489 490 ac07e7 484->490 485->489 486->476 486->479 499 ac0839-ac0845 call ac05ab 489->499 500 ac0847-ac086b call ac014d 489->500 490->489 496->466 499->500 506 ac086f-ac0879 call ab86ae 499->506 507 ac086d 500->507 508 ac087e-ac08c1 500->508 506->477 507->506 509 ac08e2-ac08f0 508->509 510 ac08c3-ac08c7 508->510 513 ac097b 509->513 514 ac08f6-ac08fa 509->514 510->509 512 ac08c9-ac08dd 510->512 512->509 513->477 514->513 516 ac08fc-ac092f CloseHandle call ac039a 514->516 519 ac0931-ac095d GetLastError call aaf2a3 call ab5333 516->519 520 ac0963-ac0977 516->520 519->520 520->513
                          APIs
                            • Part of subcall function 00AC039A: CreateFileW.KERNELBASE(00000000,00000000,?,00AC0704,?,?,00000000,?,00AC0704,00000000,0000000C), ref: 00AC03B7
                          • GetLastError.KERNEL32 ref: 00AC076F
                          • __dosmaperr.LIBCMT ref: 00AC0776
                          • GetFileType.KERNELBASE(00000000), ref: 00AC0782
                          • GetLastError.KERNEL32 ref: 00AC078C
                          • __dosmaperr.LIBCMT ref: 00AC0795
                          • CloseHandle.KERNEL32(00000000), ref: 00AC07B5
                          • CloseHandle.KERNEL32(?), ref: 00AC08FF
                          • GetLastError.KERNEL32 ref: 00AC0931
                          • __dosmaperr.LIBCMT ref: 00AC0938
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorLast__dosmaperr$CloseFileHandle$CreateType
                          • String ID: H
                          • API String ID: 4237864984-2852464175
                          • Opcode ID: 44da0d9f7eb6bddf88f4bd1263be9cf9bee0ff5170a668ded8b81303be7eb903
                          • Instruction ID: 6e6d6cee9604562667a8f03f2b8962965b9ab54e18f9f9ebf7e6893b9190babe
                          • Opcode Fuzzy Hash: 44da0d9f7eb6bddf88f4bd1263be9cf9bee0ff5170a668ded8b81303be7eb903
                          • Instruction Fuzzy Hash: 4CA11332A14608CFDF19AF68D851FAE7BA0AB0A320F15415DF815AF3D2DB359D12CB91

                          Control-flow Graph

                          APIs
                            • Part of subcall function 00A83A5A: GetModuleFileNameW.KERNEL32(00000000,?,00007FFF,00B51418,?,00A82E7F,?,?,?,00000000), ref: 00A83A78
                            • Part of subcall function 00A83357: GetFullPathNameW.KERNEL32(?,00007FFF,?,?), ref: 00A83379
                          • RegOpenKeyExW.KERNELBASE(80000001,Software\AutoIt v3\AutoIt,00000000,00000001,?,?,\Include\), ref: 00A8356A
                          • RegQueryValueExW.ADVAPI32(?,Include,00000000,00000000,00000000,?), ref: 00AC318D
                          • RegQueryValueExW.ADVAPI32(?,Include,00000000,00000000,?,?,00000000), ref: 00AC31CE
                          • RegCloseKey.ADVAPI32(?), ref: 00AC3210
                          • _wcslen.LIBCMT ref: 00AC3277
                          • _wcslen.LIBCMT ref: 00AC3286
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: NameQueryValue_wcslen$CloseFileFullModuleOpenPath
                          • String ID: Include$Software\AutoIt v3\AutoIt$\$\Include\
                          • API String ID: 98802146-2727554177
                          • Opcode ID: 3ca0258fb77be5eee2a87063fa2eba8a11f51ab58b39ca4430bdb9215e945803
                          • Instruction ID: 4171e989bc7f7dde88da8843430b5b2870a5c10daa931c9bf056b65294f3a303
                          • Opcode Fuzzy Hash: 3ca0258fb77be5eee2a87063fa2eba8a11f51ab58b39ca4430bdb9215e945803
                          • Instruction Fuzzy Hash: CF71C0724093019ED704EF65DD82EABBBE8FF9A740F80446EF545931B0EB309A48CB56

                          Control-flow Graph

                          APIs
                          • GetSysColorBrush.USER32(0000000F), ref: 00A82B8E
                          • LoadCursorW.USER32(00000000,00007F00), ref: 00A82B9D
                          • LoadIconW.USER32(00000063), ref: 00A82BB3
                          • LoadIconW.USER32(000000A4), ref: 00A82BC5
                          • LoadIconW.USER32(000000A2), ref: 00A82BD7
                          • LoadImageW.USER32(00000063,00000001,00000010,00000010,00000000), ref: 00A82BEF
                          • RegisterClassExW.USER32(?), ref: 00A82C40
                            • Part of subcall function 00A82CD4: GetSysColorBrush.USER32(0000000F), ref: 00A82D07
                            • Part of subcall function 00A82CD4: RegisterClassExW.USER32(00000030), ref: 00A82D31
                            • Part of subcall function 00A82CD4: RegisterWindowMessageW.USER32(TaskbarCreated), ref: 00A82D42
                            • Part of subcall function 00A82CD4: InitCommonControlsEx.COMCTL32(?), ref: 00A82D5F
                            • Part of subcall function 00A82CD4: ImageList_Create.COMCTL32(00000010,00000010,00000021,00000001,00000001), ref: 00A82D6F
                            • Part of subcall function 00A82CD4: LoadIconW.USER32(000000A9), ref: 00A82D85
                            • Part of subcall function 00A82CD4: ImageList_ReplaceIcon.COMCTL32(000000FF,00000000), ref: 00A82D94
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Load$Icon$ImageRegister$BrushClassColorList_$CommonControlsCreateCursorInitMessageReplaceWindow
                          • String ID: #$0$AutoIt v3
                          • API String ID: 423443420-4155596026
                          • Opcode ID: d7f64807fe60971398ed0aba6b74f68be2dc469206431c2d37ca88c87158b472
                          • Instruction ID: 54526442a090729edbbcc61b396d3b91548e50ad8275af774ee989adf1f81d2f
                          • Opcode Fuzzy Hash: d7f64807fe60971398ed0aba6b74f68be2dc469206431c2d37ca88c87158b472
                          • Instruction Fuzzy Hash: C4212C75E40314BBDB10DFA9EC65BA97FB4FB48B51F00459AE500A76A0DBB14940CF98

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 598 a83170-a83185 599 a831e5-a831e7 598->599 600 a83187-a8318a 598->600 599->600 603 a831e9 599->603 601 a831eb 600->601 602 a8318c-a83193 600->602 607 ac2dfb-ac2e23 call a818e2 call a9e499 601->607 608 a831f1-a831f6 601->608 604 a83199-a8319e 602->604 605 a83265-a8326d PostQuitMessage 602->605 606 a831d0-a831d8 DefWindowProcW 603->606 610 ac2e7c-ac2e90 call aebf30 604->610 611 a831a4-a831a8 604->611 613 a83219-a8321b 605->613 612 a831de-a831e4 606->612 642 ac2e28-ac2e2f 607->642 614 a831f8-a831fb 608->614 615 a8321d-a83244 SetTimer RegisterWindowMessageW 608->615 610->613 636 ac2e96 610->636 617 ac2e68-ac2e72 call aec161 611->617 618 a831ae-a831b3 611->618 613->612 621 ac2d9c-ac2d9f 614->621 622 a83201-a8320f KillTimer call a830f2 614->622 615->613 619 a83246-a83251 CreatePopupMenu 615->619 632 ac2e77 617->632 625 ac2e4d-ac2e54 618->625 626 a831b9-a831be 618->626 619->613 628 ac2dd7-ac2df6 MoveWindow 621->628 629 ac2da1-ac2da5 621->629 631 a83214 call a83c50 622->631 625->606 639 ac2e5a-ac2e63 call ae0ad7 625->639 634 a83253-a83263 call a8326f 626->634 635 a831c4-a831ca 626->635 628->613 637 ac2dc6-ac2dd2 SetFocus 629->637 638 ac2da7-ac2daa 629->638 631->613 632->613 634->613 635->606 635->642 636->606 637->613 638->635 643 ac2db0-ac2dc1 call a818e2 638->643 639->606 642->606 647 ac2e35-ac2e48 call a830f2 call a83837 642->647 643->613 647->606
                          APIs
                          • DefWindowProcW.USER32(?,?,?,?,?,?,?,?,?,00A8316A,?,?), ref: 00A831D8
                          • KillTimer.USER32(?,00000001,?,?,?,?,?,00A8316A,?,?), ref: 00A83204
                          • SetTimer.USER32(?,00000001,000002EE,00000000), ref: 00A83227
                          • RegisterWindowMessageW.USER32(TaskbarCreated,?,?,?,?,?,00A8316A,?,?), ref: 00A83232
                          • CreatePopupMenu.USER32 ref: 00A83246
                          • PostQuitMessage.USER32(00000000), ref: 00A83267
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageTimerWindow$CreateKillMenuPopupPostProcQuitRegister
                          • String ID: TaskbarCreated
                          • API String ID: 129472671-2362178303
                          • Opcode ID: 33c18494d445df9e494200de268b79de4644cb3adba58965af3a9432c1f5a6d0
                          • Instruction ID: 9b0149b6478a09dd753a8d20c413d155d5059194fc730feed1608fcc10f2b3bf
                          • Opcode Fuzzy Hash: 33c18494d445df9e494200de268b79de4644cb3adba58965af3a9432c1f5a6d0
                          • Instruction Fuzzy Hash: 6E412533240204AADF157F7C9D1DBBD3E69EB15F01F0446A9FA02872E1EFA19E418B61

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 654 a81410-a81449 655 ac24b8-ac24b9 DestroyWindow 654->655 656 a8144f-a81465 mciSendStringW 654->656 660 ac24c4-ac24d1 655->660 657 a8146b-a81473 656->657 658 a816c6-a816d3 656->658 659 a81479-a81488 call a8182e 657->659 657->660 661 a816f8-a816ff 658->661 662 a816d5-a816f0 UnregisterHotKey 658->662 674 ac250e-ac251a 659->674 675 a8148e-a81496 659->675 666 ac2500-ac2507 660->666 667 ac24d3-ac24d6 660->667 661->657 665 a81705 661->665 662->661 664 a816f2-a816f3 call a810d0 662->664 664->661 665->658 666->660 670 ac2509 666->670 671 ac24d8-ac24e0 call a86246 667->671 672 ac24e2-ac24e5 FindClose 667->672 670->674 676 ac24eb-ac24f8 671->676 672->676 681 ac251c-ac251e FreeLibrary 674->681 682 ac2524-ac252b 674->682 678 a8149c-a814c1 call a8cfa0 675->678 679 ac2532-ac253f 675->679 676->666 680 ac24fa-ac24fb call af32b1 676->680 692 a814f8-a81503 CoUninitialize 678->692 693 a814c3 678->693 686 ac2566-ac256d 679->686 687 ac2541-ac255e VirtualFree 679->687 680->666 681->682 682->674 685 ac252d 682->685 685->679 686->679 689 ac256f 686->689 687->686 688 ac2560-ac2561 call af3317 687->688 688->686 694 ac2574-ac2578 689->694 692->694 696 a81509-a8150e 692->696 695 a814c6-a814f6 call a81a05 call a819ae 693->695 694->696 697 ac257e-ac2584 694->697 695->692 699 ac2589-ac2596 call af32eb 696->699 700 a81514-a8151e 696->700 697->696 713 ac2598 699->713 701 a81524-a815a5 call a8988f call a81944 call a817d5 call a9fe14 call a8177c call a8988f call a8cfa0 call a817fe call a9fe14 700->701 702 a81707-a81714 call a9f80e 700->702 717 ac259d-ac25bf call a9fdcd 701->717 743 a815ab-a815cf call a9fe14 701->743 702->701 715 a8171a 702->715 713->717 715->702 722 ac25c1 717->722 725 ac25c6-ac25e8 call a9fdcd 722->725 731 ac25ea 725->731 734 ac25ef-ac2611 call a9fdcd 731->734 741 ac2613 734->741 744 ac2618-ac2625 call ae64d4 741->744 743->725 750 a815d5-a815f9 call a9fe14 743->750 749 ac2627 744->749 752 ac262c-ac2639 call a9ac64 749->752 750->734 755 a815ff-a81619 call a9fe14 750->755 758 ac263b 752->758 755->744 760 a8161f-a81643 call a817d5 call a9fe14 755->760 761 ac2640-ac264d call af3245 758->761 760->752 769 a81649-a81651 760->769 768 ac264f 761->768 771 ac2654-ac2661 call af32cc 768->771 769->761 770 a81657-a81675 call a8988f call a8190a 769->770 770->771 780 a8167b-a81689 770->780 777 ac2663 771->777 779 ac2668-ac2675 call af32cc 777->779 785 ac2677 779->785 780->779 782 a8168f-a816c5 call a8988f * 3 call a81876 780->782 785->785
                          APIs
                          • mciSendStringW.WINMM(close all,00000000,00000000,00000000), ref: 00A81459
                          • CoUninitialize.COMBASE ref: 00A814F8
                          • UnregisterHotKey.USER32(?), ref: 00A816DD
                          • DestroyWindow.USER32(?), ref: 00AC24B9
                          • FreeLibrary.KERNEL32(?), ref: 00AC251E
                          • VirtualFree.KERNEL32(?,00000000,00008000), ref: 00AC254B
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Free$DestroyLibrarySendStringUninitializeUnregisterVirtualWindow
                          • String ID: close all
                          • API String ID: 469580280-3243417748
                          • Opcode ID: 6f43d49d8b27856b5f5105b09179bb5d33f972158c1d5b41ef1c13ba89febb30
                          • Instruction ID: 42f2b75d863bb9aefb37cdfdd6617b3fd0d6a239fd7d1a5c799e6a494b5c37f7
                          • Opcode Fuzzy Hash: 6f43d49d8b27856b5f5105b09179bb5d33f972158c1d5b41ef1c13ba89febb30
                          • Instruction Fuzzy Hash: 5AD147317012128FDB29EF15CA99F69F7A4BF05700F2542ADE44AAB261DB30AD13CF91

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 803 a82c63-a82cd3 CreateWindowExW * 2 ShowWindow * 2
                          APIs
                          • CreateWindowExW.USER32(00000000,AutoIt v3,AutoIt v3,00CF0000,80000000,80000000,0000012C,00000064,00000000,00000000,00000000,00000001), ref: 00A82C91
                          • CreateWindowExW.USER32(00000000,edit,00000000,50B008C4,00000000,00000000,00000000,00000000,00000000,00000001,00000000), ref: 00A82CB2
                          • ShowWindow.USER32(00000000,?,?,?,?,?,?,00A81CAD,?), ref: 00A82CC6
                          • ShowWindow.USER32(00000000,?,?,?,?,?,?,00A81CAD,?), ref: 00A82CCF
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$CreateShow
                          • String ID: AutoIt v3$edit
                          • API String ID: 1584632944-3779509399
                          • Opcode ID: bf50a22d434c1d8f88b70657125570ebf30489f6c666d950fcd335ac5d8bb63f
                          • Instruction ID: 8528698cb382afb30aa0f3d6e6dbde41c8832322707d82442e96f1870251e032
                          • Opcode Fuzzy Hash: bf50a22d434c1d8f88b70657125570ebf30489f6c666d950fcd335ac5d8bb63f
                          • Instruction Fuzzy Hash: 68F03A755803907AEB310B1BAC18FB72EBDD7C6F61F01449AF900A31B0CA610840DAB8

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 954 a83b1c-a83b27 955 a83b99-a83b9b 954->955 956 a83b29-a83b2e 954->956 957 a83b8c-a83b8f 955->957 956->955 958 a83b30-a83b48 RegOpenKeyExW 956->958 958->955 959 a83b4a-a83b69 RegQueryValueExW 958->959 960 a83b6b-a83b76 959->960 961 a83b80-a83b8b RegCloseKey 959->961 962 a83b78-a83b7a 960->962 963 a83b90-a83b97 960->963 961->957 964 a83b7e 962->964 963->964 964->961
                          APIs
                          • RegOpenKeyExW.KERNELBASE(80000001,Control Panel\Mouse,00000000,00000001,00000000,?,?,80000001,80000001,?,00A83B0F,SwapMouseButtons,00000004,?), ref: 00A83B40
                          • RegQueryValueExW.KERNELBASE(00000000,00000000,00000000,00000000,?,?,?,?,?,80000001,80000001,?,00A83B0F,SwapMouseButtons,00000004,?), ref: 00A83B61
                          • RegCloseKey.KERNELBASE(00000000,?,?,?,80000001,80000001,?,00A83B0F,SwapMouseButtons,00000004,?), ref: 00A83B83
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CloseOpenQueryValue
                          • String ID: Control Panel\Mouse
                          • API String ID: 3677997916-824357125
                          • Opcode ID: 148d19427e73264f1114dbdda428912a4c5d2e0bfb974549c12ca7f7d289ec99
                          • Instruction ID: 361b2ea40ddbd2c0bdd26b0bea4f9cfc8d8bbc5217ac4b3ea8ac4c131837ca48
                          • Opcode Fuzzy Hash: 148d19427e73264f1114dbdda428912a4c5d2e0bfb974549c12ca7f7d289ec99
                          • Instruction Fuzzy Hash: AE112AB6510208FFDF21DFA5DC48AEEBBB8EF04B84B108459A806D7110E6719F409760
                          APIs
                          • LoadStringW.USER32(00000065,?,0000007F,00000104), ref: 00AC33A2
                            • Part of subcall function 00A86B57: _wcslen.LIBCMT ref: 00A86B6A
                          • Shell_NotifyIconW.SHELL32(00000001,?), ref: 00A83A04
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: IconLoadNotifyShell_String_wcslen
                          • String ID: Line:
                          • API String ID: 2289894680-1585850449
                          • Opcode ID: d043f14bb0d7be4e81a1cebde926df53bce52c2d425dff2c99b1ecb1f06e92c7
                          • Instruction ID: 1d9184d3b820dbe5e820ba810f4b5c3302222c4d65204b057a2426f1375e4262
                          • Opcode Fuzzy Hash: d043f14bb0d7be4e81a1cebde926df53bce52c2d425dff2c99b1ecb1f06e92c7
                          • Instruction Fuzzy Hash: 5D31CF72408300AADB25FB24DC55BEBB7E8AB40B10F00496EF59A97191EF709A49C7C6
                          APIs
                          • __CxxThrowException@8.LIBVCRUNTIME ref: 00AA0668
                            • Part of subcall function 00AA32A4: RaiseException.KERNEL32(?,?,?,00AA068A,?,00B51444,?,?,?,?,?,?,00AA068A,00A81129,00B48738,00A81129), ref: 00AA3304
                          • __CxxThrowException@8.LIBVCRUNTIME ref: 00AA0685
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Exception@8Throw$ExceptionRaise
                          • String ID: Unknown exception
                          • API String ID: 3476068407-410509341
                          • Opcode ID: 548fe742a9dbf0c7a0897a1bd2c3eebed39ad751fb1ad7e37c63cbf756e48b8b
                          • Instruction ID: 6c6003fee8d07ef2c1664903574ff9d568f2106e6c024a855b707f42aacf11cf
                          • Opcode Fuzzy Hash: 548fe742a9dbf0c7a0897a1bd2c3eebed39ad751fb1ad7e37c63cbf756e48b8b
                          • Instruction Fuzzy Hash: 56F0C234A0020D7B8F00B7A4D946DAE77AC5E42358B604171B814D75E1EFB1EB69C5C0
                          APIs
                            • Part of subcall function 00A81BC3: MapVirtualKeyW.USER32(0000005B,00000000), ref: 00A81BF4
                            • Part of subcall function 00A81BC3: MapVirtualKeyW.USER32(00000010,00000000), ref: 00A81BFC
                            • Part of subcall function 00A81BC3: MapVirtualKeyW.USER32(000000A0,00000000), ref: 00A81C07
                            • Part of subcall function 00A81BC3: MapVirtualKeyW.USER32(000000A1,00000000), ref: 00A81C12
                            • Part of subcall function 00A81BC3: MapVirtualKeyW.USER32(00000011,00000000), ref: 00A81C1A
                            • Part of subcall function 00A81BC3: MapVirtualKeyW.USER32(00000012,00000000), ref: 00A81C22
                            • Part of subcall function 00A81B4A: RegisterWindowMessageW.USER32(00000004,?,00A812C4), ref: 00A81BA2
                          • GetStdHandle.KERNEL32(000000F6,00000000,00000000), ref: 00A8136A
                          • OleInitialize.OLE32 ref: 00A81388
                          • CloseHandle.KERNEL32(00000000,00000000), ref: 00AC24AB
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Virtual$Handle$CloseInitializeMessageRegisterWindow
                          • String ID:
                          • API String ID: 1986988660-0
                          • Opcode ID: a4137cd03fefac0c8f3cbd276562f7e815aa6cb6189caf7d701ebf479c50db77
                          • Instruction ID: 0c6c20a70c9c906960dedff233462016d040db3903a9d540716ea9b5d35e0570
                          • Opcode Fuzzy Hash: a4137cd03fefac0c8f3cbd276562f7e815aa6cb6189caf7d701ebf479c50db77
                          • Instruction Fuzzy Hash: 9C71B6B59023008ED785EF7DBA457A53AE4BBA83867548EEAD41AC7361FF304885CF50
                          APIs
                            • Part of subcall function 00A83923: Shell_NotifyIconW.SHELL32(00000001,?), ref: 00A83A04
                          • Shell_NotifyIconW.SHELL32(00000001,000003A8), ref: 00AEC259
                          • KillTimer.USER32(?,00000001,?,?), ref: 00AEC261
                          • SetTimer.USER32(?,00000001,000002EE,00000000), ref: 00AEC270
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: IconNotifyShell_Timer$Kill
                          • String ID:
                          • API String ID: 3500052701-0
                          • Opcode ID: de86bf545dfab11a608d1b97e1cea2f833eb61513923be0e1f050f0ff208a1b3
                          • Instruction ID: ce7f237684f6463f448543216748aec29aa9c1d8523436476f6d771ece699384
                          • Opcode Fuzzy Hash: de86bf545dfab11a608d1b97e1cea2f833eb61513923be0e1f050f0ff208a1b3
                          • Instruction Fuzzy Hash: 3031D570904384AFEB32AF758855BEBBBFC9F06314F00449EE2DA97241C7745A86CB51
                          APIs
                          • CloseHandle.KERNELBASE(00000000,00000000,?,?,00AB85CC,?,00B48CC8,0000000C), ref: 00AB8704
                          • GetLastError.KERNEL32(?,00AB85CC,?,00B48CC8,0000000C), ref: 00AB870E
                          • __dosmaperr.LIBCMT ref: 00AB8739
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CloseErrorHandleLast__dosmaperr
                          • String ID:
                          • API String ID: 2583163307-0
                          • Opcode ID: 299b072e0650dbac25d41e5f2659b23fbe58cf6c4931d76a04147778d4b27163
                          • Instruction ID: b62a99bbf24d58527a8fe573d6f09779fcaad0f927a05f5d1d45a97ae0688036
                          • Opcode Fuzzy Hash: 299b072e0650dbac25d41e5f2659b23fbe58cf6c4931d76a04147778d4b27163
                          • Instruction Fuzzy Hash: 6A014E32A0572026D664733CA9557FE6B9D4B92778F390159F8148F1D3DEB8CC81D150
                          APIs
                          • TranslateMessage.USER32(?), ref: 00A8DB7B
                          • DispatchMessageW.USER32(?), ref: 00A8DB89
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00A8DB9F
                          • Sleep.KERNELBASE(0000000A), ref: 00A8DBB1
                          • TranslateAcceleratorW.USER32(?,?,?), ref: 00AD1CC9
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Message$Translate$AcceleratorDispatchPeekSleep
                          • String ID:
                          • API String ID: 3288985973-0
                          • Opcode ID: 532381368b20759fbc6d05a6ec66bc7410ac4042e9b18cb7237c19efa933bfb5
                          • Instruction ID: 2d122ac9e5dd2bba04406a4d8872e69f75ce5623849c35a9d8c58cdbb2af5f10
                          • Opcode Fuzzy Hash: 532381368b20759fbc6d05a6ec66bc7410ac4042e9b18cb7237c19efa933bfb5
                          • Instruction Fuzzy Hash: 7BF05E306443409BEB30DB608C49FEA77A9EB45311F508919E65A830C0DF7098488B25
                          APIs
                          • __Init_thread_footer.LIBCMT ref: 00A917F6
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Init_thread_footer
                          • String ID: CALL
                          • API String ID: 1385522511-4196123274
                          • Opcode ID: 363cc4c46b67d86bd052997b67432d3a44f126241fc410e27db93737dca169cb
                          • Instruction ID: 4debb884a98a4e51ae94e70994ae7b005391f74b850ff663eeddb282c6023a84
                          • Opcode Fuzzy Hash: 363cc4c46b67d86bd052997b67432d3a44f126241fc410e27db93737dca169cb
                          • Instruction Fuzzy Hash: 6C228BB46083029FCB14DF14C584B2ABBF1BF89314F29895DF5968B3A2D731E945CB92
                          APIs
                          • GetOpenFileNameW.COMDLG32(?), ref: 00AC2C8C
                            • Part of subcall function 00A83AA2: GetFullPathNameW.KERNEL32(?,00007FFF,?,00000000,?,?,00A83A97,?,?,00A82E7F,?,?,?,00000000), ref: 00A83AC2
                            • Part of subcall function 00A82DA5: GetLongPathNameW.KERNELBASE(?,?,00007FFF), ref: 00A82DC4
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Name$Path$FileFullLongOpen
                          • String ID: X
                          • API String ID: 779396738-3081909835
                          • Opcode ID: 1fc35abb5930b04289a46070919c3417fec31fcc686c8c2664dceb735db7c33b
                          • Instruction ID: 58a730e53c2986fa6dacd10e5caa5d173b8820fdceba1fdf916e44cbb634ab3f
                          • Opcode Fuzzy Hash: 1fc35abb5930b04289a46070919c3417fec31fcc686c8c2664dceb735db7c33b
                          • Instruction Fuzzy Hash: F021B771A002589FDF01EF94C949BEE7BFCAF49715F008059E405B7241DBB45A898FA1
                          APIs
                          • Shell_NotifyIconW.SHELL32(00000000,?), ref: 00A83908
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: IconNotifyShell_
                          • String ID:
                          • API String ID: 1144537725-0
                          • Opcode ID: 5f51b6139bddc1288164ebce9e8d5268362626f8cfd22a46c5f1e999caa8f299
                          • Instruction ID: d3945723bd1b4a6c517635ae33e366bb7befa1b8834c6eb82645ef614a0ee4bb
                          • Opcode Fuzzy Hash: 5f51b6139bddc1288164ebce9e8d5268362626f8cfd22a46c5f1e999caa8f299
                          • Instruction Fuzzy Hash: DE3193715043019FDB20EF24D894797BBE4FB49709F00096EF59987250EB71AA44CB52
                          APIs
                          • timeGetTime.WINMM ref: 00A9F661
                            • Part of subcall function 00A8D730: GetInputState.USER32 ref: 00A8D807
                          • Sleep.KERNEL32(00000000), ref: 00ADF2DE
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: InputSleepStateTimetime
                          • String ID:
                          • API String ID: 4149333218-0
                          • Opcode ID: 1252358bc7003941cf336eab2a456d0f6e38ebdde1d2ad200ff403fd39da929f
                          • Instruction ID: 25ab10f43cad830e668693b51d421d2dc2a17f265661ef3880d331c36ea51415
                          • Opcode Fuzzy Hash: 1252358bc7003941cf336eab2a456d0f6e38ebdde1d2ad200ff403fd39da929f
                          • Instruction Fuzzy Hash: 7BF082712803059FD314FF65D545B9ABBE4EF45760F004029E85AC73A1DB70A800CB90
                          APIs
                          • __Init_thread_footer.LIBCMT ref: 00A8BB4E
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Init_thread_footer
                          • String ID:
                          • API String ID: 1385522511-0
                          • Opcode ID: 85f7d678ea5678c9868280b80a993fc580baeb6a71313f14d573fb1485649781
                          • Instruction ID: 67d1596d4480087d191de2c349764e16a96255bdd43d0a00e6f755b58ba38a9a
                          • Opcode Fuzzy Hash: 85f7d678ea5678c9868280b80a993fc580baeb6a71313f14d573fb1485649781
                          • Instruction Fuzzy Hash: F832AB34A002099FDB24EF54C894FBEB7B9EF45340F18809AE916AB361D774ED41CBA1
                          APIs
                            • Part of subcall function 00A84E90: LoadLibraryA.KERNEL32(kernel32.dll,?,?,00A84EDD,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84E9C
                            • Part of subcall function 00A84E90: GetProcAddress.KERNEL32(00000000,Wow64DisableWow64FsRedirection), ref: 00A84EAE
                            • Part of subcall function 00A84E90: FreeLibrary.KERNEL32(00000000,?,?,00A84EDD,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84EC0
                          • LoadLibraryExW.KERNEL32(?,00000000,00000002,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84EFD
                            • Part of subcall function 00A84E59: LoadLibraryA.KERNEL32(kernel32.dll,?,?,00AC3CDE,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84E62
                            • Part of subcall function 00A84E59: GetProcAddress.KERNEL32(00000000,Wow64RevertWow64FsRedirection), ref: 00A84E74
                            • Part of subcall function 00A84E59: FreeLibrary.KERNEL32(00000000,?,?,00AC3CDE,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84E87
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Library$Load$AddressFreeProc
                          • String ID:
                          • API String ID: 2632591731-0
                          • Opcode ID: f936b5ab68e8235e9745e8c89b56583751af2a5be0fcc924dc47e68579162d5c
                          • Instruction ID: 5a8df62306b267249aa0ab9d9c43d4dfddee8159d0fe6ccf55c420d43da0ca0c
                          • Opcode Fuzzy Hash: f936b5ab68e8235e9745e8c89b56583751af2a5be0fcc924dc47e68579162d5c
                          • Instruction Fuzzy Hash: 8B11E332600206AACF14FF70DE02FED77A5AF48B14F20842EF642A61D1EE709E459B90
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: __wsopen_s
                          • String ID:
                          • API String ID: 3347428461-0
                          • Opcode ID: cb9d16bfaefe56ca91b4ce430b0448bf34a4900a5faadc3b1034f3fe3c0e7357
                          • Instruction ID: 2c065155f934ae03b318901469a2de5f674d7456fcb1080a86ed429e3a6202e1
                          • Opcode Fuzzy Hash: cb9d16bfaefe56ca91b4ce430b0448bf34a4900a5faadc3b1034f3fe3c0e7357
                          • Instruction Fuzzy Hash: 9B11187590420AAFCF05DF58E941ADA7BF9EF48314F114199FC08AB312DA31DA11CBA5
                          APIs
                            • Part of subcall function 00AB4C7D: RtlAllocateHeap.NTDLL(00000008,00A81129,00000000,?,00AB2E29,00000001,00000364,?,?,?,00AAF2DE,00AB3863,00B51444,?,00A9FDF5,?), ref: 00AB4CBE
                          • _free.LIBCMT ref: 00AB506C
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AllocateHeap_free
                          • String ID:
                          • API String ID: 614378929-0
                          • Opcode ID: 9ba45ce058d1080761d5af908226540236078fd1fc19e2e0238d0ad147f07c6e
                          • Instruction ID: c8e7dcaf21eb0d827b6ea6d2929e0235ee3f89299a7351171537db92ebd8601e
                          • Opcode Fuzzy Hash: 9ba45ce058d1080761d5af908226540236078fd1fc19e2e0238d0ad147f07c6e
                          • Instruction Fuzzy Hash: 0A0149726047056FE3319F65D881ADAFBECFB89370F25052DE184832C2EA30A905C7B4
                          APIs
                          • GetForegroundWindow.USER32(00000000,?,?,?,00B114B5,?), ref: 00B12A01
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ForegroundWindow
                          • String ID:
                          • API String ID: 2020703349-0
                          • Opcode ID: 1203ff758a2badfeb36dd41635d1bf5c760bae75d7f83d4c70129d931961ae8f
                          • Instruction ID: 67aa28cc21d77dd34d6e614707fad01c9280eb3fe801809fc021c91efc2c38d5
                          • Opcode Fuzzy Hash: 1203ff758a2badfeb36dd41635d1bf5c760bae75d7f83d4c70129d931961ae8f
                          • Instruction Fuzzy Hash: EF019E36350A419FD3258B6CC494BA23BD2EF85354FA984A8C0478B251DB32EC92C7A0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: d6c69ec2a70ac845cc05b5f137181c3f07394ab8b33ef369e8c7ef627d5c9574
                          • Instruction ID: 5c720be89bbabe7fa1cdbdf1bbe034fe030e169de2f175af08e4c741acb0de7d
                          • Opcode Fuzzy Hash: d6c69ec2a70ac845cc05b5f137181c3f07394ab8b33ef369e8c7ef627d5c9574
                          • Instruction Fuzzy Hash: 3DF0F432511A10AAD6317B698E05B9A739C9F53330F100F1AF425931D3DB74D80586A5
                          APIs
                          • RtlAllocateHeap.NTDLL(00000008,00A81129,00000000,?,00AB2E29,00000001,00000364,?,?,?,00AAF2DE,00AB3863,00B51444,?,00A9FDF5,?), ref: 00AB4CBE
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AllocateHeap
                          • String ID:
                          • API String ID: 1279760036-0
                          • Opcode ID: b4027969909b799f02409888a5c1918f98d9eeb6e9087febe266085ba1a746f9
                          • Instruction ID: 2a13cc43aff9c2ed5cad346139aef5b3bc9f3a5b41f95fa960d41f7c8411e908
                          • Opcode Fuzzy Hash: b4027969909b799f02409888a5c1918f98d9eeb6e9087febe266085ba1a746f9
                          • Instruction Fuzzy Hash: 10F0B43164632466DB215F669D05BDA3F9CAF8BFA1B144121F919A71C3CB71DC1046E0
                          APIs
                          • RtlAllocateHeap.NTDLL(00000000,?,00B51444,?,00A9FDF5,?,?,00A8A976,00000010,00B51440,00A813FC,?,00A813C6,?,00A81129), ref: 00AB3852
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AllocateHeap
                          • String ID:
                          • API String ID: 1279760036-0
                          • Opcode ID: 0aec889a6b9f3c72acd47269aaa1ab68b9e5b3ae521b2c47b0c8e5569108ff6c
                          • Instruction ID: 3fce964ddd8493587830abb293876afe77533f575295570838016d861941c32e
                          • Opcode Fuzzy Hash: 0aec889a6b9f3c72acd47269aaa1ab68b9e5b3ae521b2c47b0c8e5569108ff6c
                          • Instruction Fuzzy Hash: AEE0A0331423246ADE212BFA9D00BDA365CAB827B0F160021BC04934D2DB509D0181E2
                          APIs
                          • FreeLibrary.KERNEL32(?,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84F6D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FreeLibrary
                          • String ID:
                          • API String ID: 3664257935-0
                          • Opcode ID: 9c96fc223ef94cc3b11c5fb8a728f0f37be2fc7ae0e447c01174fcda7ceb6ea0
                          • Instruction ID: 0ca0cee64526943acd640547917ef84d0493d2687fead791ffe23d9f852ed2fa
                          • Opcode Fuzzy Hash: 9c96fc223ef94cc3b11c5fb8a728f0f37be2fc7ae0e447c01174fcda7ceb6ea0
                          • Instruction Fuzzy Hash: 58F03971105752CFDB34AF64D590822BBF4BF187293258A7EE2EA83621CB319C44DF10
                          APIs
                          • IsWindow.USER32(00000000), ref: 00B12A66
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window
                          • String ID:
                          • API String ID: 2353593579-0
                          • Opcode ID: 02e25c0b6ad95ae7cafde8bcd6894ed507e6e6b1cf8d69f1dad70af69c22664f
                          • Instruction ID: 743c129c650ea516b4bbc2e4c7f69103f9dea92e33dd7f6cae489d60006be3c5
                          • Opcode Fuzzy Hash: 02e25c0b6ad95ae7cafde8bcd6894ed507e6e6b1cf8d69f1dad70af69c22664f
                          • Instruction Fuzzy Hash: 4CE04F363A011AAACB14EB31DCC48FA779CEF55395750457ABC16C3100DB30A9A586A0
                          APIs
                          • Shell_NotifyIconW.SHELL32(00000002,?), ref: 00A8314E
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: IconNotifyShell_
                          • String ID:
                          • API String ID: 1144537725-0
                          • Opcode ID: 3a8c518591d812c2fe3cfb3f74b9f7a48e7d5087baba076fa8f6f3e5d41240d3
                          • Instruction ID: fc0d8fa4b39032ca15a5b506a5978329eea1e987c8e48436dda56af65649558c
                          • Opcode Fuzzy Hash: 3a8c518591d812c2fe3cfb3f74b9f7a48e7d5087baba076fa8f6f3e5d41240d3
                          • Instruction Fuzzy Hash: D5F03070914318AFEB529B28DC4A7DA7BBCAB01708F0005E9A68897292DB745B89CF55
                          APIs
                          • GetLongPathNameW.KERNELBASE(?,?,00007FFF), ref: 00A82DC4
                            • Part of subcall function 00A86B57: _wcslen.LIBCMT ref: 00A86B6A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: LongNamePath_wcslen
                          • String ID:
                          • API String ID: 541455249-0
                          • Opcode ID: ea94aa46a1f3da6d77362688306c5342cfe30d907f9202d6fb3661b0534c8ecc
                          • Instruction ID: dc883996c23a11785ed340b6d548cef69ecc23eeec340073b971e92afbb7fd81
                          • Opcode Fuzzy Hash: ea94aa46a1f3da6d77362688306c5342cfe30d907f9202d6fb3661b0534c8ecc
                          • Instruction Fuzzy Hash: 2EE0C272A002245BCB20A6989C0AFEA77EDDFC8794F0540B6FD09E7248DA70ED808690
                          APIs
                            • Part of subcall function 00A83837: Shell_NotifyIconW.SHELL32(00000000,?), ref: 00A83908
                            • Part of subcall function 00A8D730: GetInputState.USER32 ref: 00A8D807
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00A82B6B
                            • Part of subcall function 00A830F2: Shell_NotifyIconW.SHELL32(00000002,?), ref: 00A8314E
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: IconNotifyShell_$CurrentDirectoryInputState
                          • String ID:
                          • API String ID: 3667716007-0
                          • Opcode ID: 1965a6841f35da200d937a17d9fcf6a2b4bb73988a08b83b65120c3855cc7259
                          • Instruction ID: ee4ed1403ae1cbdda77576167731a2d719a7774724a9e0a37059b7efbeec7c09
                          • Opcode Fuzzy Hash: 1965a6841f35da200d937a17d9fcf6a2b4bb73988a08b83b65120c3855cc7259
                          • Instruction Fuzzy Hash: B2E0863370424406CE04BB74AA566BDA7599BD1756F40197EF542472A2CE2449494752
                          APIs
                          • CreateFileW.KERNELBASE(00000000,00000000,?,00AC0704,?,?,00000000,?,00AC0704,00000000,0000000C), ref: 00AC03B7
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CreateFile
                          • String ID:
                          • API String ID: 823142352-0
                          • Opcode ID: b776737d84c988da700726b8a564ee3827695a029b094eb2d6f945b055fef015
                          • Instruction ID: b8d9eef3d3a76fbbd67537f88c4555b729ddf64e3224afe741e551ec1f067939
                          • Opcode Fuzzy Hash: b776737d84c988da700726b8a564ee3827695a029b094eb2d6f945b055fef015
                          • Instruction Fuzzy Hash: FFD06C3208010DBBDF028F84DD06EDA3FAAFB48714F018000BE18A6020C732E831AB90
                          APIs
                          • SystemParametersInfoW.USER32(00002001,00000000,00000002), ref: 00A81CBC
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: InfoParametersSystem
                          • String ID:
                          • API String ID: 3098949447-0
                          • Opcode ID: 4f2b0f2ea3f7cef68d2ae65e25af08b6b3f84da139c69aeafe108f947fabd59c
                          • Instruction ID: 896f58e01bf12f7d65285ee406927c5d629dfadd85666f3ef4bce10debaf113c
                          • Opcode Fuzzy Hash: 4f2b0f2ea3f7cef68d2ae65e25af08b6b3f84da139c69aeafe108f947fabd59c
                          • Instruction Fuzzy Hash: 79C092362C1304AFF2158B84BC5BF507B65A368B02F448841FA09AB5F3DBA22820EA54
                          APIs
                            • Part of subcall function 00A99BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 00A99BB2
                          • DefDlgProcW.USER32(?,0000004E,?,?,?,?,?,?), ref: 00B1961A
                          • SendMessageW.USER32(?,0000130B,00000000,00000000), ref: 00B1965B
                          • GetWindowLongW.USER32(FFFFFDD9,000000F0), ref: 00B1969F
                          • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00B196C9
                          • SendMessageW.USER32 ref: 00B196F2
                          • GetKeyState.USER32(00000011), ref: 00B1978B
                          • GetKeyState.USER32(00000009), ref: 00B19798
                          • SendMessageW.USER32(?,0000130B,00000000,00000000), ref: 00B197AE
                          • GetKeyState.USER32(00000010), ref: 00B197B8
                          • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00B197E9
                          • SendMessageW.USER32 ref: 00B19810
                          • SendMessageW.USER32(?,00001030,?,00B17E95), ref: 00B19918
                          • ImageList_SetDragCursorImage.COMCTL32(00000000,00000000,00000000,?,?,?), ref: 00B1992E
                          • ImageList_BeginDrag.COMCTL32(00000000,000000F8,000000F0), ref: 00B19941
                          • SetCapture.USER32(?), ref: 00B1994A
                          • ClientToScreen.USER32(?,?), ref: 00B199AF
                          • ImageList_DragEnter.COMCTL32(00000000,?,?), ref: 00B199BC
                          • InvalidateRect.USER32(?,00000000,00000001,?,?,?), ref: 00B199D6
                          • ReleaseCapture.USER32 ref: 00B199E1
                          • GetCursorPos.USER32(?), ref: 00B19A19
                          • ScreenToClient.USER32(?,?), ref: 00B19A26
                          • SendMessageW.USER32(?,00001012,00000000,?), ref: 00B19A80
                          • SendMessageW.USER32 ref: 00B19AAE
                          • SendMessageW.USER32(?,00001111,00000000,?), ref: 00B19AEB
                          • SendMessageW.USER32 ref: 00B19B1A
                          • SendMessageW.USER32(?,0000110B,00000009,00000000), ref: 00B19B3B
                          • SendMessageW.USER32(?,0000110B,00000009,?), ref: 00B19B4A
                          • GetCursorPos.USER32(?), ref: 00B19B68
                          • ScreenToClient.USER32(?,?), ref: 00B19B75
                          • GetParent.USER32(?), ref: 00B19B93
                          • SendMessageW.USER32(?,00001012,00000000,?), ref: 00B19BFA
                          • SendMessageW.USER32 ref: 00B19C2B
                          • ClientToScreen.USER32(?,?), ref: 00B19C84
                          • TrackPopupMenuEx.USER32(?,00000000,?,?,?,00000000), ref: 00B19CB4
                          • SendMessageW.USER32(?,00001111,00000000,?), ref: 00B19CDE
                          • SendMessageW.USER32 ref: 00B19D01
                          • ClientToScreen.USER32(?,?), ref: 00B19D4E
                          • TrackPopupMenuEx.USER32(?,00000080,?,?,?,00000000), ref: 00B19D82
                            • Part of subcall function 00A99944: GetWindowLongW.USER32(?,000000EB), ref: 00A99952
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B19E05
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$ClientScreen$ImageLongWindow$CursorDragList_State$CaptureMenuPopupTrack$BeginEnterInvalidateParentProcRectRelease
                          • String ID: @GUI_DRAGID$F
                          • API String ID: 3429851547-4164748364
                          • Opcode ID: 3866d577d0f1ff954937800a6b954fd7da64b38b6ab993bae16e650ad8da3f46
                          • Instruction ID: f75a0bb681a6c8f04a267088a8e453b4697d732d0f7b81e759a8ffa1cd1e6a82
                          • Opcode Fuzzy Hash: 3866d577d0f1ff954937800a6b954fd7da64b38b6ab993bae16e650ad8da3f46
                          • Instruction Fuzzy Hash: A9428F71204281EFD724CF28CC54BEABBE5FF89310F544AA9F595872A1DB319C94CB51
                          APIs
                          • SendMessageW.USER32(00000000,00000408,00000000,00000000), ref: 00B148F3
                          • SendMessageW.USER32(00000000,00000188,00000000,00000000), ref: 00B14908
                          • SendMessageW.USER32(00000000,0000018A,00000000,00000000), ref: 00B14927
                          • SendMessageW.USER32(?,00000148,00000000,00000000), ref: 00B1494B
                          • SendMessageW.USER32(00000000,00000147,00000000,00000000), ref: 00B1495C
                          • SendMessageW.USER32(00000000,00000149,00000000,00000000), ref: 00B1497B
                          • SendMessageW.USER32(00000000,0000130B,00000000,00000000), ref: 00B149AE
                          • SendMessageW.USER32(00000000,0000133C,00000000,?), ref: 00B149D4
                          • SendMessageW.USER32(00000000,0000110A,00000009,00000000), ref: 00B14A0F
                          • SendMessageW.USER32(00000000,0000113E,00000000,00000004), ref: 00B14A56
                          • SendMessageW.USER32(00000000,0000113E,00000000,00000004), ref: 00B14A7E
                          • IsMenu.USER32(?), ref: 00B14A97
                          • GetMenuItemInfoW.USER32(?,?,00000000,?), ref: 00B14AF2
                          • GetMenuItemInfoW.USER32(?,?,00000000,?), ref: 00B14B20
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B14B94
                          • SendMessageW.USER32(?,0000113E,00000000,00000008), ref: 00B14BE3
                          • SendMessageW.USER32(00000000,00001001,00000000,?), ref: 00B14C82
                          • wsprintfW.USER32 ref: 00B14CAE
                          • SendMessageW.USER32(00000000,0000000E,00000000,00000000), ref: 00B14CC9
                          • GetWindowTextW.USER32(?,00000000,00000001), ref: 00B14CF1
                          • SendMessageW.USER32(00000000,000000F0,00000000,00000000), ref: 00B14D13
                          • SendMessageW.USER32(00000000,0000000E,00000000,00000000), ref: 00B14D33
                          • GetWindowTextW.USER32(?,00000000,00000001), ref: 00B14D5A
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$MenuWindow$InfoItemText$Longwsprintf
                          • String ID: %d/%02d/%02d
                          • API String ID: 4054740463-328681919
                          • Opcode ID: 1af160657e7a5c0f4b68de4df2eff3514680c37979a76d7cb2e4648fcb8c4c9f
                          • Instruction ID: 1622c0225e5d3a54343e3b479537721362b75bd8010a1413382bde88818bf174
                          • Opcode Fuzzy Hash: 1af160657e7a5c0f4b68de4df2eff3514680c37979a76d7cb2e4648fcb8c4c9f
                          • Instruction Fuzzy Hash: BE12BB71640214AFEB248F28CC89FEE7BE8EF45710F5441A9F51AEB2A1DB749981CB50
                          APIs
                          • GetForegroundWindow.USER32(00000000,00000000,00000000), ref: 00A9F998
                          • FindWindowW.USER32(Shell_TrayWnd,00000000), ref: 00ADF474
                          • IsIconic.USER32(00000000), ref: 00ADF47D
                          • ShowWindow.USER32(00000000,00000009), ref: 00ADF48A
                          • SetForegroundWindow.USER32(00000000), ref: 00ADF494
                          • GetWindowThreadProcessId.USER32(00000000,00000000), ref: 00ADF4AA
                          • GetCurrentThreadId.KERNEL32 ref: 00ADF4B1
                          • GetWindowThreadProcessId.USER32(00000000,00000000), ref: 00ADF4BD
                          • AttachThreadInput.USER32(?,00000000,00000001), ref: 00ADF4CE
                          • AttachThreadInput.USER32(?,00000000,00000001), ref: 00ADF4D6
                          • AttachThreadInput.USER32(00000000,000000FF,00000001), ref: 00ADF4DE
                          • SetForegroundWindow.USER32(00000000), ref: 00ADF4E1
                          • MapVirtualKeyW.USER32(00000012,00000000), ref: 00ADF4F6
                          • keybd_event.USER32(00000012,00000000), ref: 00ADF501
                          • MapVirtualKeyW.USER32(00000012,00000000), ref: 00ADF50B
                          • keybd_event.USER32(00000012,00000000), ref: 00ADF510
                          • MapVirtualKeyW.USER32(00000012,00000000), ref: 00ADF519
                          • keybd_event.USER32(00000012,00000000), ref: 00ADF51E
                          • MapVirtualKeyW.USER32(00000012,00000000), ref: 00ADF528
                          • keybd_event.USER32(00000012,00000000), ref: 00ADF52D
                          • SetForegroundWindow.USER32(00000000), ref: 00ADF530
                          • AttachThreadInput.USER32(?,000000FF,00000000), ref: 00ADF557
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Thread$AttachForegroundInputVirtualkeybd_event$Process$CurrentFindIconicShow
                          • String ID: Shell_TrayWnd
                          • API String ID: 4125248594-2988720461
                          • Opcode ID: cdf5eeaa24ae4d422551c607b9086bc818a39103724c9c4e71df259906ca73b2
                          • Instruction ID: c99001258ad5bb2b62d7ed78150cad3b029e570d632f910afa8f94cfde8ed0a4
                          • Opcode Fuzzy Hash: cdf5eeaa24ae4d422551c607b9086bc818a39103724c9c4e71df259906ca73b2
                          • Instruction Fuzzy Hash: D2314371A80318BFEB216BB55C4AFBF7E6DEB44B50F504066FA02E71D1CBB15D00AA60
                          APIs
                            • Part of subcall function 00AE16C3: LookupPrivilegeValueW.ADVAPI32(00000000,00000000,00000004), ref: 00AE170D
                            • Part of subcall function 00AE16C3: AdjustTokenPrivileges.ADVAPI32(?,00000000,00000000,?,00000000,?), ref: 00AE173A
                            • Part of subcall function 00AE16C3: GetLastError.KERNEL32 ref: 00AE174A
                          • LogonUserW.ADVAPI32(?,?,?,00000000,00000000,?), ref: 00AE1286
                          • DuplicateTokenEx.ADVAPI32(?,00000000,00000000,00000002,00000001,?), ref: 00AE12A8
                          • CloseHandle.KERNEL32(?), ref: 00AE12B9
                          • OpenWindowStationW.USER32(winsta0,00000000,00060000), ref: 00AE12D1
                          • GetProcessWindowStation.USER32 ref: 00AE12EA
                          • SetProcessWindowStation.USER32(00000000), ref: 00AE12F4
                          • OpenDesktopW.USER32(default,00000000,00000000,00060081), ref: 00AE1310
                            • Part of subcall function 00AE10BF: AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000,?,00AE11FC), ref: 00AE10D4
                            • Part of subcall function 00AE10BF: CloseHandle.KERNEL32(?,?,00AE11FC), ref: 00AE10E9
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: StationTokenWindow$AdjustCloseHandleOpenPrivilegesProcess$DesktopDuplicateErrorLastLogonLookupPrivilegeUserValue
                          • String ID: $default$winsta0
                          • API String ID: 22674027-1027155976
                          • Opcode ID: 9fb00876ce6bbd3a74c7126db11ed938893fb9962e45c4f654ced4797dd83ede
                          • Instruction ID: 5d4cbb71dcbaec49513a16278a315e0ddb304006866b55c26275bbea0534c9c8
                          • Opcode Fuzzy Hash: 9fb00876ce6bbd3a74c7126db11ed938893fb9962e45c4f654ced4797dd83ede
                          • Instruction Fuzzy Hash: 0581A0B1A40299AFDF219FA5DD49FEE7FB9EF04704F148129F911A72A0DB708954CB20
                          APIs
                            • Part of subcall function 00AE10F9: GetUserObjectSecurity.USER32(?,00000004,?,00000000,?), ref: 00AE1114
                            • Part of subcall function 00AE10F9: GetLastError.KERNEL32(?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE1120
                            • Part of subcall function 00AE10F9: GetProcessHeap.KERNEL32(00000008,?,?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE112F
                            • Part of subcall function 00AE10F9: HeapAlloc.KERNEL32(00000000,?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE1136
                            • Part of subcall function 00AE10F9: GetUserObjectSecurity.USER32(?,00000004,00000000,?,?), ref: 00AE114D
                          • GetSecurityDescriptorDacl.ADVAPI32(?,?,?,?), ref: 00AE0BCC
                          • GetAclInformation.ADVAPI32(?,?,0000000C,00000002), ref: 00AE0C00
                          • GetLengthSid.ADVAPI32(?), ref: 00AE0C17
                          • GetAce.ADVAPI32(?,00000000,?), ref: 00AE0C51
                          • AddAce.ADVAPI32(?,00000002,000000FF,?,?), ref: 00AE0C6D
                          • GetLengthSid.ADVAPI32(?), ref: 00AE0C84
                          • GetProcessHeap.KERNEL32(00000008,00000008), ref: 00AE0C8C
                          • HeapAlloc.KERNEL32(00000000), ref: 00AE0C93
                          • GetLengthSid.ADVAPI32(?,00000008,?), ref: 00AE0CB4
                          • CopySid.ADVAPI32(00000000), ref: 00AE0CBB
                          • AddAce.ADVAPI32(?,00000002,000000FF,00000000,?), ref: 00AE0CEA
                          • SetSecurityDescriptorDacl.ADVAPI32(?,00000001,?,00000000), ref: 00AE0D0C
                          • SetUserObjectSecurity.USER32(?,00000004,?), ref: 00AE0D1E
                          • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00AE0D45
                          • HeapFree.KERNEL32(00000000), ref: 00AE0D4C
                          • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00AE0D55
                          • HeapFree.KERNEL32(00000000), ref: 00AE0D5C
                          • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00AE0D65
                          • HeapFree.KERNEL32(00000000), ref: 00AE0D6C
                          • GetProcessHeap.KERNEL32(00000000,?), ref: 00AE0D78
                          • HeapFree.KERNEL32(00000000), ref: 00AE0D7F
                            • Part of subcall function 00AE1193: GetProcessHeap.KERNEL32(00000008,00AE0BB1,?,00000000,?,00AE0BB1,?), ref: 00AE11A1
                            • Part of subcall function 00AE1193: HeapAlloc.KERNEL32(00000000,?,00000000,?,00AE0BB1,?), ref: 00AE11A8
                            • Part of subcall function 00AE1193: InitializeSecurityDescriptor.ADVAPI32(00000000,00000001,?,00000000,?,00AE0BB1,?), ref: 00AE11B7
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Heap$Process$Security$Free$AllocDescriptorLengthObjectUser$Dacl$CopyErrorInformationInitializeLast
                          • String ID:
                          • API String ID: 4175595110-0
                          • Opcode ID: 0a6519f26cdedf87c125d92ea647da77c897df16680e61e79d0fc460b81d1c97
                          • Instruction ID: c29a2b3d2f78f0dda76b0ccf5bd91b40ceb7d7517ae2e483afc2710b6248f80c
                          • Opcode Fuzzy Hash: 0a6519f26cdedf87c125d92ea647da77c897df16680e61e79d0fc460b81d1c97
                          • Instruction Fuzzy Hash: 23715C7294024AEBDF10DFA5DC88FEEBBB8FF08300F148515E915A7191DBB5AA45CB60
                          APIs
                          • OpenClipboard.USER32(00B1CC08), ref: 00AFEB29
                          • IsClipboardFormatAvailable.USER32(0000000D), ref: 00AFEB37
                          • GetClipboardData.USER32(0000000D), ref: 00AFEB43
                          • CloseClipboard.USER32 ref: 00AFEB4F
                          • GlobalLock.KERNEL32(00000000), ref: 00AFEB87
                          • CloseClipboard.USER32 ref: 00AFEB91
                          • GlobalUnlock.KERNEL32(00000000), ref: 00AFEBBC
                          • IsClipboardFormatAvailable.USER32(00000001), ref: 00AFEBC9
                          • GetClipboardData.USER32(00000001), ref: 00AFEBD1
                          • GlobalLock.KERNEL32(00000000), ref: 00AFEBE2
                          • GlobalUnlock.KERNEL32(00000000), ref: 00AFEC22
                          • IsClipboardFormatAvailable.USER32(0000000F), ref: 00AFEC38
                          • GetClipboardData.USER32(0000000F), ref: 00AFEC44
                          • GlobalLock.KERNEL32(00000000), ref: 00AFEC55
                          • DragQueryFileW.SHELL32(00000000,000000FF,00000000,00000000), ref: 00AFEC77
                          • DragQueryFileW.SHELL32(00000000,?,?,00000104), ref: 00AFEC94
                          • DragQueryFileW.SHELL32(00000000,?,?,00000104), ref: 00AFECD2
                          • GlobalUnlock.KERNEL32(00000000), ref: 00AFECF3
                          • CountClipboardFormats.USER32 ref: 00AFED14
                          • CloseClipboard.USER32 ref: 00AFED59
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Clipboard$Global$AvailableCloseDataDragFileFormatLockQueryUnlock$CountFormatsOpen
                          • String ID:
                          • API String ID: 420908878-0
                          • Opcode ID: 61213cf9bfa17d5f22bba42af2de622772183f134fc391e5bcf9384712aac4a9
                          • Instruction ID: 65eca84ac2b1f306c65b8878b438251491c362fc5de42e0834144c4ea3ce4857
                          • Opcode Fuzzy Hash: 61213cf9bfa17d5f22bba42af2de622772183f134fc391e5bcf9384712aac4a9
                          • Instruction Fuzzy Hash: 8761BC34244205AFD310EFA4C888FBA7BA4AF84704F488559F596972A2DF31DD06CBA2
                          APIs
                          • FindFirstFileW.KERNEL32(?,?), ref: 00AF69BE
                          • FindClose.KERNEL32(00000000), ref: 00AF6A12
                          • FileTimeToLocalFileTime.KERNEL32(?,?), ref: 00AF6A4E
                          • FileTimeToLocalFileTime.KERNEL32(?,?), ref: 00AF6A75
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • FileTimeToSystemTime.KERNEL32(?,?), ref: 00AF6AB2
                          • FileTimeToSystemTime.KERNEL32(?,?), ref: 00AF6ADF
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Time$File$FindLocalSystem$CloseFirst_wcslen
                          • String ID: %02d$%03d$%4d$%4d%02d%02d%02d%02d%02d$%4d%02d%02d%02d%02d%02d%03d
                          • API String ID: 3830820486-3289030164
                          • Opcode ID: 03bce68515b9d767fb44ef4151beda1e36e693f5189286deaa4d904197ef0f93
                          • Instruction ID: 0093f9f673340a60752115da354e22f2e5807072404a167676b0d3663c19d43a
                          • Opcode Fuzzy Hash: 03bce68515b9d767fb44ef4151beda1e36e693f5189286deaa4d904197ef0f93
                          • Instruction Fuzzy Hash: DAD13DB2508304AFC714EBA4C982EBBB7ECAF98704F44491DF685D7191EB74DA44CB62
                          APIs
                          • FindFirstFileW.KERNEL32(?,?,74DE8FB0,?,00000000), ref: 00AF9663
                          • GetFileAttributesW.KERNEL32(?), ref: 00AF96A1
                          • SetFileAttributesW.KERNEL32(?,?), ref: 00AF96BB
                          • FindNextFileW.KERNEL32(00000000,?), ref: 00AF96D3
                          • FindClose.KERNEL32(00000000), ref: 00AF96DE
                          • FindFirstFileW.KERNEL32(*.*,?), ref: 00AF96FA
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00AF974A
                          • SetCurrentDirectoryW.KERNEL32(00B46B7C), ref: 00AF9768
                          • FindNextFileW.KERNEL32(00000000,00000010), ref: 00AF9772
                          • FindClose.KERNEL32(00000000), ref: 00AF977F
                          • FindClose.KERNEL32(00000000), ref: 00AF978F
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Find$File$Close$AttributesCurrentDirectoryFirstNext
                          • String ID: *.*
                          • API String ID: 1409584000-438819550
                          • Opcode ID: a9cfb5805ae896988455e6bd8094d7331c686cd179c2810adc18969c4a9f8894
                          • Instruction ID: 11d4a5826fd1e9724d2e095fe0442cc07d55f1f7bea7e66dc8dc90fcf03e5d77
                          • Opcode Fuzzy Hash: a9cfb5805ae896988455e6bd8094d7331c686cd179c2810adc18969c4a9f8894
                          • Instruction Fuzzy Hash: AB31A23254021D6BDB14AFF4EC49BEF7BAC9F09321F508195FA15E30A0DB74DE448A54
                          APIs
                          • FindFirstFileW.KERNEL32(?,?,74DE8FB0,?,00000000), ref: 00AF97BE
                          • FindNextFileW.KERNEL32(00000000,?), ref: 00AF9819
                          • FindClose.KERNEL32(00000000), ref: 00AF9824
                          • FindFirstFileW.KERNEL32(*.*,?), ref: 00AF9840
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00AF9890
                          • SetCurrentDirectoryW.KERNEL32(00B46B7C), ref: 00AF98AE
                          • FindNextFileW.KERNEL32(00000000,00000010), ref: 00AF98B8
                          • FindClose.KERNEL32(00000000), ref: 00AF98C5
                          • FindClose.KERNEL32(00000000), ref: 00AF98D5
                            • Part of subcall function 00AEDAE5: CreateFileW.KERNEL32(?,40000000,00000001,00000000,00000003,02000080,00000000), ref: 00AEDB00
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Find$File$Close$CurrentDirectoryFirstNext$Create
                          • String ID: *.*
                          • API String ID: 2640511053-438819550
                          • Opcode ID: 09ce8a1625d62c58f1ac1851d5b743f652b012de5517657bd785fa251ab5e530
                          • Instruction ID: 36ca15ffe86da62074de78293d6bbdf106d1f098afa0aef23a14294c0f6bc2d4
                          • Opcode Fuzzy Hash: 09ce8a1625d62c58f1ac1851d5b743f652b012de5517657bd785fa251ab5e530
                          • Instruction Fuzzy Hash: D831C33254021D6ADB14AFF4EC49BEF7BACDF06360F108195F954A31E0DB70DE848AA4
                          APIs
                            • Part of subcall function 00B0C998: CharUpperBuffW.USER32(?,?,?,?,?,?,?,00B0B6AE,?,?), ref: 00B0C9B5
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0C9F1
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0CA68
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0CA9E
                          • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 00B0BF3E
                          • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?,?,?), ref: 00B0BFA9
                          • RegCloseKey.ADVAPI32(00000000), ref: 00B0BFCD
                          • RegQueryValueExW.ADVAPI32(?,?,00000000,?,00000000,?), ref: 00B0C02C
                          • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,00000008), ref: 00B0C0E7
                          • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,?,?,00000000), ref: 00B0C154
                          • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,?,?,00000000), ref: 00B0C1E9
                          • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,00000000,?,?,?,00000000), ref: 00B0C23A
                          • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,?,?,00000000), ref: 00B0C2E3
                          • RegCloseKey.ADVAPI32(?,?,00000000), ref: 00B0C382
                          • RegCloseKey.ADVAPI32(00000000), ref: 00B0C38F
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: QueryValue$Close_wcslen$BuffCharConnectOpenRegistryUpper
                          • String ID:
                          • API String ID: 3102970594-0
                          • Opcode ID: 28947d4787c5738a90f9964365a1747e7b0ddb2bbd175626c73bb3500969f365
                          • Instruction ID: ad52027597cc51c446224256ad45da65a8f745b7090da2df40bf37fe4fabfe1b
                          • Opcode Fuzzy Hash: 28947d4787c5738a90f9964365a1747e7b0ddb2bbd175626c73bb3500969f365
                          • Instruction Fuzzy Hash: 9B025D716042009FD714DF28C995E2ABBE5EF89318F18C59DF84ADB2A2DB31EC45CB52
                          APIs
                          • GetLocalTime.KERNEL32(?), ref: 00AF8257
                          • SystemTimeToFileTime.KERNEL32(?,?), ref: 00AF8267
                          • LocalFileTimeToFileTime.KERNEL32(?,?), ref: 00AF8273
                          • GetCurrentDirectoryW.KERNEL32(00007FFF,?), ref: 00AF8310
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00AF8324
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00AF8356
                          • SetCurrentDirectoryW.KERNEL32(?,?,?,?,?), ref: 00AF838C
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00AF8395
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CurrentDirectoryTime$File$Local$System
                          • String ID: *.*
                          • API String ID: 1464919966-438819550
                          • Opcode ID: 6bcbbe268e0b1ce39d3d4e4b2a5395bfd85a6e0149ce47cab6c67746e537fb95
                          • Instruction ID: 32051b9cfd1a9c4e8bd9f59beef77782e6ad2a027ac8bacbc800ef5eb93e65ce
                          • Opcode Fuzzy Hash: 6bcbbe268e0b1ce39d3d4e4b2a5395bfd85a6e0149ce47cab6c67746e537fb95
                          • Instruction Fuzzy Hash: 57618BB25043099FCB10EF60C9409AFB7E8FF89714F04891EFA9987251DB35E945CB92
                          APIs
                            • Part of subcall function 00A83AA2: GetFullPathNameW.KERNEL32(?,00007FFF,?,00000000,?,?,00A83A97,?,?,00A82E7F,?,?,?,00000000), ref: 00A83AC2
                            • Part of subcall function 00AEE199: GetFileAttributesW.KERNEL32(?,00AECF95), ref: 00AEE19A
                          • FindFirstFileW.KERNEL32(?,?), ref: 00AED122
                          • DeleteFileW.KERNEL32(?,?,?,?,?,00000000,?,?,?), ref: 00AED1DD
                          • MoveFileW.KERNEL32(?,?), ref: 00AED1F0
                          • DeleteFileW.KERNEL32(?,?,?,?), ref: 00AED20D
                          • FindNextFileW.KERNEL32(00000000,00000010), ref: 00AED237
                            • Part of subcall function 00AED29C: CopyFileExW.KERNEL32(?,?,00000000,00000000,00000000,00000008,?,?,00AED21C,?,?), ref: 00AED2B2
                          • FindClose.KERNEL32(00000000,?,?,?), ref: 00AED253
                          • FindClose.KERNEL32(00000000), ref: 00AED264
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: File$Find$CloseDelete$AttributesCopyFirstFullMoveNameNextPath
                          • String ID: \*.*
                          • API String ID: 1946585618-1173974218
                          • Opcode ID: 19a1fbfb2723afd52e01d474c34abc81014f0d70c3c0f3f8052e5a1eaa492cb6
                          • Instruction ID: 773eb41713eccbf4402595b0baabc6cd8e261d1d8bdf2197a5bd629b8caa02ae
                          • Opcode Fuzzy Hash: 19a1fbfb2723afd52e01d474c34abc81014f0d70c3c0f3f8052e5a1eaa492cb6
                          • Instruction Fuzzy Hash: 0B615B3180514DABCF05FBE1CA929FEBBB5AF25300F648169E40277191EB31AF09DB61
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Clipboard$AllocCloseEmptyGlobalOpen
                          • String ID:
                          • API String ID: 1737998785-0
                          • Opcode ID: af9a3ef8ef8e53c79e328b08e274697bdcd5115abc236c349af198df0037c115
                          • Instruction ID: 79a95a6904572e620bdd06bbf713174e58427e41e2642bfe31d36e9f6eebb1a1
                          • Opcode Fuzzy Hash: af9a3ef8ef8e53c79e328b08e274697bdcd5115abc236c349af198df0037c115
                          • Instruction Fuzzy Hash: 4441BE35204611AFE320DF55E888B69BBE5FF44328F54C4A9F5558BA72CB35EC41CB90
                          APIs
                            • Part of subcall function 00AE16C3: LookupPrivilegeValueW.ADVAPI32(00000000,00000000,00000004), ref: 00AE170D
                            • Part of subcall function 00AE16C3: AdjustTokenPrivileges.ADVAPI32(?,00000000,00000000,?,00000000,?), ref: 00AE173A
                            • Part of subcall function 00AE16C3: GetLastError.KERNEL32 ref: 00AE174A
                          • ExitWindowsEx.USER32(?,00000000), ref: 00AEE932
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AdjustErrorExitLastLookupPrivilegePrivilegesTokenValueWindows
                          • String ID: $ $@$SeShutdownPrivilege
                          • API String ID: 2234035333-3163812486
                          • Opcode ID: 51cbaaf0018f5be85d6040b6eea9415b9a15a5306df5722d4c4e7233fc8c1ea1
                          • Instruction ID: 3b91874b001344c0658f943144be4fe9e4ff5367617d301409d7b6b0e21bdedd
                          • Opcode Fuzzy Hash: 51cbaaf0018f5be85d6040b6eea9415b9a15a5306df5722d4c4e7233fc8c1ea1
                          • Instruction Fuzzy Hash: E601F972650251ABEB54A7B69C8AFFFB2EC9718750F154422FC13E71D3EAB09C4481A4
                          APIs
                          • socket.WSOCK32(00000002,00000001,00000006,?,00000002,00000000), ref: 00B01276
                          • WSAGetLastError.WSOCK32 ref: 00B01283
                          • bind.WSOCK32(00000000,?,00000010), ref: 00B012BA
                          • WSAGetLastError.WSOCK32 ref: 00B012C5
                          • closesocket.WSOCK32(00000000), ref: 00B012F4
                          • listen.WSOCK32(00000000,00000005), ref: 00B01303
                          • WSAGetLastError.WSOCK32 ref: 00B0130D
                          • closesocket.WSOCK32(00000000), ref: 00B0133C
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorLast$closesocket$bindlistensocket
                          • String ID:
                          • API String ID: 540024437-0
                          • Opcode ID: ba38ec928b4b33a0d8c8afdc366d59270b205a32d2068a2c6bf2ba908bc8e29d
                          • Instruction ID: a1aebc5216adb2995f8d11420cccc0a5127f33027ed4e272f202f5520e213c01
                          • Opcode Fuzzy Hash: ba38ec928b4b33a0d8c8afdc366d59270b205a32d2068a2c6bf2ba908bc8e29d
                          • Instruction Fuzzy Hash: 2D416D71600100AFD714DF68C588B69BFE5EF46318F588598E8569F2D2C771ED81CBA1
                          APIs
                            • Part of subcall function 00A83AA2: GetFullPathNameW.KERNEL32(?,00007FFF,?,00000000,?,?,00A83A97,?,?,00A82E7F,?,?,?,00000000), ref: 00A83AC2
                            • Part of subcall function 00AEE199: GetFileAttributesW.KERNEL32(?,00AECF95), ref: 00AEE19A
                          • FindFirstFileW.KERNEL32(?,?), ref: 00AED420
                          • DeleteFileW.KERNEL32(?,?,?,?), ref: 00AED470
                          • FindNextFileW.KERNEL32(00000000,00000010), ref: 00AED481
                          • FindClose.KERNEL32(00000000), ref: 00AED498
                          • FindClose.KERNEL32(00000000), ref: 00AED4A1
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FileFind$Close$AttributesDeleteFirstFullNameNextPath
                          • String ID: \*.*
                          • API String ID: 2649000838-1173974218
                          • Opcode ID: 67c5d8d39828dd213384b6cc03f0e89c868a3327b08bacc3335e4eb6ae2d5ccd
                          • Instruction ID: 6389eb92870ed2a4460581f46f2fb2ae23b88ff0ab0923a6cc9d7d0600328c36
                          • Opcode Fuzzy Hash: 67c5d8d39828dd213384b6cc03f0e89c868a3327b08bacc3335e4eb6ae2d5ccd
                          • Instruction Fuzzy Hash: 683160710083859BC305FF64D9958AFB7E8AEA5314F844A1EF4D593191EB30AA09D763
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: __floor_pentium4
                          • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                          • API String ID: 4168288129-2761157908
                          • Opcode ID: 51c0e5b5be58e30553588eb440b76362d54d8e536541d8e4bad2bbb0069bde29
                          • Instruction ID: cd4ce8154468fbca8f16f78984a23dbf18b6545926ebb2fced6c69dc5689510d
                          • Opcode Fuzzy Hash: 51c0e5b5be58e30553588eb440b76362d54d8e536541d8e4bad2bbb0069bde29
                          • Instruction Fuzzy Hash: 07C23C71E046288FDB25CF68DD407EAB7B9EB49305F1841EAD84DE7242E775AE818F40
                          APIs
                          • _wcslen.LIBCMT ref: 00AF64DC
                          • CoInitialize.OLE32(00000000), ref: 00AF6639
                          • CoCreateInstance.OLE32(00B1FCF8,00000000,00000001,00B1FB68,?), ref: 00AF6650
                          • CoUninitialize.OLE32 ref: 00AF68D4
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CreateInitializeInstanceUninitialize_wcslen
                          • String ID: .lnk
                          • API String ID: 886957087-24824748
                          • Opcode ID: a0266997ead616ea7ab75e835d9747c8b8c722686cc185b6dbe9e17d3c395cdf
                          • Instruction ID: f61de2b5f63e1271355a7624d815bde2df4a44444e55f8140a4a2555e3adea20
                          • Opcode Fuzzy Hash: a0266997ead616ea7ab75e835d9747c8b8c722686cc185b6dbe9e17d3c395cdf
                          • Instruction Fuzzy Hash: DAD16971508305AFD304EF64C981A6BB7E8FF98704F14496DF5959B2A1EB30ED09CBA2
                          APIs
                          • GetForegroundWindow.USER32(?,?,00000000), ref: 00B022E8
                            • Part of subcall function 00AFE4EC: GetWindowRect.USER32(?,?), ref: 00AFE504
                          • GetDesktopWindow.USER32 ref: 00B02312
                          • GetWindowRect.USER32(00000000), ref: 00B02319
                          • mouse_event.USER32(00008001,?,?,00000002,00000002), ref: 00B02355
                          • GetCursorPos.USER32(?), ref: 00B02381
                          • mouse_event.USER32(00008001,?,?,00000000,00000000), ref: 00B023DF
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Rectmouse_event$CursorDesktopForeground
                          • String ID:
                          • API String ID: 2387181109-0
                          • Opcode ID: 1765d3caa64d80a1587d510bab4b29c8a205e170d1e0a899996c76d8e8ab8c97
                          • Instruction ID: 88da68813256f7e9850c19172f89eb056ee1ad26fa6af38e578ecc8abdc07233
                          • Opcode Fuzzy Hash: 1765d3caa64d80a1587d510bab4b29c8a205e170d1e0a899996c76d8e8ab8c97
                          • Instruction Fuzzy Hash: 3931E072504315AFCB20DF54D849B9BBBEAFF84310F00491AF98997191DB34EA08CB96
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • FindFirstFileW.KERNEL32(00000001,?,*.*,?,?,00000000,00000000), ref: 00AF9B78
                          • FindClose.KERNEL32(00000000,?,00000000,00000000), ref: 00AF9C8B
                            • Part of subcall function 00AF3874: GetInputState.USER32 ref: 00AF38CB
                            • Part of subcall function 00AF3874: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00AF3966
                          • Sleep.KERNEL32(0000000A,?,00000000,00000000), ref: 00AF9BA8
                          • FindNextFileW.KERNEL32(?,?,?,00000000,00000000), ref: 00AF9C75
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Find$File$CloseFirstInputMessageNextPeekSleepState_wcslen
                          • String ID: *.*
                          • API String ID: 1972594611-438819550
                          • Opcode ID: 7f77bf3ed768aa6d69fb27b30746c5032e3b44c374662ba4db3bc5dc9ed82144
                          • Instruction ID: cc1a6a485f660a2999425aa291ef1bb4c73862f42a523b1f08e711134dcda93e
                          • Opcode Fuzzy Hash: 7f77bf3ed768aa6d69fb27b30746c5032e3b44c374662ba4db3bc5dc9ed82144
                          • Instruction Fuzzy Hash: 3241487194420EAFCF54EFA4C985BEEBBB8EF05310F244056F905A2191EB309E85CBA1
                          APIs
                            • Part of subcall function 00A99BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 00A99BB2
                          • DefDlgProcW.USER32(?,?,?,?,?), ref: 00A99A4E
                          • GetSysColor.USER32(0000000F), ref: 00A99B23
                          • SetBkColor.GDI32(?,00000000), ref: 00A99B36
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Color$LongProcWindow
                          • String ID:
                          • API String ID: 3131106179-0
                          • Opcode ID: 0294db8c13c6a8bb74973c56e25de81460fc95eeeb2703865debb6d2be8b7817
                          • Instruction ID: 4851ccfee9d54217e2d49a0f5b77b3d55825c50a0c5994b336fdbc43a106b223
                          • Opcode Fuzzy Hash: 0294db8c13c6a8bb74973c56e25de81460fc95eeeb2703865debb6d2be8b7817
                          • Instruction Fuzzy Hash: 5FA1E770308544BFEF299B2C8C99FBF36EDEB46380B14454EF503D6A91EA259D42D272
                          APIs
                            • Part of subcall function 00B0304E: inet_addr.WSOCK32(?,?,?,?,?,00000000), ref: 00B0307A
                            • Part of subcall function 00B0304E: _wcslen.LIBCMT ref: 00B0309B
                          • socket.WSOCK32(00000002,00000002,00000011,?,?,00000000), ref: 00B0185D
                          • WSAGetLastError.WSOCK32 ref: 00B01884
                          • bind.WSOCK32(00000000,?,00000010), ref: 00B018DB
                          • WSAGetLastError.WSOCK32 ref: 00B018E6
                          • closesocket.WSOCK32(00000000), ref: 00B01915
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorLast$_wcslenbindclosesocketinet_addrsocket
                          • String ID:
                          • API String ID: 1601658205-0
                          • Opcode ID: 1ab6ed3fe6fa37056753b71dae8808e3ab93f1cf0ffabd7f083431573ace8e61
                          • Instruction ID: ed31004820fa7e4204fd8e7235f5b45ac07afa22149476e45ddd7bea7461ec5e
                          • Opcode Fuzzy Hash: 1ab6ed3fe6fa37056753b71dae8808e3ab93f1cf0ffabd7f083431573ace8e61
                          • Instruction Fuzzy Hash: A751D471A002109FEB14AF28C986F6A7BE5EB44718F54C498F9065F3D3D771AD41CBA1
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$EnabledForegroundIconicVisibleZoomed
                          • String ID:
                          • API String ID: 292994002-0
                          • Opcode ID: 57d3bb5c4de6186ae37357a9f86f093586edfbbd7d550940bb5f7d024aa240c7
                          • Instruction ID: 4ef54ba1977b7beb262436abf541f01f71dc7f6b56f6c839ce2bb59516dba315
                          • Opcode Fuzzy Hash: 57d3bb5c4de6186ae37357a9f86f093586edfbbd7d550940bb5f7d024aa240c7
                          • Instruction Fuzzy Hash: 1221A3317802115FD7209F2ED884BAA7BE5EF95324B9984A8E946CF351CB71DC82CBD0
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID: ERCP$VUUU$VUUU$VUUU$VUUU
                          • API String ID: 0-1546025612
                          • Opcode ID: a023ddc79a74144d865e5eae7ae11a1cc9a7547bd328cd0132b88779c6d9ec58
                          • Instruction ID: 83abbdf3cc227138b27a6a861a5d0fb10c6efc6637a94c267baddb7105d16d7c
                          • Opcode Fuzzy Hash: a023ddc79a74144d865e5eae7ae11a1cc9a7547bd328cd0132b88779c6d9ec58
                          • Instruction Fuzzy Hash: 82A27171E0061ACBDF24DF58C940BEEB7B1BF54310F6581AAE815AB285EB749D81CF90
                          APIs
                          • GetKeyboardState.USER32(?,00000001,00000040,00000000), ref: 00AEAAAC
                          • SetKeyboardState.USER32(00000080), ref: 00AEAAC8
                          • PostMessageW.USER32(?,00000102,00000001,00000001), ref: 00AEAB36
                          • SendInput.USER32(00000001,?,0000001C,00000001,00000040,00000000), ref: 00AEAB88
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: KeyboardState$InputMessagePostSend
                          • String ID:
                          • API String ID: 432972143-0
                          • Opcode ID: a4e66b3ef7f87116fa97e82dbdb61a17f41e5a53f520163d1668c568f4c0e29d
                          • Instruction ID: f0af9e119849d5cca53902eab971261c663e93c7afcc52f709b4be8123edd5f0
                          • Opcode Fuzzy Hash: a4e66b3ef7f87116fa97e82dbdb61a17f41e5a53f520163d1668c568f4c0e29d
                          • Instruction Fuzzy Hash: 72310870A80388AEFF35CB66CC05BFA7BA6EB64310F04821AF581961D1D775AD85C762
                          APIs
                          • _free.LIBCMT ref: 00ABBB7F
                            • Part of subcall function 00AB29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000), ref: 00AB29DE
                            • Part of subcall function 00AB29C8: GetLastError.KERNEL32(00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000,00000000), ref: 00AB29F0
                          • GetTimeZoneInformation.KERNEL32 ref: 00ABBB91
                          • WideCharToMultiByte.KERNEL32(00000000,?,00B5121C,000000FF,?,0000003F,?,?), ref: 00ABBC09
                          • WideCharToMultiByte.KERNEL32(00000000,?,00B51270,000000FF,?,0000003F,?,?,?,00B5121C,000000FF,?,0000003F,?,?), ref: 00ABBC36
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ByteCharMultiWide$ErrorFreeHeapInformationLastTimeZone_free
                          • String ID:
                          • API String ID: 806657224-0
                          • Opcode ID: 4ff3f41808ef8472b43faa447929b95ec9ef9c1d830394cbdf2d055626078925
                          • Instruction ID: 4b0efcfdc5a201d768f9cecd981520641478f27daf93c7fe1680cde98a1cbace
                          • Opcode Fuzzy Hash: 4ff3f41808ef8472b43faa447929b95ec9ef9c1d830394cbdf2d055626078925
                          • Instruction Fuzzy Hash: 3E31C070944205EFCB11DF68CC80AADBFBCBF46311B144AAAE014DB2A2DB719E40CB60
                          APIs
                          • InternetReadFile.WININET(?,?,00000400,?), ref: 00AFCE89
                          • GetLastError.KERNEL32(?,00000000), ref: 00AFCEEA
                          • SetEvent.KERNEL32(?,?,00000000), ref: 00AFCEFE
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorEventFileInternetLastRead
                          • String ID:
                          • API String ID: 234945975-0
                          • Opcode ID: e2c9fbc0d6ce9420b7f98fe1bacd4bc78ad7c46bbfccbe5bc0454bac0ed2af19
                          • Instruction ID: d2b0068455f9208002f408f2bc4f67e4db9802e09096e65faa4c298778e18467
                          • Opcode Fuzzy Hash: e2c9fbc0d6ce9420b7f98fe1bacd4bc78ad7c46bbfccbe5bc0454bac0ed2af19
                          • Instruction Fuzzy Hash: 32215E7154070DABD720DFA6DA44BA6BBF8EF50364F10841AF646D3151EB74EE048B54
                          APIs
                          • lstrlenW.KERNEL32(?,?,?,00000000), ref: 00AE82AA
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: lstrlen
                          • String ID: ($|
                          • API String ID: 1659193697-1631851259
                          • Opcode ID: b0b0b169828a664d3c0d25298dd80fae242ce2571c2a6197ca92a2754aa57427
                          • Instruction ID: e82fe329077f8f6dcfc38cceaaa592bd125d409cd3bb082516382997063adf51
                          • Opcode Fuzzy Hash: b0b0b169828a664d3c0d25298dd80fae242ce2571c2a6197ca92a2754aa57427
                          • Instruction Fuzzy Hash: F0323575A007469FCB28CF5AC481A6AB7F0FF48710B15C56EE49ADB3A1EB74E941CB40
                          APIs
                          • FindFirstFileW.KERNEL32(?,?), ref: 00AF5CC1
                          • FindNextFileW.KERNEL32(00000000,?), ref: 00AF5D17
                          • FindClose.KERNEL32(?), ref: 00AF5D5F
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Find$File$CloseFirstNext
                          • String ID:
                          • API String ID: 3541575487-0
                          • Opcode ID: 527ecaeca86188e0b75e909112e5344ffc7d790f704110c2721b64397c290ffa
                          • Instruction ID: 5df8178655b7a0fc9449b36c3e5a66f3839fa7dc4fae917aa3de97bc884d2d42
                          • Opcode Fuzzy Hash: 527ecaeca86188e0b75e909112e5344ffc7d790f704110c2721b64397c290ffa
                          • Instruction Fuzzy Hash: 1551AC34A046059FC714DF68C484AA6B7E4FF0A324F14855DFA9A8B3A1DB30ED04CF91
                          APIs
                          • IsDebuggerPresent.KERNEL32 ref: 00AB271A
                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00AB2724
                          • UnhandledExceptionFilter.KERNEL32(?), ref: 00AB2731
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ExceptionFilterUnhandled$DebuggerPresent
                          • String ID:
                          • API String ID: 3906539128-0
                          • Opcode ID: c8ec7c3abe1992cca2fa021a7a76b6e0a8bc7bf99e76673835b057dc4c9fcc2a
                          • Instruction ID: 4f33a31608c5fb75d33d16ecadde4b2f2727c541a0e9b8a0fbe8029d40ff41c5
                          • Opcode Fuzzy Hash: c8ec7c3abe1992cca2fa021a7a76b6e0a8bc7bf99e76673835b057dc4c9fcc2a
                          • Instruction Fuzzy Hash: 3D31D5749412189BCB21DF68DD88BDDBBB8AF08310F5041EAE41CA72A1EB309F818F44
                          APIs
                          • SetErrorMode.KERNEL32(00000001), ref: 00AF51DA
                          • GetDiskFreeSpaceExW.KERNEL32(?,?,?,?), ref: 00AF5238
                          • SetErrorMode.KERNEL32(00000000), ref: 00AF52A1
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorMode$DiskFreeSpace
                          • String ID:
                          • API String ID: 1682464887-0
                          • Opcode ID: a1bde0c2520100abf49debae49f31a890a2c5fd11a78ef0024e6bb699dedfc3f
                          • Instruction ID: 5d0bd1ca2b7b7bab36a5adf33afe96e1a9e82b29c00c8fac127b04531b2c8709
                          • Opcode Fuzzy Hash: a1bde0c2520100abf49debae49f31a890a2c5fd11a78ef0024e6bb699dedfc3f
                          • Instruction Fuzzy Hash: 2D314F75A00518DFDB00DF94D884EEDBBB4FF49314F048099E905AB352DB31E855CBA0
                          APIs
                            • Part of subcall function 00A9FDDB: __CxxThrowException@8.LIBVCRUNTIME ref: 00AA0668
                            • Part of subcall function 00A9FDDB: __CxxThrowException@8.LIBVCRUNTIME ref: 00AA0685
                          • LookupPrivilegeValueW.ADVAPI32(00000000,00000000,00000004), ref: 00AE170D
                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,00000000,?,00000000,?), ref: 00AE173A
                          • GetLastError.KERNEL32 ref: 00AE174A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Exception@8Throw$AdjustErrorLastLookupPrivilegePrivilegesTokenValue
                          • String ID:
                          • API String ID: 577356006-0
                          • Opcode ID: 0a44bc970848e3bd27a9b75e65008f08b8360b5d62df1e3984e81f81d6b22ab0
                          • Instruction ID: 7d224c814fc1e6a073da4e7e16bdc074093fefbe7f7b01424c1f9c795938d91e
                          • Opcode Fuzzy Hash: 0a44bc970848e3bd27a9b75e65008f08b8360b5d62df1e3984e81f81d6b22ab0
                          • Instruction Fuzzy Hash: 3B11CEB2510304AFD718AF54EC86DAABBF9EB08B14B20852EE05697641EB70BC41CA24
                          APIs
                          • CreateFileW.KERNEL32(?,00000080,00000003,00000000,00000003,00000080,00000000), ref: 00AED608
                          • DeviceIoControl.KERNEL32(00000000,002D1400,?,0000000C,?,00000028,?,00000000), ref: 00AED645
                          • CloseHandle.KERNEL32(?,?,00000080,00000003,00000000,00000003,00000080,00000000), ref: 00AED650
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CloseControlCreateDeviceFileHandle
                          • String ID:
                          • API String ID: 33631002-0
                          • Opcode ID: 295a834c4fb48881058d8742ed6f72e6316353c022275d871a4485b1ac2d7c80
                          • Instruction ID: c340cceead0974c0ff8891070722e609ab7d8a4acb19cf3434a6924f8e0a887f
                          • Opcode Fuzzy Hash: 295a834c4fb48881058d8742ed6f72e6316353c022275d871a4485b1ac2d7c80
                          • Instruction Fuzzy Hash: 13113C75E45228BBDB108F95AC45FEFBFBCEB45B50F108115F914E7290D6704A058BA1
                          APIs
                          • AllocateAndInitializeSid.ADVAPI32(?,00000002,00000020,00000220,00000000,00000000,00000000,00000000,00000000,00000000,?,?), ref: 00AE168C
                          • CheckTokenMembership.ADVAPI32(00000000,?,?), ref: 00AE16A1
                          • FreeSid.ADVAPI32(?), ref: 00AE16B1
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AllocateCheckFreeInitializeMembershipToken
                          • String ID:
                          • API String ID: 3429775523-0
                          • Opcode ID: 55e50b9a131c8b7de9fcc8df639eb9d6386ea525acebe73111ad181170e71f64
                          • Instruction ID: 8aa8dde40552bf11f4b27a7b9f3a7a757650272b79daf6b338e387d9f20e2156
                          • Opcode Fuzzy Hash: 55e50b9a131c8b7de9fcc8df639eb9d6386ea525acebe73111ad181170e71f64
                          • Instruction Fuzzy Hash: EDF0F471990309FBDB00DFE49C89EAEBBBCEB08604F508565E501E2181E774AA448A50
                          APIs
                          • GetUserNameW.ADVAPI32(?,?), ref: 00ADD28C
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: NameUser
                          • String ID: X64
                          • API String ID: 2645101109-893830106
                          • Opcode ID: 9b8c01fb8d14535b421e9fbc08af6a3fedd016068bd12aad8b884ec8403ca338
                          • Instruction ID: 88e7a58779805b86ea4b82cd9bf63e583fbd2eb44ba1f488c513cbdfe351344f
                          • Opcode Fuzzy Hash: 9b8c01fb8d14535b421e9fbc08af6a3fedd016068bd12aad8b884ec8403ca338
                          • Instruction Fuzzy Hash: 0FD0CAB480122DEACF94CBA0EC88DDAB7BCBB08345F204292F146A2100DB3096888F20
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 2fbdbeface8d474e65e3d830227d731b015bc4fe83c76ff0107a9da6199ccf29
                          • Instruction ID: f0c1a4aec0f960fa73f5699264b99f5ea929de64bbb3b2cf06fbe6dddf5bfdb7
                          • Opcode Fuzzy Hash: 2fbdbeface8d474e65e3d830227d731b015bc4fe83c76ff0107a9da6199ccf29
                          • Instruction Fuzzy Hash: A3021E71E002199FEF24CFA9C9806ADFBF1EF49324F258169D919E7384D731AE418B94
                          APIs
                          • FindFirstFileW.KERNEL32(?,?), ref: 00AF6918
                          • FindClose.KERNEL32(00000000), ref: 00AF6961
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Find$CloseFileFirst
                          • String ID:
                          • API String ID: 2295610775-0
                          • Opcode ID: a4e76a629afdb182037d4414f731fb9629bd4c09b121a4b2678116809cf4d58c
                          • Instruction ID: 63e788d81139e1af7025120fbba72a8b35b15c6a39bec8c93a09892d9db5daef
                          • Opcode Fuzzy Hash: a4e76a629afdb182037d4414f731fb9629bd4c09b121a4b2678116809cf4d58c
                          • Instruction Fuzzy Hash: 04118E316042049FD710DF69D4C4A26BBE5FF85328F54C699F5698F6A2CB70EC05CB91
                          APIs
                          • GetLastError.KERNEL32(00000000,?,00000FFF,00000000,?,?,?,00B04891,?,?,00000035,?), ref: 00AF37E4
                          • FormatMessageW.KERNEL32(00001000,00000000,?,00000000,?,00000FFF,00000000,?,?,?,00B04891,?,?,00000035,?), ref: 00AF37F4
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorFormatLastMessage
                          • String ID:
                          • API String ID: 3479602957-0
                          • Opcode ID: 7cbaa96a44db0fdd4a4948804079b96c27f3ed4bfb8234607a58e278da4ed3a3
                          • Instruction ID: 03bf59dc581deae2dfd1d9fcb77b94dbb49adb7a5fe4a611bb915d3bfccb2040
                          • Opcode Fuzzy Hash: 7cbaa96a44db0fdd4a4948804079b96c27f3ed4bfb8234607a58e278da4ed3a3
                          • Instruction Fuzzy Hash: BFF0E5B17042282AEB2067A69D4DFEB7AAEEFC5761F000165F609D3281D9B09944C7F0
                          APIs
                          • SendInput.USER32(00000001,?,0000001C,?,?,00000002), ref: 00AEB25D
                          • keybd_event.USER32(?,75C0C0D0,?,00000000), ref: 00AEB270
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: InputSendkeybd_event
                          • String ID:
                          • API String ID: 3536248340-0
                          • Opcode ID: 0e5dc09109001a7520f32620cc6b3709cea88dcd9a5467bbdb60d0a555c2a2e1
                          • Instruction ID: 61319686cab56b46569ad4ba33ad315c86924ce7a658fcaf326dad5630381ccb
                          • Opcode Fuzzy Hash: 0e5dc09109001a7520f32620cc6b3709cea88dcd9a5467bbdb60d0a555c2a2e1
                          • Instruction Fuzzy Hash: E4F01D7185428DABDB059FA1C806BEE7FB4FF04305F008009F965A6191C77986119FA4
                          APIs
                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000,?,00AE11FC), ref: 00AE10D4
                          • CloseHandle.KERNEL32(?,?,00AE11FC), ref: 00AE10E9
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AdjustCloseHandlePrivilegesToken
                          • String ID:
                          • API String ID: 81990902-0
                          • Opcode ID: 398573e59dbfe708dc32079ae5a071a9b000df335066ce30ce7fc8f2f183ff53
                          • Instruction ID: 9081938c69fe2dd503b008352a19035cc8bd0b3bfba0a271510cfe69b4128066
                          • Opcode Fuzzy Hash: 398573e59dbfe708dc32079ae5a071a9b000df335066ce30ce7fc8f2f183ff53
                          • Instruction Fuzzy Hash: B7E0BF72154610AFEB252B51FD09EB77BE9EB04310B24C82DF5A5814B1DB726C90DB54
                          Strings
                          • Variable is not of type 'Object'., xrefs: 00AD0C40
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID: Variable is not of type 'Object'.
                          • API String ID: 0-1840281001
                          • Opcode ID: 734f1855d61c729895fc9b037d5fdda8a5b8daa20527d10a6e3d7f6c64f107e5
                          • Instruction ID: 2421e9ef46bf31b118aef2a658d247f8d2e2932c4e9c995e38817fc0536a48e2
                          • Opcode Fuzzy Hash: 734f1855d61c729895fc9b037d5fdda8a5b8daa20527d10a6e3d7f6c64f107e5
                          • Instruction Fuzzy Hash: 75328870900218DFDF14EF94D985BEDBBB5BF05318F14806AE806AB292DB75AE45CF60
                          APIs
                          • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,00AB6766,?,?,00000008,?,?,00ABFEFE,00000000), ref: 00AB6998
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ExceptionRaise
                          • String ID:
                          • API String ID: 3997070919-0
                          • Opcode ID: 12bef984b4ab182706006702ab22c3bbce86294f813a5abd93abe0d2210101d3
                          • Instruction ID: 160671e1170b19a4320203e91a1d1b925265550ec699a9206cf4fae5e03816e5
                          • Opcode Fuzzy Hash: 12bef984b4ab182706006702ab22c3bbce86294f813a5abd93abe0d2210101d3
                          • Instruction Fuzzy Hash: 53B13C726106089FDB15CF28C486BA57BF4FF45364F29865CE899CF2A2C739E991CB40
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID: 0-3916222277
                          • Opcode ID: b1cba6e7569677588b1b643648cc5afc5b5b88ee3987ca758300f807d47eef20
                          • Instruction ID: 0631869903f56784e7b3c6475d3f37f94b91e250edfb82566ddbdb6536389d65
                          • Opcode Fuzzy Hash: b1cba6e7569677588b1b643648cc5afc5b5b88ee3987ca758300f807d47eef20
                          • Instruction Fuzzy Hash: 58126D75A10229DBCF24CF58D9806EEB7F5FF48710F14819AE809EB255DB349A81DFA0
                          APIs
                          • BlockInput.USER32(00000001), ref: 00AFEABD
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: BlockInput
                          • String ID:
                          • API String ID: 3456056419-0
                          • Opcode ID: 328a42b25f79e97a3c9d6f6bac3ee599497e31db378295745a474670c037834a
                          • Instruction ID: fda4c20d486e2f09378efa38786bf5c0ab2dde09f5a40b0022d0443a8d566bc7
                          • Opcode Fuzzy Hash: 328a42b25f79e97a3c9d6f6bac3ee599497e31db378295745a474670c037834a
                          • Instruction Fuzzy Hash: 71E01A312102049FD710EF99D804E9ABBE9AF987A0F408426FD4AC7261DB70A8408BA0
                          APIs
                          • SetUnhandledExceptionFilter.KERNEL32(Function_000209E1,00AA03EE), ref: 00AA09DA
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ExceptionFilterUnhandled
                          • String ID:
                          • API String ID: 3192549508-0
                          • Opcode ID: 4dc7be7a3a4dabee086e78310ec363755923758dc53211666dcb6ccf1e263271
                          • Instruction ID: 7fe7c3d36912501d4df602322a8e1ab339a458c759d7d57127d6181e343f5337
                          • Opcode Fuzzy Hash: 4dc7be7a3a4dabee086e78310ec363755923758dc53211666dcb6ccf1e263271
                          • Instruction Fuzzy Hash:
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID: 0
                          • API String ID: 0-4108050209
                          • Opcode ID: 9084b4e029052128895840c3c28e948f6724b1d83b91d22a18243ac96ad56844
                          • Instruction ID: 36071676543707f8f74878427c837d6691ef61e1d017ca905ae6f8476c02bf0f
                          • Opcode Fuzzy Hash: 9084b4e029052128895840c3c28e948f6724b1d83b91d22a18243ac96ad56844
                          • Instruction Fuzzy Hash: 5551557260C7056BDB3887688D5EBBF63A99B0B340F18051BD886D72C2CB1DDE85D356
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 95ee080141789b6b802c942246ef3edc073ae1d853912c57b0a76b69b3789f3e
                          • Instruction ID: 2cccfcec255029e85f56d26afc1bac7bf817e3db9d046ed82912cf5df2423e46
                          • Opcode Fuzzy Hash: 95ee080141789b6b802c942246ef3edc073ae1d853912c57b0a76b69b3789f3e
                          • Instruction Fuzzy Hash: AB320022D29F414DD7339634C822339A65DAFB73C5F15D737E81AB69AAEF69C4834100
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 61a63bb8b4adcfff60ba35267b64d96007e5cab59dd6070381b01fa1f638f80b
                          • Instruction ID: f7302250b88250565732704f09020a26930520a079ddf4bef231cee01807d756
                          • Opcode Fuzzy Hash: 61a63bb8b4adcfff60ba35267b64d96007e5cab59dd6070381b01fa1f638f80b
                          • Instruction Fuzzy Hash: 9432E131B401168BDF28CB69C4946BD7BF2EB45330FA8856BD49B9B392D634DE81DB40
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 2c6b74540e2e6fb6d10f3ba60de6a81a6a968f5993e0f5a12b28695176caf906
                          • Instruction ID: 1f513b970b14c9cefb652aacb93709e7d4488baed12615294f9b45d008960ba5
                          • Opcode Fuzzy Hash: 2c6b74540e2e6fb6d10f3ba60de6a81a6a968f5993e0f5a12b28695176caf906
                          • Instruction Fuzzy Hash: BF228F70E046099FDF14DFA5C981BAEB7F6FF44300F244529E816AB291EB35E951CB50
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: cf3884660c1fc7da1ffe71c068612c49bddbac38417b6175299b2def69fdc296
                          • Instruction ID: 51b4c00f11c00933c3ae81e48db03469c54e59f413f57b477c2b2788b431d99b
                          • Opcode Fuzzy Hash: cf3884660c1fc7da1ffe71c068612c49bddbac38417b6175299b2def69fdc296
                          • Instruction Fuzzy Hash: F70280B1A0020AEFDF04DF54D981BAEB7F1FF44340F158169E816DB291EB31AA21CB95
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: d9a741f98128e3f170f3c25c4e2ad1c575ff62b1df76b115259c6a460a5fe445
                          • Instruction ID: a93be53529e9004efe11b325dd427d76790308967ac044447f059c02d66dfd55
                          • Opcode Fuzzy Hash: d9a741f98128e3f170f3c25c4e2ad1c575ff62b1df76b115259c6a460a5fe445
                          • Instruction Fuzzy Hash: DFB1F220D2AF414DD32396398871336B69CAFBB6D5F91D71BFC2675D22EF2686834140
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 93657a121f16255c59120ad0d08fdbba6372c273009ad596b4ecdf6e8f3c6909
                          • Instruction ID: 4e36eb484c560cbb63633f516119c626051bcc5d79c30b1d7cb7cb93eedef793
                          • Opcode Fuzzy Hash: 93657a121f16255c59120ad0d08fdbba6372c273009ad596b4ecdf6e8f3c6909
                          • Instruction Fuzzy Hash: 569153726080A35ADB29473A857407EFFE15A933B2B1A079ED4F2CB1C5FF249964D620
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 05e0b846b00456d0f1e87463b9d189974beed2fe63262d4392584e128a114ea2
                          • Instruction ID: 5e829aecc28e684111fe55ee5fd4f9fcfc46f005b644cf1a9b16d502cac15660
                          • Opcode Fuzzy Hash: 05e0b846b00456d0f1e87463b9d189974beed2fe63262d4392584e128a114ea2
                          • Instruction Fuzzy Hash: EF912F722090A34EDB69473D857453EFFE15A933A171A079EE4F2CB1C5EF248964E720
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 40101273f58913c3cb3bc7eb54df01d47b4121c3e67d19f11ec2cb23d33ea445
                          • Instruction ID: 96d52092c10e8c1ab45088d8743351ec65cf85cf093652d2eb3d7e33c3889cdc
                          • Opcode Fuzzy Hash: 40101273f58913c3cb3bc7eb54df01d47b4121c3e67d19f11ec2cb23d33ea445
                          • Instruction Fuzzy Hash: 549130722090A35EDB69477A857403EFFF15A933A2B1A079ED4F2CB1C1FF248965D620
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: ebf312025fd685482e07da92bcadefc8b07612218551987a7ef8ca380c887fb1
                          • Instruction ID: 27f845dc10b4906fc426ee2810f3034d68a0585c799b5820c95135d1b2c08dd0
                          • Opcode Fuzzy Hash: ebf312025fd685482e07da92bcadefc8b07612218551987a7ef8ca380c887fb1
                          • Instruction Fuzzy Hash: F96137B1708709A6DE349B288D95BBF63A8DF43750F24091AE843DB2C1DB159E42C775
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 0de080297a5409d978f6569f19a908afe248f3a4ecbd8095941aeb785e659bbe
                          • Instruction ID: 447c52a392f2bf35b438ffcdc35c8f3f7e386d4dfbedc3361b3748c028e9deaf
                          • Opcode Fuzzy Hash: 0de080297a5409d978f6569f19a908afe248f3a4ecbd8095941aeb785e659bbe
                          • Instruction Fuzzy Hash: A661997160870967DF388B288DA5BBF63A8EF43704F14095AE943DB2C1EB16ED428B55
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 70da388f96bbbf26b230a155b4728740b34f0d100ea60ab2bbadb9d7d0befbf0
                          • Instruction ID: f3064c1ef404cf326a88a49b6cc334b914c53b16a87077993816bddc45391849
                          • Opcode Fuzzy Hash: 70da388f96bbbf26b230a155b4728740b34f0d100ea60ab2bbadb9d7d0befbf0
                          • Instruction Fuzzy Hash: 848174726090A31DDB6D473A857443EFFE15A933A1B1A079DD4F2CB1C1EF24C954E620
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 258c31b98c21070db14766f0e04f80bb9f7ca5d19298dc7472ee0d830283b858
                          • Instruction ID: 0b40acc8305f8a9403fc51106febde4f8529244de17a77a5ac17b760e15b7156
                          • Opcode Fuzzy Hash: 258c31b98c21070db14766f0e04f80bb9f7ca5d19298dc7472ee0d830283b858
                          • Instruction Fuzzy Hash: 75512A9985FBDA1FDB179734886A198FFB0AC1726174887CFD8825E8CBD381041AC75B
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 284c4cdcf42df3814828f3ca44ad4ee68e879d544a6254c94109ab6f711dac70
                          • Instruction ID: ff8ae548ba247c5f1dbd8e70ac8d45b9f1502eab957b2bb6343cb0f9cd3f8453
                          • Opcode Fuzzy Hash: 284c4cdcf42df3814828f3ca44ad4ee68e879d544a6254c94109ab6f711dac70
                          • Instruction Fuzzy Hash: B521A5326216158BDB28CF79C82277A73E5A764311F15866EE4A7C37D0DE39AD04CB80
                          APIs
                          • DeleteObject.GDI32(00000000), ref: 00B02B30
                          • DeleteObject.GDI32(00000000), ref: 00B02B43
                          • DestroyWindow.USER32 ref: 00B02B52
                          • GetDesktopWindow.USER32 ref: 00B02B6D
                          • GetWindowRect.USER32(00000000), ref: 00B02B74
                          • SetRect.USER32(?,00000000,00000000,00000007,00000002), ref: 00B02CA3
                          • AdjustWindowRectEx.USER32(?,88C00000,00000000,?), ref: 00B02CB1
                          • CreateWindowExW.USER32(?,AutoIt v3,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B02CF8
                          • GetClientRect.USER32(00000000,?), ref: 00B02D04
                          • CreateWindowExW.USER32(00000000,static,00000000,5000000E,00000000,00000000,?,?,00000000,00000000,00000000), ref: 00B02D40
                          • CreateFileW.KERNEL32(?,80000000,00000000,00000000,00000003,00000000,00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B02D62
                          • GetFileSize.KERNEL32(00000000,00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B02D75
                          • GlobalAlloc.KERNEL32(00000002,00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B02D80
                          • GlobalLock.KERNEL32(00000000), ref: 00B02D89
                          • ReadFile.KERNEL32(00000000,00000000,00000000,?,00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B02D98
                          • GlobalUnlock.KERNEL32(00000000), ref: 00B02DA1
                          • CloseHandle.KERNEL32(00000000,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B02DA8
                          • GlobalFree.KERNEL32(00000000), ref: 00B02DB3
                          • CreateStreamOnHGlobal.OLE32(00000000,00000001,?,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B02DC5
                          • OleLoadPicture.OLEAUT32(?,00000000,00000000,00B1FC38,00000000), ref: 00B02DDB
                          • GlobalFree.KERNEL32(00000000), ref: 00B02DEB
                          • CopyImage.USER32(00000007,00000000,00000000,00000000,00002000), ref: 00B02E11
                          • SendMessageW.USER32(00000000,00000172,00000000,00000007), ref: 00B02E30
                          • SetWindowPos.USER32(00000000,00000000,00000000,00000000,?,?,00000020,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B02E52
                          • ShowWindow.USER32(00000004,?,88C00000,000000FF,000000FF,?,?,00000000,00000000,00000000), ref: 00B0303F
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Global$CreateRect$File$DeleteFreeObject$AdjustAllocClientCloseCopyDesktopDestroyHandleImageLoadLockMessagePictureReadSendShowSizeStreamUnlock
                          • String ID: $AutoIt v3$DISPLAY$static
                          • API String ID: 2211948467-2373415609
                          • Opcode ID: 4be34078b4bc6f0c90c18eac45af2728118c252187ddd736e904d7701c257b78
                          • Instruction ID: 114e6cd75076a1fa9b2eedb53aa4ff41fe7ef931a7424e0efc35b3106dfc52b2
                          • Opcode Fuzzy Hash: 4be34078b4bc6f0c90c18eac45af2728118c252187ddd736e904d7701c257b78
                          • Instruction Fuzzy Hash: 93028A71940205AFDB14DFA4CD89EAE7FB9FB49711F108598F915AB2A1DB70ED00CB60
                          APIs
                          • SetTextColor.GDI32(?,00000000), ref: 00B1712F
                          • GetSysColorBrush.USER32(0000000F), ref: 00B17160
                          • GetSysColor.USER32(0000000F), ref: 00B1716C
                          • SetBkColor.GDI32(?,000000FF), ref: 00B17186
                          • SelectObject.GDI32(?,?), ref: 00B17195
                          • InflateRect.USER32(?,000000FF,000000FF), ref: 00B171C0
                          • GetSysColor.USER32(00000010), ref: 00B171C8
                          • CreateSolidBrush.GDI32(00000000), ref: 00B171CF
                          • FrameRect.USER32(?,?,00000000), ref: 00B171DE
                          • DeleteObject.GDI32(00000000), ref: 00B171E5
                          • InflateRect.USER32(?,000000FE,000000FE), ref: 00B17230
                          • FillRect.USER32(?,?,?), ref: 00B17262
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B17284
                            • Part of subcall function 00B173E8: GetSysColor.USER32(00000012), ref: 00B17421
                            • Part of subcall function 00B173E8: SetTextColor.GDI32(?,?), ref: 00B17425
                            • Part of subcall function 00B173E8: GetSysColorBrush.USER32(0000000F), ref: 00B1743B
                            • Part of subcall function 00B173E8: GetSysColor.USER32(0000000F), ref: 00B17446
                            • Part of subcall function 00B173E8: GetSysColor.USER32(00000011), ref: 00B17463
                            • Part of subcall function 00B173E8: CreatePen.GDI32(00000000,00000001,00743C00), ref: 00B17471
                            • Part of subcall function 00B173E8: SelectObject.GDI32(?,00000000), ref: 00B17482
                            • Part of subcall function 00B173E8: SetBkColor.GDI32(?,00000000), ref: 00B1748B
                            • Part of subcall function 00B173E8: SelectObject.GDI32(?,?), ref: 00B17498
                            • Part of subcall function 00B173E8: InflateRect.USER32(?,000000FF,000000FF), ref: 00B174B7
                            • Part of subcall function 00B173E8: RoundRect.GDI32(?,?,?,?,?,00000005,00000005), ref: 00B174CE
                            • Part of subcall function 00B173E8: GetWindowLongW.USER32(00000000,000000F0), ref: 00B174DB
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Color$Rect$Object$BrushInflateSelect$CreateLongTextWindow$DeleteFillFrameRoundSolid
                          • String ID:
                          • API String ID: 4124339563-0
                          • Opcode ID: ef87c5385ef2b42ec6c8dec7964396e558489849ff6f9acab757863d4658c667
                          • Instruction ID: 67a98e6c50c074cbc8980a448beced26829d9f7290243ed250c0af910e11ddac
                          • Opcode Fuzzy Hash: ef87c5385ef2b42ec6c8dec7964396e558489849ff6f9acab757863d4658c667
                          • Instruction Fuzzy Hash: 97A18E72088301FFDB019F60DC48A9A7BF9FB49320F904A19F962A71A1DB70E9458B91
                          APIs
                          • DestroyWindow.USER32(?,?), ref: 00A98E14
                          • SendMessageW.USER32(?,00001308,?,00000000), ref: 00AD6AC5
                          • ImageList_Remove.COMCTL32(?,000000FF,?), ref: 00AD6AFE
                          • MoveWindow.USER32(?,?,?,?,?,00000000), ref: 00AD6F43
                            • Part of subcall function 00A98F62: InvalidateRect.USER32(?,00000000,00000001,?,?,?,00A98BE8,?,00000000,?,?,?,?,00A98BBA,00000000,?), ref: 00A98FC5
                          • SendMessageW.USER32(?,00001053), ref: 00AD6F7F
                          • SendMessageW.USER32(?,00001008,000000FF,00000000), ref: 00AD6F96
                          • ImageList_Destroy.COMCTL32(00000000,?), ref: 00AD6FAC
                          • ImageList_Destroy.COMCTL32(00000000,?), ref: 00AD6FB7
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: DestroyImageList_MessageSend$Window$InvalidateMoveRectRemove
                          • String ID: 0
                          • API String ID: 2760611726-4108050209
                          • Opcode ID: cb2483d5b6115b5d6543f3e5b04dccfb840690307f0985d43e11a8c42e384042
                          • Instruction ID: 2a0e38c1869611c395d7a9e4d0ee0e79f2711b21d637197e988245edd346806f
                          • Opcode Fuzzy Hash: cb2483d5b6115b5d6543f3e5b04dccfb840690307f0985d43e11a8c42e384042
                          • Instruction Fuzzy Hash: CC12AD30600611DFDB25CF28D994BAABBF5FB49301F54846AF4968B261CB35EC52CB91
                          APIs
                          • DestroyWindow.USER32(00000000), ref: 00B0273E
                          • SystemParametersInfoW.USER32(00000030,00000000,?,00000000), ref: 00B0286A
                          • SetRect.USER32(?,00000000,00000000,0000012C,?), ref: 00B028A9
                          • AdjustWindowRectEx.USER32(?,88C00000,00000000,00000008), ref: 00B028B9
                          • CreateWindowExW.USER32(00000008,AutoIt v3,?,88C00000,000000FF,?,?,?,00000000,00000000,00000000), ref: 00B02900
                          • GetClientRect.USER32(00000000,?), ref: 00B0290C
                          • CreateWindowExW.USER32(00000000,static,?,50000000,?,00000004,00000500,-00000017,00000000,00000000,00000000), ref: 00B02955
                          • CreateDCW.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00B02964
                          • GetStockObject.GDI32(00000011), ref: 00B02974
                          • SelectObject.GDI32(00000000,00000000), ref: 00B02978
                          • GetTextFaceW.GDI32(00000000,00000040,?,?,50000000,?,00000004,00000500,-00000017,00000000,00000000,00000000,?,88C00000,000000FF,?), ref: 00B02988
                          • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00B02991
                          • DeleteDC.GDI32(00000000), ref: 00B0299A
                          • CreateFontW.GDI32(00000000,00000000,00000000,00000000,00000258,00000000,00000000,00000000,00000001,00000004,00000000,00000002,00000000,?), ref: 00B029C6
                          • SendMessageW.USER32(00000030,00000000,00000001), ref: 00B029DD
                          • CreateWindowExW.USER32(00000200,msctls_progress32,00000000,50000001,?,-0000001D,00000104,00000014,00000000,00000000,00000000), ref: 00B02A1D
                          • SendMessageW.USER32(00000000,00000401,00000000,00640000), ref: 00B02A31
                          • SendMessageW.USER32(00000404,00000001,00000000), ref: 00B02A42
                          • CreateWindowExW.USER32(00000000,static,?,50000000,?,00000041,00000500,-00000027,00000000,00000000,00000000), ref: 00B02A77
                          • GetStockObject.GDI32(00000011), ref: 00B02A82
                          • SendMessageW.USER32(00000030,00000000,?,50000000), ref: 00B02A8D
                          • ShowWindow.USER32(00000004,?,50000000,?,00000004,00000500,-00000017,00000000,00000000,00000000,?,88C00000,000000FF,?,?,?), ref: 00B02A97
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Create$MessageSend$ObjectRect$Stock$AdjustCapsClientDeleteDestroyDeviceFaceFontInfoParametersSelectShowSystemText
                          • String ID: AutoIt v3$DISPLAY$msctls_progress32$static
                          • API String ID: 2910397461-517079104
                          • Opcode ID: 5f767fc5a62092cdf3d4206eca6d3c4e67c98b84da7feb3cd4439abc359f9ade
                          • Instruction ID: b0e68b093fa5918c586f4fed15160483d76e85cb7301fafc6201f1eb26616f2b
                          • Opcode Fuzzy Hash: 5f767fc5a62092cdf3d4206eca6d3c4e67c98b84da7feb3cd4439abc359f9ade
                          • Instruction Fuzzy Hash: BCB14971A40215BFEB14DFA8CD89FAE7BB9EB08711F108554F915E72A0DB70AD40CBA4
                          APIs
                          • SetErrorMode.KERNEL32(00000001), ref: 00AF4AED
                          • GetDriveTypeW.KERNEL32(?,00B1CB68,?,\\.\,00B1CC08), ref: 00AF4BCA
                          • SetErrorMode.KERNEL32(00000000,00B1CB68,?,\\.\,00B1CC08), ref: 00AF4D36
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorMode$DriveType
                          • String ID: 1394$ATA$ATAPI$CDROM$Fibre$FileBackedVirtual$Fixed$MMC$Network$PhysicalDrive$RAID$RAMDisk$Removable$SAS$SATA$SCSI$SSA$SSD$USB$Unknown$Virtual$\\.\$iSCSI
                          • API String ID: 2907320926-4222207086
                          • Opcode ID: 85a8120173ab2d3a797613af03d81fc28dbbba477c88595718beb95cc3163432
                          • Instruction ID: 5c7d31d69e6bdf5435c16c32d068931689cad9e41a63c4203d512441a16b6797
                          • Opcode Fuzzy Hash: 85a8120173ab2d3a797613af03d81fc28dbbba477c88595718beb95cc3163432
                          • Instruction Fuzzy Hash: 7E61D430A4520D9BCB04DFA4CA8197E77F0EB4D714B249065F906AB262DB35DE42EB52
                          APIs
                          • GetSysColor.USER32(00000012), ref: 00B17421
                          • SetTextColor.GDI32(?,?), ref: 00B17425
                          • GetSysColorBrush.USER32(0000000F), ref: 00B1743B
                          • GetSysColor.USER32(0000000F), ref: 00B17446
                          • CreateSolidBrush.GDI32(?), ref: 00B1744B
                          • GetSysColor.USER32(00000011), ref: 00B17463
                          • CreatePen.GDI32(00000000,00000001,00743C00), ref: 00B17471
                          • SelectObject.GDI32(?,00000000), ref: 00B17482
                          • SetBkColor.GDI32(?,00000000), ref: 00B1748B
                          • SelectObject.GDI32(?,?), ref: 00B17498
                          • InflateRect.USER32(?,000000FF,000000FF), ref: 00B174B7
                          • RoundRect.GDI32(?,?,?,?,?,00000005,00000005), ref: 00B174CE
                          • GetWindowLongW.USER32(00000000,000000F0), ref: 00B174DB
                          • SendMessageW.USER32(00000000,0000000E,00000000,00000000), ref: 00B1752A
                          • GetWindowTextW.USER32(00000000,00000000,00000001), ref: 00B17554
                          • InflateRect.USER32(?,000000FD,000000FD), ref: 00B17572
                          • DrawFocusRect.USER32(?,?), ref: 00B1757D
                          • GetSysColor.USER32(00000011), ref: 00B1758E
                          • SetTextColor.GDI32(?,00000000), ref: 00B17596
                          • DrawTextW.USER32(?,00B170F5,000000FF,?,00000000), ref: 00B175A8
                          • SelectObject.GDI32(?,?), ref: 00B175BF
                          • DeleteObject.GDI32(?), ref: 00B175CA
                          • SelectObject.GDI32(?,?), ref: 00B175D0
                          • DeleteObject.GDI32(?), ref: 00B175D5
                          • SetTextColor.GDI32(?,?), ref: 00B175DB
                          • SetBkColor.GDI32(?,?), ref: 00B175E5
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Color$Object$Text$RectSelect$BrushCreateDeleteDrawInflateWindow$FocusLongMessageRoundSendSolid
                          • String ID:
                          • API String ID: 1996641542-0
                          • Opcode ID: d339a52be2e05f165b85a34f77b9fa53cbadc31d2ebe8acf19f7f9503c979af2
                          • Instruction ID: 20c9c8fa4ffc88904643ec9b3ad3a3364225fb471cbfa23273ce1911398c66c0
                          • Opcode Fuzzy Hash: d339a52be2e05f165b85a34f77b9fa53cbadc31d2ebe8acf19f7f9503c979af2
                          • Instruction Fuzzy Hash: 02615D72984218FFDF019FA4DC49AEE7FB9EB08320F618155F915BB2A1DB749940CB90
                          APIs
                          • GetCursorPos.USER32(?), ref: 00B11128
                          • GetDesktopWindow.USER32 ref: 00B1113D
                          • GetWindowRect.USER32(00000000), ref: 00B11144
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B11199
                          • DestroyWindow.USER32(?), ref: 00B111B9
                          • CreateWindowExW.USER32(00000008,tooltips_class32,00000000,7FFFFFFD,80000000,80000000,80000000,80000000,00000000,00000000,00000000,00000000), ref: 00B111ED
                          • SendMessageW.USER32(00000000,00000432,00000000,00000030), ref: 00B1120B
                          • SendMessageW.USER32(00000000,00000418,00000000,?), ref: 00B1121D
                          • SendMessageW.USER32(00000000,00000421,?,?), ref: 00B11232
                          • SendMessageW.USER32(00000000,0000041D,00000000,00000000), ref: 00B11245
                          • IsWindowVisible.USER32(00000000), ref: 00B112A1
                          • SendMessageW.USER32(00000000,00000412,00000000,D8F0D8F0), ref: 00B112BC
                          • SendMessageW.USER32(00000000,00000411,00000001,00000030), ref: 00B112D0
                          • GetWindowRect.USER32(00000000,?), ref: 00B112E8
                          • MonitorFromPoint.USER32(?,?,00000002), ref: 00B1130E
                          • GetMonitorInfoW.USER32(00000000,?), ref: 00B11328
                          • CopyRect.USER32(?,?), ref: 00B1133F
                          • SendMessageW.USER32(00000000,00000412,00000000), ref: 00B113AA
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSendWindow$Rect$Monitor$CopyCreateCursorDesktopDestroyFromInfoLongPointVisible
                          • String ID: ($0$tooltips_class32
                          • API String ID: 698492251-4156429822
                          • Opcode ID: 61546cc84ab6ce67390fc6e5fed97a534542c60d0ea1000c209956d57b5879a9
                          • Instruction ID: 36c76d7c6fe2e35d55136b50c7b14d2c49946b01c6232ddb803493fd5f7228a2
                          • Opcode Fuzzy Hash: 61546cc84ab6ce67390fc6e5fed97a534542c60d0ea1000c209956d57b5879a9
                          • Instruction Fuzzy Hash: 5AB19E71604341AFD704DF68C985BAEBBE4FF88750F408958FA999B2A1CB31DC44CBA1
                          APIs
                          • SystemParametersInfoW.USER32(00000030,00000000,000000FF,00000000), ref: 00A98968
                          • GetSystemMetrics.USER32(00000007), ref: 00A98970
                          • SystemParametersInfoW.USER32(00000030,00000000,000000FF,00000000), ref: 00A9899B
                          • GetSystemMetrics.USER32(00000008), ref: 00A989A3
                          • GetSystemMetrics.USER32(00000004), ref: 00A989C8
                          • SetRect.USER32(000000FF,00000000,00000000,000000FF,000000FF), ref: 00A989E5
                          • AdjustWindowRectEx.USER32(000000FF,?,00000000,?), ref: 00A989F5
                          • CreateWindowExW.USER32(?,AutoIt v3 GUI,?,?,?,000000FF,000000FF,000000FF,?,00000000,00000000), ref: 00A98A28
                          • SetWindowLongW.USER32(00000000,000000EB,00000000), ref: 00A98A3C
                          • GetClientRect.USER32(00000000,000000FF), ref: 00A98A5A
                          • GetStockObject.GDI32(00000011), ref: 00A98A76
                          • SendMessageW.USER32(00000000,00000030,00000000), ref: 00A98A81
                            • Part of subcall function 00A9912D: GetCursorPos.USER32(?), ref: 00A99141
                            • Part of subcall function 00A9912D: ScreenToClient.USER32(00000000,?), ref: 00A9915E
                            • Part of subcall function 00A9912D: GetAsyncKeyState.USER32(00000001), ref: 00A99183
                            • Part of subcall function 00A9912D: GetAsyncKeyState.USER32(00000002), ref: 00A9919D
                          • SetTimer.USER32(00000000,00000000,00000028,00A990FC), ref: 00A98AA8
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: System$MetricsRectWindow$AsyncClientInfoParametersState$AdjustCreateCursorLongMessageObjectScreenSendStockTimer
                          • String ID: AutoIt v3 GUI
                          • API String ID: 1458621304-248962490
                          • Opcode ID: cbb68c01de623015d40f64880b3e00c46bcdd138b521046526d7ad059d4ea7f4
                          • Instruction ID: 7f5d2e9f72d1df0a4983efe84fbd597f26768798f4b8c47dc79b7b0c5b4b082a
                          • Opcode Fuzzy Hash: cbb68c01de623015d40f64880b3e00c46bcdd138b521046526d7ad059d4ea7f4
                          • Instruction Fuzzy Hash: E7B16C71A40209AFDF14DFA8CD45BEE3BF5FB48315F10856AFA16A7290DB34A841CB50
                          APIs
                            • Part of subcall function 00AE10F9: GetUserObjectSecurity.USER32(?,00000004,?,00000000,?), ref: 00AE1114
                            • Part of subcall function 00AE10F9: GetLastError.KERNEL32(?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE1120
                            • Part of subcall function 00AE10F9: GetProcessHeap.KERNEL32(00000008,?,?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE112F
                            • Part of subcall function 00AE10F9: HeapAlloc.KERNEL32(00000000,?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE1136
                            • Part of subcall function 00AE10F9: GetUserObjectSecurity.USER32(?,00000004,00000000,?,?), ref: 00AE114D
                          • GetSecurityDescriptorDacl.ADVAPI32(?,?,?,?), ref: 00AE0DF5
                          • GetAclInformation.ADVAPI32(?,?,0000000C,00000002), ref: 00AE0E29
                          • GetLengthSid.ADVAPI32(?), ref: 00AE0E40
                          • GetAce.ADVAPI32(?,00000000,?), ref: 00AE0E7A
                          • AddAce.ADVAPI32(?,00000002,000000FF,?,?), ref: 00AE0E96
                          • GetLengthSid.ADVAPI32(?), ref: 00AE0EAD
                          • GetProcessHeap.KERNEL32(00000008,00000008), ref: 00AE0EB5
                          • HeapAlloc.KERNEL32(00000000), ref: 00AE0EBC
                          • GetLengthSid.ADVAPI32(?,00000008,?), ref: 00AE0EDD
                          • CopySid.ADVAPI32(00000000), ref: 00AE0EE4
                          • AddAce.ADVAPI32(?,00000002,000000FF,00000000,?), ref: 00AE0F13
                          • SetSecurityDescriptorDacl.ADVAPI32(?,00000001,?,00000000), ref: 00AE0F35
                          • SetUserObjectSecurity.USER32(?,00000004,?), ref: 00AE0F47
                          • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00AE0F6E
                          • HeapFree.KERNEL32(00000000), ref: 00AE0F75
                          • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00AE0F7E
                          • HeapFree.KERNEL32(00000000), ref: 00AE0F85
                          • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00AE0F8E
                          • HeapFree.KERNEL32(00000000), ref: 00AE0F95
                          • GetProcessHeap.KERNEL32(00000000,?), ref: 00AE0FA1
                          • HeapFree.KERNEL32(00000000), ref: 00AE0FA8
                            • Part of subcall function 00AE1193: GetProcessHeap.KERNEL32(00000008,00AE0BB1,?,00000000,?,00AE0BB1,?), ref: 00AE11A1
                            • Part of subcall function 00AE1193: HeapAlloc.KERNEL32(00000000,?,00000000,?,00AE0BB1,?), ref: 00AE11A8
                            • Part of subcall function 00AE1193: InitializeSecurityDescriptor.ADVAPI32(00000000,00000001,?,00000000,?,00AE0BB1,?), ref: 00AE11B7
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Heap$Process$Security$Free$AllocDescriptorLengthObjectUser$Dacl$CopyErrorInformationInitializeLast
                          • String ID:
                          • API String ID: 4175595110-0
                          • Opcode ID: 580e6f562cc295c66c843e4d46a42da7f810d4f0c1a15c65fd50a88fd5b766b7
                          • Instruction ID: 5580bcdc49d0f757909d8c1cebcad1b28946db06283d7b4ae86d51dd22fd186a
                          • Opcode Fuzzy Hash: 580e6f562cc295c66c843e4d46a42da7f810d4f0c1a15c65fd50a88fd5b766b7
                          • Instruction Fuzzy Hash: CA717B7294024AABDB209FA5DC48FEEBBB8BF08300F148115F959E7191DB709E55CB60
                          APIs
                          • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 00B0C4BD
                          • RegCreateKeyExW.ADVAPI32(?,?,00000000,00B1CC08,00000000,?,00000000,?,?), ref: 00B0C544
                          • RegCloseKey.ADVAPI32(00000000,00000000,00000000), ref: 00B0C5A4
                          • _wcslen.LIBCMT ref: 00B0C5F4
                          • _wcslen.LIBCMT ref: 00B0C66F
                          • RegSetValueExW.ADVAPI32(00000001,?,00000000,00000001,?,?), ref: 00B0C6B2
                          • RegSetValueExW.ADVAPI32(00000001,?,00000000,00000007,?,?), ref: 00B0C7C1
                          • RegSetValueExW.ADVAPI32(00000001,?,00000000,0000000B,?,00000008), ref: 00B0C84D
                          • RegCloseKey.ADVAPI32(?), ref: 00B0C881
                          • RegCloseKey.ADVAPI32(00000000), ref: 00B0C88E
                          • RegSetValueExW.ADVAPI32(00000001,?,00000000,00000003,00000000,00000000), ref: 00B0C960
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Value$Close$_wcslen$ConnectCreateRegistry
                          • String ID: REG_BINARY$REG_DWORD$REG_EXPAND_SZ$REG_MULTI_SZ$REG_QWORD$REG_SZ
                          • API String ID: 9721498-966354055
                          • Opcode ID: 23fdccc0e82ba5ca5072c1a971ef3fd7bd069e6903686e9ff3c2db61d91019e7
                          • Instruction ID: ca5ab5113f6a5354c19319ee68ccea4a9315b43483174edfa740231d19ae225d
                          • Opcode Fuzzy Hash: 23fdccc0e82ba5ca5072c1a971ef3fd7bd069e6903686e9ff3c2db61d91019e7
                          • Instruction Fuzzy Hash: 181269356042019FDB14EF14C981A2ABBE5FF88714F14899CF89A9B3A2DB31FD41CB95
                          APIs
                          • CharUpperBuffW.USER32(?,?), ref: 00B109C6
                          • _wcslen.LIBCMT ref: 00B10A01
                          • SendMessageW.USER32(?,00001105,00000000,00000000), ref: 00B10A54
                          • _wcslen.LIBCMT ref: 00B10A8A
                          • _wcslen.LIBCMT ref: 00B10B06
                          • _wcslen.LIBCMT ref: 00B10B81
                            • Part of subcall function 00A9F9F2: _wcslen.LIBCMT ref: 00A9F9FD
                            • Part of subcall function 00AE2BE8: SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00AE2BFA
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$MessageSend$BuffCharUpper
                          • String ID: CHECK$COLLAPSE$EXISTS$EXPAND$GETITEMCOUNT$GETSELECTED$GETTEXT$GETTOTALCOUNT$ISCHECKED$SELECT$UNCHECK
                          • API String ID: 1103490817-4258414348
                          • Opcode ID: 0e269150fd342cf76365a0d2f9f27fca3bfe8d5a49fb774ac847393a8305c68b
                          • Instruction ID: 0d91e5beded7437b4d56776ff64acdfc1b132441ba983bb82e9cfbe63e362c70
                          • Opcode Fuzzy Hash: 0e269150fd342cf76365a0d2f9f27fca3bfe8d5a49fb774ac847393a8305c68b
                          • Instruction Fuzzy Hash: 3BE1AF312283418FCB14EF24C59096AB7E1FF98314F94899DF8969B362DB70ED85CB91
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$BuffCharUpper
                          • String ID: HKCC$HKCR$HKCU$HKEY_CLASSES_ROOT$HKEY_CURRENT_CONFIG$HKEY_CURRENT_USER$HKEY_LOCAL_MACHINE$HKEY_USERS$HKLM$HKU
                          • API String ID: 1256254125-909552448
                          • Opcode ID: 782b0024cbd1fc9c6cb47b2810e48cc5fc2768cb721c49f9bdded7a34ec4f72c
                          • Instruction ID: f61031300e11efba1ca26e588e472f23d4fae8c92f01c0ecb75d87bb3eccf6f6
                          • Opcode Fuzzy Hash: 782b0024cbd1fc9c6cb47b2810e48cc5fc2768cb721c49f9bdded7a34ec4f72c
                          • Instruction Fuzzy Hash: 2871E13360016A8BDB20DF6CC9415BB3FD5EBA1750B6507A8F866972D8EB30CE45D3A0
                          APIs
                          • _wcslen.LIBCMT ref: 00B1835A
                          • _wcslen.LIBCMT ref: 00B1836E
                          • _wcslen.LIBCMT ref: 00B18391
                          • _wcslen.LIBCMT ref: 00B183B4
                          • LoadImageW.USER32(00000000,?,00000001,?,?,00002010), ref: 00B183F2
                          • LoadLibraryExW.KERNEL32(?,00000000,00000032,?,?,00000001,?,?,?,00B1361A,?), ref: 00B1844E
                          • LoadImageW.USER32(?,?,00000001,?,?,00000000), ref: 00B18487
                          • LoadImageW.USER32(00000000,?,00000001,?,?,00000000), ref: 00B184CA
                          • LoadImageW.USER32(?,?,00000001,?,?,00000000), ref: 00B18501
                          • FreeLibrary.KERNEL32(?), ref: 00B1850D
                          • ExtractIconExW.SHELL32(?,00000000,00000000,00000000,00000001), ref: 00B1851D
                          • DestroyIcon.USER32(?), ref: 00B1852C
                          • SendMessageW.USER32(?,00000170,00000000,00000000), ref: 00B18549
                          • SendMessageW.USER32(?,00000064,00000172,00000001), ref: 00B18555
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Load$Image_wcslen$IconLibraryMessageSend$DestroyExtractFree
                          • String ID: .dll$.exe$.icl
                          • API String ID: 799131459-1154884017
                          • Opcode ID: 6b9e146e384dca60765044d0ad9f27ea82be78c2dbbd3cee56ff4e67cb8e4922
                          • Instruction ID: 29e6ed438dbe608c480323990dcc36ac5822c26489e369eab03f4ee408bde6b4
                          • Opcode Fuzzy Hash: 6b9e146e384dca60765044d0ad9f27ea82be78c2dbbd3cee56ff4e67cb8e4922
                          • Instruction Fuzzy Hash: EB61CF71540205BAEB14DF64DC81BFE7BA8FB18B11F508649F815D71D1DFB4AA90CBA0
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID: "$#OnAutoItStartRegister$#ce$#comments-end$#comments-start$#cs$#include$#include-once$#notrayicon$#pragma compile$#requireadmin$'$Bad directive syntax error$Cannot parse #include$Unterminated group of comments
                          • API String ID: 0-1645009161
                          • Opcode ID: 994a5d87104a90436c2ca938b36d7817e773d056cbf2ce42806934971e99bf21
                          • Instruction ID: 6b4dcbba685b4aae6d6ef73fdf8841f87a23eeb22aecdf7522661659f3f08898
                          • Opcode Fuzzy Hash: 994a5d87104a90436c2ca938b36d7817e773d056cbf2ce42806934971e99bf21
                          • Instruction Fuzzy Hash: 9C81D071A44605BBDB20BF60CD42FAF7BB8AF15300F154068F805AB1D6EB74EA91C7A1
                          APIs
                          • CharLowerBuffW.USER32(?,?), ref: 00AF3EF8
                          • _wcslen.LIBCMT ref: 00AF3F03
                          • _wcslen.LIBCMT ref: 00AF3F5A
                          • _wcslen.LIBCMT ref: 00AF3F98
                          • GetDriveTypeW.KERNEL32(?), ref: 00AF3FD6
                          • mciSendStringW.WINMM(?,00000000,00000000,00000000), ref: 00AF401E
                          • mciSendStringW.WINMM(?,00000000,00000000,00000000), ref: 00AF4059
                          • mciSendStringW.WINMM(?,00000000,00000000,00000000), ref: 00AF4087
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: SendString_wcslen$BuffCharDriveLowerType
                          • String ID: type cdaudio alias cd wait$ wait$close$close cd wait$closed$open$open $set cd door
                          • API String ID: 1839972693-4113822522
                          • Opcode ID: 02ce18d7ca4d04462a49f861ade83d91702b28cce1ceab91d1775d75a4684af6
                          • Instruction ID: b9e938064f59cbf9ed921c97bd564fad0dc61479abd496abb8357e2b3859fa43
                          • Opcode Fuzzy Hash: 02ce18d7ca4d04462a49f861ade83d91702b28cce1ceab91d1775d75a4684af6
                          • Instruction Fuzzy Hash: F171CD32A042069FC710EF24C98197BB7F4EF99758F00492DFA9697261EB30DE45CB92
                          APIs
                          • LoadIconW.USER32(00000063), ref: 00AE5A2E
                          • SendMessageW.USER32(?,00000080,00000000,00000000), ref: 00AE5A40
                          • SetWindowTextW.USER32(?,?), ref: 00AE5A57
                          • GetDlgItem.USER32(?,000003EA), ref: 00AE5A6C
                          • SetWindowTextW.USER32(00000000,?), ref: 00AE5A72
                          • GetDlgItem.USER32(?,000003E9), ref: 00AE5A82
                          • SetWindowTextW.USER32(00000000,?), ref: 00AE5A88
                          • SendDlgItemMessageW.USER32(?,000003E9,000000CC,?,00000000), ref: 00AE5AA9
                          • SendDlgItemMessageW.USER32(?,000003E9,000000C5,00000000,00000000), ref: 00AE5AC3
                          • GetWindowRect.USER32(?,?), ref: 00AE5ACC
                          • _wcslen.LIBCMT ref: 00AE5B33
                          • SetWindowTextW.USER32(?,?), ref: 00AE5B6F
                          • GetDesktopWindow.USER32 ref: 00AE5B75
                          • GetWindowRect.USER32(00000000), ref: 00AE5B7C
                          • MoveWindow.USER32(?,?,00000080,00000000,?,00000000), ref: 00AE5BD3
                          • GetClientRect.USER32(?,?), ref: 00AE5BE0
                          • PostMessageW.USER32(?,00000005,00000000,?), ref: 00AE5C05
                          • SetTimer.USER32(?,0000040A,00000000,00000000), ref: 00AE5C2F
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$ItemMessageText$RectSend$ClientDesktopIconLoadMovePostTimer_wcslen
                          • String ID:
                          • API String ID: 895679908-0
                          • Opcode ID: d69c05e5c3708ba00e86ebb76acd45ac9aa233596fd33451fd400d0ab00a630e
                          • Instruction ID: c3ed702d0f3d9a3039073a7642d0487925b6fb6e64666b79552a15f56a423bcf
                          • Opcode Fuzzy Hash: d69c05e5c3708ba00e86ebb76acd45ac9aa233596fd33451fd400d0ab00a630e
                          • Instruction Fuzzy Hash: 4A715D31900B49AFDB20DFB9DE85AAEBBF5FF48708F104518E542A35A0DB75E944CB50
                          APIs
                          • LoadCursorW.USER32(00000000,00007F89), ref: 00AFFE27
                          • LoadCursorW.USER32(00000000,00007F8A), ref: 00AFFE32
                          • LoadCursorW.USER32(00000000,00007F00), ref: 00AFFE3D
                          • LoadCursorW.USER32(00000000,00007F03), ref: 00AFFE48
                          • LoadCursorW.USER32(00000000,00007F8B), ref: 00AFFE53
                          • LoadCursorW.USER32(00000000,00007F01), ref: 00AFFE5E
                          • LoadCursorW.USER32(00000000,00007F81), ref: 00AFFE69
                          • LoadCursorW.USER32(00000000,00007F88), ref: 00AFFE74
                          • LoadCursorW.USER32(00000000,00007F80), ref: 00AFFE7F
                          • LoadCursorW.USER32(00000000,00007F86), ref: 00AFFE8A
                          • LoadCursorW.USER32(00000000,00007F83), ref: 00AFFE95
                          • LoadCursorW.USER32(00000000,00007F85), ref: 00AFFEA0
                          • LoadCursorW.USER32(00000000,00007F82), ref: 00AFFEAB
                          • LoadCursorW.USER32(00000000,00007F84), ref: 00AFFEB6
                          • LoadCursorW.USER32(00000000,00007F04), ref: 00AFFEC1
                          • LoadCursorW.USER32(00000000,00007F02), ref: 00AFFECC
                          • GetCursorInfo.USER32(?), ref: 00AFFEDC
                          • GetLastError.KERNEL32 ref: 00AFFF1E
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Cursor$Load$ErrorInfoLast
                          • String ID:
                          • API String ID: 3215588206-0
                          • Opcode ID: 6d15f25c2c41ccaee6fb90310c070c3be2ec058f426e0eb6fef4479af3602b17
                          • Instruction ID: 4379941068ccfc1d76dfbb101ac3fab2477320f40f762b4872c3d35bfed16523
                          • Opcode Fuzzy Hash: 6d15f25c2c41ccaee6fb90310c070c3be2ec058f426e0eb6fef4479af3602b17
                          • Instruction Fuzzy Hash: 914144B0D443196EDB109FBA8C8586EBFE8FF04754B50852AF11DE7291DB789901CF91
                          APIs
                          • __scrt_initialize_thread_safe_statics_platform_specific.LIBCMT ref: 00AA00C6
                            • Part of subcall function 00AA00ED: InitializeCriticalSectionAndSpinCount.KERNEL32(00B5070C,00000FA0,39DD5126,?,?,?,?,00AC23B3,000000FF), ref: 00AA011C
                            • Part of subcall function 00AA00ED: GetModuleHandleW.KERNEL32(api-ms-win-core-synch-l1-2-0.dll,?,?,?,?,00AC23B3,000000FF), ref: 00AA0127
                            • Part of subcall function 00AA00ED: GetModuleHandleW.KERNEL32(kernel32.dll,?,?,?,?,00AC23B3,000000FF), ref: 00AA0138
                            • Part of subcall function 00AA00ED: GetProcAddress.KERNEL32(00000000,InitializeConditionVariable), ref: 00AA014E
                            • Part of subcall function 00AA00ED: GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 00AA015C
                            • Part of subcall function 00AA00ED: GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 00AA016A
                            • Part of subcall function 00AA00ED: __crt_fast_encode_pointer.LIBVCRUNTIME ref: 00AA0195
                            • Part of subcall function 00AA00ED: __crt_fast_encode_pointer.LIBVCRUNTIME ref: 00AA01A0
                          • ___scrt_fastfail.LIBCMT ref: 00AA00E7
                            • Part of subcall function 00AA00A3: __onexit.LIBCMT ref: 00AA00A9
                          Strings
                          • WakeAllConditionVariable, xrefs: 00AA0162
                          • SleepConditionVariableCS, xrefs: 00AA0154
                          • InitializeConditionVariable, xrefs: 00AA0148
                          • api-ms-win-core-synch-l1-2-0.dll, xrefs: 00AA0122
                          • kernel32.dll, xrefs: 00AA0133
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AddressProc$HandleModule__crt_fast_encode_pointer$CountCriticalInitializeSectionSpin___scrt_fastfail__onexit__scrt_initialize_thread_safe_statics_platform_specific
                          • String ID: InitializeConditionVariable$SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
                          • API String ID: 66158676-1714406822
                          • Opcode ID: 6884776bada938eb51a3e19e87eb8e0559789972622ec0947303c8f16696194c
                          • Instruction ID: 79abcac19d06b2f2bd67a667436abab71b1a80dc5d3b22565183389b89791149
                          • Opcode Fuzzy Hash: 6884776bada938eb51a3e19e87eb8e0559789972622ec0947303c8f16696194c
                          • Instruction Fuzzy Hash: 4C21A7326847116FDB116B64BD46FF937E4EB46F51F404679F805E72E1DF649C008A90
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen
                          • String ID: CLASS$CLASSNN$INSTANCE$NAME$REGEXPCLASS$TEXT
                          • API String ID: 176396367-1603158881
                          • Opcode ID: 61275be9a411a77fd9613d5249f347637e12c4f570e7d71930248f212677f045
                          • Instruction ID: 9794f90fa1bfc526857457daad236012ad3f2e5269384052b9b78c111a3146de
                          • Opcode Fuzzy Hash: 61275be9a411a77fd9613d5249f347637e12c4f570e7d71930248f212677f045
                          • Instruction Fuzzy Hash: 54E10533A00556AFCF249F69C859BEEFBB0BF54710F548169E456E7280DB30AF8587A0
                          APIs
                          • CharLowerBuffW.USER32(00000000,00000000,00B1CC08), ref: 00AF4527
                          • _wcslen.LIBCMT ref: 00AF453B
                          • _wcslen.LIBCMT ref: 00AF4599
                          • _wcslen.LIBCMT ref: 00AF45F4
                          • _wcslen.LIBCMT ref: 00AF463F
                          • _wcslen.LIBCMT ref: 00AF46A7
                            • Part of subcall function 00A9F9F2: _wcslen.LIBCMT ref: 00A9F9FD
                          • GetDriveTypeW.KERNEL32(?,00B46BF0,00000061), ref: 00AF4743
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$BuffCharDriveLowerType
                          • String ID: all$cdrom$fixed$network$ramdisk$removable$unknown
                          • API String ID: 2055661098-1000479233
                          • Opcode ID: 8ad8f9f54649984c3a2c5bb941911e29afa4b885b835880e59663612ce0a70df
                          • Instruction ID: e85c7a5e8ea5f341bb405b944d3311624819cbcfa615270e006d7eac04896af9
                          • Opcode Fuzzy Hash: 8ad8f9f54649984c3a2c5bb941911e29afa4b885b835880e59663612ce0a70df
                          • Instruction Fuzzy Hash: 3AB1FE316083069FC710EF68C990A7BB7E5AFAA760F50491DF696C7291E730DD44CBA2
                          APIs
                          • LoadLibraryA.KERNEL32(kernel32.dll,?,00B1CC08), ref: 00B040BB
                          • GetProcAddress.KERNEL32(00000000,GetModuleHandleExW), ref: 00B040CD
                          • GetModuleFileNameW.KERNEL32(?,?,00000104,?,?,?,00B1CC08), ref: 00B040F2
                          • FreeLibrary.KERNEL32(00000000,?,00B1CC08), ref: 00B0413E
                          • StringFromGUID2.OLE32(?,?,00000028,?,00B1CC08), ref: 00B041A8
                          • SysFreeString.OLEAUT32(00000009), ref: 00B04262
                          • QueryPathOfRegTypeLib.OLEAUT32(?,?,?,?,?), ref: 00B042C8
                          • SysFreeString.OLEAUT32(?), ref: 00B042F2
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FreeString$Library$AddressFileFromLoadModuleNamePathProcQueryType
                          • String ID: GetModuleHandleExW$kernel32.dll
                          • API String ID: 354098117-199464113
                          • Opcode ID: 7a8d7e57bb5623e0e961b0b216ba36c5e6dac8c81ccff3b9de9a41804da7831f
                          • Instruction ID: fb81b6a5fcaf284728b403996695fa8a86214e13bd36bcdc3467b0bab8009544
                          • Opcode Fuzzy Hash: 7a8d7e57bb5623e0e961b0b216ba36c5e6dac8c81ccff3b9de9a41804da7831f
                          • Instruction Fuzzy Hash: C5122DB5A00115EFDB14DF54C984EAEBBF5FF45314F248098EA05AB2A1DB31ED46CBA0
                          APIs
                          • GetMenuItemCount.USER32(00B51990), ref: 00AC2F8D
                          • GetMenuItemCount.USER32(00B51990), ref: 00AC303D
                          • GetCursorPos.USER32(?), ref: 00AC3081
                          • SetForegroundWindow.USER32(00000000), ref: 00AC308A
                          • TrackPopupMenuEx.USER32(00B51990,00000000,?,00000000,00000000,00000000), ref: 00AC309D
                          • PostMessageW.USER32(00000000,00000000,00000000,00000000), ref: 00AC30A9
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Menu$CountItem$CursorForegroundMessagePopupPostTrackWindow
                          • String ID: 0
                          • API String ID: 36266755-4108050209
                          • Opcode ID: ac935da290b6de1fed706a5ef7077354ea4b09d1a5494100668a30690bce8cd0
                          • Instruction ID: 141ab43e7b33296edc4bf19085d2cfeadc82b5a4b7ffdae74730998697256630
                          • Opcode Fuzzy Hash: ac935da290b6de1fed706a5ef7077354ea4b09d1a5494100668a30690bce8cd0
                          • Instruction Fuzzy Hash: 3F71F771644209BEEF259F28CC49FEABF75FF15764F20421AF5146A1E0CBB1A920DB90
                          APIs
                          • DestroyWindow.USER32(00000000,?), ref: 00B16DEB
                            • Part of subcall function 00A86B57: _wcslen.LIBCMT ref: 00A86B6A
                          • CreateWindowExW.USER32(00000008,tooltips_class32,00000000,?,80000000,80000000,80000000,80000000,?,00000000,00000000,?), ref: 00B16E5F
                          • SendMessageW.USER32(00000000,00000433,00000000,00000030), ref: 00B16E81
                          • SendMessageW.USER32(00000000,00000432,00000000,00000030), ref: 00B16E94
                          • DestroyWindow.USER32(?), ref: 00B16EB5
                          • CreateWindowExW.USER32(00000008,tooltips_class32,00000000,?,80000000,80000000,80000000,80000000,?,00000000,00A80000,00000000), ref: 00B16EE4
                          • SendMessageW.USER32(00000000,00000432,00000000,00000030), ref: 00B16EFD
                          • GetDesktopWindow.USER32 ref: 00B16F16
                          • GetWindowRect.USER32(00000000), ref: 00B16F1D
                          • SendMessageW.USER32(00000000,00000418,00000000,?), ref: 00B16F35
                          • SendMessageW.USER32(00000000,00000421,?,00000000), ref: 00B16F4D
                            • Part of subcall function 00A99944: GetWindowLongW.USER32(?,000000EB), ref: 00A99952
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$MessageSend$CreateDestroy$DesktopLongRect_wcslen
                          • String ID: 0$tooltips_class32
                          • API String ID: 2429346358-3619404913
                          • Opcode ID: bff4677d6128856f33ceadcbb249768a8d25dc0b9397a33c7d501c057eaaebbb
                          • Instruction ID: 15053bc37e102afaae2ffa40bd2ce864a492e125f5c70df000bfdff56dd02c52
                          • Opcode Fuzzy Hash: bff4677d6128856f33ceadcbb249768a8d25dc0b9397a33c7d501c057eaaebbb
                          • Instruction Fuzzy Hash: 5B716675244340AFDB21CF18DC48BAABBE9FB89304F84499DF99987261CB70A946CB11
                          APIs
                            • Part of subcall function 00A99BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 00A99BB2
                          • DragQueryPoint.SHELL32(?,?), ref: 00B19147
                            • Part of subcall function 00B17674: ClientToScreen.USER32(?,?), ref: 00B1769A
                            • Part of subcall function 00B17674: GetWindowRect.USER32(?,?), ref: 00B17710
                            • Part of subcall function 00B17674: PtInRect.USER32(?,?,00B18B89), ref: 00B17720
                          • SendMessageW.USER32(?,000000B0,?,?), ref: 00B191B0
                          • DragQueryFileW.SHELL32(?,000000FF,00000000,00000000), ref: 00B191BB
                          • DragQueryFileW.SHELL32(?,00000000,?,00000104), ref: 00B191DE
                          • SendMessageW.USER32(?,000000C2,00000001,?), ref: 00B19225
                          • SendMessageW.USER32(?,000000B0,?,?), ref: 00B1923E
                          • SendMessageW.USER32(?,000000B1,?,?), ref: 00B19255
                          • SendMessageW.USER32(?,000000B1,?,?), ref: 00B19277
                          • DragFinish.SHELL32(?), ref: 00B1927E
                          • DefDlgProcW.USER32(?,00000233,?,00000000,?,?,?), ref: 00B19371
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$Drag$Query$FileRectWindow$ClientFinishLongPointProcScreen
                          • String ID: @GUI_DRAGFILE$@GUI_DRAGID$@GUI_DROPID
                          • API String ID: 221274066-3440237614
                          • Opcode ID: b4e52cc1c8e08cdb63b7bb87072aa73438e9f2df8da808fc15e02ca4e880e331
                          • Instruction ID: 282fa3b120a7d97c5ad1f7affd4a96ef959be645a79398ba93f88f72a59f9c46
                          • Opcode Fuzzy Hash: b4e52cc1c8e08cdb63b7bb87072aa73438e9f2df8da808fc15e02ca4e880e331
                          • Instruction Fuzzy Hash: 59618B71108301AFD701EF64DD85EAFBBE8EF88750F40496EF595931A0DB309A49CB92
                          APIs
                          • InternetConnectW.WININET(?,?,?,?,?,?,00000000,00000000), ref: 00AFC4B0
                          • GetLastError.KERNEL32(?,00000003,?,?,?,?,?,?), ref: 00AFC4C3
                          • SetEvent.KERNEL32(?,?,00000003,?,?,?,?,?,?), ref: 00AFC4D7
                          • HttpOpenRequestW.WININET(00000000,00000000,?,00000000,00000000,00000000,?,00000000), ref: 00AFC4F0
                          • InternetQueryOptionW.WININET(00000000,0000001F,?,?), ref: 00AFC533
                          • InternetSetOptionW.WININET(00000000,0000001F,00000100,00000004), ref: 00AFC549
                          • HttpSendRequestW.WININET(00000000,00000000,00000000,00000000,00000000), ref: 00AFC554
                          • HttpQueryInfoW.WININET(00000000,00000005,?,?,?), ref: 00AFC584
                          • GetLastError.KERNEL32(?,00000003,?,?,?,?,?,?), ref: 00AFC5DC
                          • SetEvent.KERNEL32(?,?,00000003,?,?,?,?,?,?), ref: 00AFC5F0
                          • InternetCloseHandle.WININET(00000000), ref: 00AFC5FB
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Internet$Http$ErrorEventLastOptionQueryRequest$CloseConnectHandleInfoOpenSend
                          • String ID:
                          • API String ID: 3800310941-3916222277
                          • Opcode ID: a0407e5ea6e6f641900205757226428c3e1f7864f9f8bf4f88b97e7959b91733
                          • Instruction ID: 32d8e2ccb387509c6ea1c6f12623558ce3e441e1341021c3a9b53b25391a98bc
                          • Opcode Fuzzy Hash: a0407e5ea6e6f641900205757226428c3e1f7864f9f8bf4f88b97e7959b91733
                          • Instruction Fuzzy Hash: 5C513CB158020DBFDB218FA1CA48ABB7BBCFB08764F008419FA46D7250DB74E944DB60
                          APIs
                          • CreateFileW.KERNEL32(?,80000000,00000000,00000000,00000003,00000000,00000000,?,00000000,?), ref: 00B18592
                          • GetFileSize.KERNEL32(00000000,00000000), ref: 00B185A2
                          • GlobalAlloc.KERNEL32(00000002,00000000), ref: 00B185AD
                          • CloseHandle.KERNEL32(00000000), ref: 00B185BA
                          • GlobalLock.KERNEL32(00000000), ref: 00B185C8
                          • ReadFile.KERNEL32(00000000,00000000,00000000,?,00000000), ref: 00B185D7
                          • GlobalUnlock.KERNEL32(00000000), ref: 00B185E0
                          • CloseHandle.KERNEL32(00000000), ref: 00B185E7
                          • CreateStreamOnHGlobal.OLE32(00000000,00000001,?), ref: 00B185F8
                          • OleLoadPicture.OLEAUT32(?,00000000,00000000,00B1FC38,?), ref: 00B18611
                          • GlobalFree.KERNEL32(00000000), ref: 00B18621
                          • GetObjectW.GDI32(?,00000018,000000FF), ref: 00B18641
                          • CopyImage.USER32(?,00000000,00000000,?,00002000), ref: 00B18671
                          • DeleteObject.GDI32(00000000), ref: 00B18699
                          • SendMessageW.USER32(?,00000172,00000000,00000000), ref: 00B186AF
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Global$File$CloseCreateHandleObject$AllocCopyDeleteFreeImageLoadLockMessagePictureReadSendSizeStreamUnlock
                          • String ID:
                          • API String ID: 3840717409-0
                          • Opcode ID: 7c2353177f3917d8b73fd33b5dee5abba946b4936fee608287be541991d9d964
                          • Instruction ID: e8e8b301c7cf7dfe1f11ea4fc56579c18c52a40627c5a79cea4f842f99ab6e7b
                          • Opcode Fuzzy Hash: 7c2353177f3917d8b73fd33b5dee5abba946b4936fee608287be541991d9d964
                          • Instruction Fuzzy Hash: 55411875640208BFDB119FA5DC88EEA7BBDFF89B11F508068F905E7260DB309A41CB60
                          APIs
                          • VariantInit.OLEAUT32(00000000), ref: 00AF1502
                          • VariantCopy.OLEAUT32(?,?), ref: 00AF150B
                          • VariantClear.OLEAUT32(?), ref: 00AF1517
                          • VariantTimeToSystemTime.OLEAUT32(?,?,?), ref: 00AF15FB
                          • VarR8FromDec.OLEAUT32(?,?), ref: 00AF1657
                          • VariantInit.OLEAUT32(?), ref: 00AF1708
                          • SysFreeString.OLEAUT32(?), ref: 00AF178C
                          • VariantClear.OLEAUT32(?), ref: 00AF17D8
                          • VariantClear.OLEAUT32(?), ref: 00AF17E7
                          • VariantInit.OLEAUT32(00000000), ref: 00AF1823
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Variant$ClearInit$Time$CopyFreeFromStringSystem
                          • String ID: %4d%02d%02d%02d%02d%02d$Default
                          • API String ID: 1234038744-3931177956
                          • Opcode ID: 2289a317dd05e3b5218c6ca2496fb912d2554d1162f29cbf0a26e51125d2ff5c
                          • Instruction ID: 3d52d88536be9c308f109e6d7ad932be72ebf7691cd2a864c8f877043a5805d5
                          • Opcode Fuzzy Hash: 2289a317dd05e3b5218c6ca2496fb912d2554d1162f29cbf0a26e51125d2ff5c
                          • Instruction Fuzzy Hash: 8DD1E071A04219EFDF04AFA5D985BB9B7F6BF44700F148056FA06AB280DB30EC41DBA1
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00B0C998: CharUpperBuffW.USER32(?,?,?,?,?,?,?,00B0B6AE,?,?), ref: 00B0C9B5
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0C9F1
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0CA68
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0CA9E
                          • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 00B0B6F4
                          • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 00B0B772
                          • RegDeleteValueW.ADVAPI32(?,?), ref: 00B0B80A
                          • RegCloseKey.ADVAPI32(?), ref: 00B0B87E
                          • RegCloseKey.ADVAPI32(?), ref: 00B0B89C
                          • LoadLibraryA.KERNEL32(advapi32.dll), ref: 00B0B8F2
                          • GetProcAddress.KERNEL32(00000000,RegDeleteKeyExW), ref: 00B0B904
                          • RegDeleteKeyW.ADVAPI32(?,?), ref: 00B0B922
                          • FreeLibrary.KERNEL32(00000000), ref: 00B0B983
                          • RegCloseKey.ADVAPI32(00000000), ref: 00B0B994
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$Close$DeleteLibrary$AddressBuffCharConnectFreeLoadOpenProcRegistryUpperValue
                          • String ID: RegDeleteKeyExW$advapi32.dll
                          • API String ID: 146587525-4033151799
                          • Opcode ID: a01bba633c413f8fa09bf4ffebf3e457e89959b5b95f3eb74e65b1312e5a7dbb
                          • Instruction ID: eb970285cfd0070d7bc615b0f1b4babc2c9b4a4f92c3101b2656d8dd2cae8f7f
                          • Opcode Fuzzy Hash: a01bba633c413f8fa09bf4ffebf3e457e89959b5b95f3eb74e65b1312e5a7dbb
                          • Instruction Fuzzy Hash: DBC16B35208201AFD714DF24C495F2ABBE5FF84318F54859CF5AA8B2A2CB71ED45CB92
                          APIs
                          • GetDC.USER32(00000000), ref: 00B025D8
                          • CreateCompatibleBitmap.GDI32(00000000,?,?), ref: 00B025E8
                          • CreateCompatibleDC.GDI32(?), ref: 00B025F4
                          • SelectObject.GDI32(00000000,?), ref: 00B02601
                          • StretchBlt.GDI32(?,00000000,00000000,?,?,?,00000006,?,?,?,00CC0020), ref: 00B0266D
                          • GetDIBits.GDI32(?,?,00000000,00000000,00000000,00000028,00000000), ref: 00B026AC
                          • GetDIBits.GDI32(?,?,00000000,?,00000000,00000028,00000000), ref: 00B026D0
                          • SelectObject.GDI32(?,?), ref: 00B026D8
                          • DeleteObject.GDI32(?), ref: 00B026E1
                          • DeleteDC.GDI32(?), ref: 00B026E8
                          • ReleaseDC.USER32(00000000,?), ref: 00B026F3
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Object$BitsCompatibleCreateDeleteSelect$BitmapReleaseStretch
                          • String ID: (
                          • API String ID: 2598888154-3887548279
                          • Opcode ID: 236407f7137f73bc2155349f66cc7ed37cfcb6429bd173db9a5cd83d5d40a61d
                          • Instruction ID: 0fbfd9a91acc403864170d9ab1136931f79c3800fae381c80a3a6a91c98ce381
                          • Opcode Fuzzy Hash: 236407f7137f73bc2155349f66cc7ed37cfcb6429bd173db9a5cd83d5d40a61d
                          • Instruction Fuzzy Hash: DC61E275D00219EFCF04CFA4D888AAEBBF6FF48310F208569E955A7250D771A951CF50
                          APIs
                          • ___free_lconv_mon.LIBCMT ref: 00ABDAA1
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD659
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD66B
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD67D
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD68F
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD6A1
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD6B3
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD6C5
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD6D7
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD6E9
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD6FB
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD70D
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD71F
                            • Part of subcall function 00ABD63C: _free.LIBCMT ref: 00ABD731
                          • _free.LIBCMT ref: 00ABDA96
                            • Part of subcall function 00AB29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000), ref: 00AB29DE
                            • Part of subcall function 00AB29C8: GetLastError.KERNEL32(00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000,00000000), ref: 00AB29F0
                          • _free.LIBCMT ref: 00ABDAB8
                          • _free.LIBCMT ref: 00ABDACD
                          • _free.LIBCMT ref: 00ABDAD8
                          • _free.LIBCMT ref: 00ABDAFA
                          • _free.LIBCMT ref: 00ABDB0D
                          • _free.LIBCMT ref: 00ABDB1B
                          • _free.LIBCMT ref: 00ABDB26
                          • _free.LIBCMT ref: 00ABDB5E
                          • _free.LIBCMT ref: 00ABDB65
                          • _free.LIBCMT ref: 00ABDB82
                          • _free.LIBCMT ref: 00ABDB9A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free$ErrorFreeHeapLast___free_lconv_mon
                          • String ID:
                          • API String ID: 161543041-0
                          • Opcode ID: 921339c503ddfbf06274601934e45e211732a45472e6d7c2e25a0c1875aeec6c
                          • Instruction ID: a27b927b7bf38ecaf30e75b4e6ccfa324c2f3442af1d7ecd18af0515840fe100
                          • Opcode Fuzzy Hash: 921339c503ddfbf06274601934e45e211732a45472e6d7c2e25a0c1875aeec6c
                          • Instruction Fuzzy Hash: B2313D31604705AFEB21AB39E945BD6BBEDFF40350F15481AE449D7193EF31AC508724
                          APIs
                          • GetClassNameW.USER32(?,?,00000100), ref: 00AE369C
                          • _wcslen.LIBCMT ref: 00AE36A7
                          • SendMessageTimeoutW.USER32(?,?,00000101,00000000,00000002,00001388,?), ref: 00AE3797
                          • GetClassNameW.USER32(?,?,00000400), ref: 00AE380C
                          • GetDlgCtrlID.USER32(?), ref: 00AE385D
                          • GetWindowRect.USER32(?,?), ref: 00AE3882
                          • GetParent.USER32(?), ref: 00AE38A0
                          • ScreenToClient.USER32(00000000), ref: 00AE38A7
                          • GetClassNameW.USER32(?,?,00000100), ref: 00AE3921
                          • GetWindowTextW.USER32(?,?,00000400), ref: 00AE395D
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClassName$Window$ClientCtrlMessageParentRectScreenSendTextTimeout_wcslen
                          • String ID: %s%u
                          • API String ID: 4010501982-679674701
                          • Opcode ID: 057434578bd9d82e7b8a133ea4e325e6ca5d83dfe7d09136a24d728e64a78c14
                          • Instruction ID: 63e2b7191d9d8533b311f9673281e67d00b9e9b58812e686b138734a99f3eaaa
                          • Opcode Fuzzy Hash: 057434578bd9d82e7b8a133ea4e325e6ca5d83dfe7d09136a24d728e64a78c14
                          • Instruction Fuzzy Hash: 5E91C272204746AFDB18DF26C899BEAF7A8FF44350F408529F999C3191DB30EA45CB91
                          APIs
                          • GetClassNameW.USER32(?,?,00000400), ref: 00AE4994
                          • GetWindowTextW.USER32(?,?,00000400), ref: 00AE49DA
                          • _wcslen.LIBCMT ref: 00AE49EB
                          • CharUpperBuffW.USER32(?,00000000), ref: 00AE49F7
                          • _wcsstr.LIBVCRUNTIME ref: 00AE4A2C
                          • GetClassNameW.USER32(00000018,?,00000400), ref: 00AE4A64
                          • GetWindowTextW.USER32(?,?,00000400), ref: 00AE4A9D
                          • GetClassNameW.USER32(00000018,?,00000400), ref: 00AE4AE6
                          • GetClassNameW.USER32(?,?,00000400), ref: 00AE4B20
                          • GetWindowRect.USER32(?,?), ref: 00AE4B8B
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClassName$Window$Text$BuffCharRectUpper_wcslen_wcsstr
                          • String ID: ThumbnailClass
                          • API String ID: 1311036022-1241985126
                          • Opcode ID: f8b039579f48b3bb5dbd5ad9de2bbc58c390a474aab42322bb5bec2a70f33956
                          • Instruction ID: 836d595a7298707f0787da297bd7394e536067b999f1faa824377cd77c6df523
                          • Opcode Fuzzy Hash: f8b039579f48b3bb5dbd5ad9de2bbc58c390a474aab42322bb5bec2a70f33956
                          • Instruction Fuzzy Hash: 7D9189710083459BDB04DF16C985BAABBECEF88354F048469FD859B096EB34ED45CBA1
                          APIs
                          • GetMenuItemInfoW.USER32(00B51990,000000FF,00000000,00000030), ref: 00AEBFAC
                          • SetMenuItemInfoW.USER32(00B51990,00000004,00000000,00000030), ref: 00AEBFE1
                          • Sleep.KERNEL32(000001F4), ref: 00AEBFF3
                          • GetMenuItemCount.USER32(?), ref: 00AEC039
                          • GetMenuItemID.USER32(?,00000000), ref: 00AEC056
                          • GetMenuItemID.USER32(?,-00000001), ref: 00AEC082
                          • GetMenuItemID.USER32(?,?), ref: 00AEC0C9
                          • CheckMenuRadioItem.USER32(?,00000000,?,00000000,00000400), ref: 00AEC10F
                          • GetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 00AEC124
                          • SetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 00AEC145
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ItemMenu$Info$CheckCountRadioSleep
                          • String ID: 0
                          • API String ID: 1460738036-4108050209
                          • Opcode ID: af2969a33b6778d1fbea258bd99da276681987fe3375fef9269661ef913b4893
                          • Instruction ID: 8964c2a327ef33e035c18ef26cf4b23a2fd4bf1ed58985e5a3c162babb2ca9d2
                          • Opcode Fuzzy Hash: af2969a33b6778d1fbea258bd99da276681987fe3375fef9269661ef913b4893
                          • Instruction Fuzzy Hash: 81617EB090038AAFDF11DF69DD88AEEBBB9FB05364F144155E811A3291CB35AD16CB60
                          APIs
                          • RegEnumKeyExW.ADVAPI32(?,00000000,?,000000FF,00000000,00000000,00000000,?,?,?,00000000), ref: 00B0CC64
                          • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?,?,?,00000000), ref: 00B0CC8D
                          • FreeLibrary.KERNEL32(00000000,?,?,00000000), ref: 00B0CD48
                            • Part of subcall function 00B0CC34: RegCloseKey.ADVAPI32(?,?,?,00000000), ref: 00B0CCAA
                            • Part of subcall function 00B0CC34: LoadLibraryA.KERNEL32(advapi32.dll,?,?,00000000), ref: 00B0CCBD
                            • Part of subcall function 00B0CC34: GetProcAddress.KERNEL32(00000000,RegDeleteKeyExW), ref: 00B0CCCF
                            • Part of subcall function 00B0CC34: FreeLibrary.KERNEL32(00000000,?,?,00000000), ref: 00B0CD05
                            • Part of subcall function 00B0CC34: RegEnumKeyExW.ADVAPI32(?,00000000,?,000000FF,00000000,00000000,00000000,?,?,?,00000000), ref: 00B0CD28
                          • RegDeleteKeyW.ADVAPI32(?,?), ref: 00B0CCF3
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Library$EnumFree$AddressCloseDeleteLoadOpenProc
                          • String ID: RegDeleteKeyExW$advapi32.dll
                          • API String ID: 2734957052-4033151799
                          • Opcode ID: 104dc5312c8d306c7e3e098ac1548dc6eda5c95152802d61b22059e0ccc00317
                          • Instruction ID: a7e8c179af5b439886ac730822fc4b99ca753cf31743a045cad9469501a751b7
                          • Opcode Fuzzy Hash: 104dc5312c8d306c7e3e098ac1548dc6eda5c95152802d61b22059e0ccc00317
                          • Instruction Fuzzy Hash: D3316F71941129BBDB208B55DC88EFFBFBCEF45750F0042A5B906E3290DB349E45DAA0
                          APIs
                          • GetFullPathNameW.KERNEL32(?,00007FFF,?,?), ref: 00AF3D40
                          • _wcslen.LIBCMT ref: 00AF3D6D
                          • CreateDirectoryW.KERNEL32(?,00000000), ref: 00AF3D9D
                          • CreateFileW.KERNEL32(?,40000000,00000000,00000000,00000003,02200000,00000000), ref: 00AF3DBE
                          • RemoveDirectoryW.KERNEL32(?), ref: 00AF3DCE
                          • DeviceIoControl.KERNEL32(00000000,000900A4,?,?,00000000,00000000,?,00000000), ref: 00AF3E55
                          • CloseHandle.KERNEL32(00000000), ref: 00AF3E60
                          • CloseHandle.KERNEL32(00000000), ref: 00AF3E6B
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CloseCreateDirectoryHandle$ControlDeviceFileFullNamePathRemove_wcslen
                          • String ID: :$\$\??\%s
                          • API String ID: 1149970189-3457252023
                          • Opcode ID: 4e77cd73d9adda5151e09837c3021deadcef54c16a8a2ed00c6aa8c31606b16a
                          • Instruction ID: b31eb17e465dd42d4c7673d36a3f677f90a6f4b6bd3cf10679bf8f016a6d6d31
                          • Opcode Fuzzy Hash: 4e77cd73d9adda5151e09837c3021deadcef54c16a8a2ed00c6aa8c31606b16a
                          • Instruction Fuzzy Hash: FF31AF72A40219ABDF209FA0DC49FEF3BBDEF89740F5040A5F619D60A0EB7097448B64
                          APIs
                          • timeGetTime.WINMM ref: 00AEE6B4
                            • Part of subcall function 00A9E551: timeGetTime.WINMM(?,?,00AEE6D4), ref: 00A9E555
                          • Sleep.KERNEL32(0000000A), ref: 00AEE6E1
                          • EnumThreadWindows.USER32(?,Function_0006E665,00000000), ref: 00AEE705
                          • FindWindowExW.USER32(00000000,00000000,BUTTON,00000000), ref: 00AEE727
                          • SetActiveWindow.USER32 ref: 00AEE746
                          • SendMessageW.USER32(00000000,000000F5,00000000,00000000), ref: 00AEE754
                          • SendMessageW.USER32(00000010,00000000,00000000), ref: 00AEE773
                          • Sleep.KERNEL32(000000FA), ref: 00AEE77E
                          • IsWindow.USER32 ref: 00AEE78A
                          • EndDialog.USER32(00000000), ref: 00AEE79B
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$MessageSendSleepTimetime$ActiveDialogEnumFindThreadWindows
                          • String ID: BUTTON
                          • API String ID: 1194449130-3405671355
                          • Opcode ID: a8c2da6f69e5c4a3beb534702e38b18a351c038a3ced3b04c6075bfbce06b17b
                          • Instruction ID: ae5340bb6df2585cb144b28cf8cc2d8a4c4c8dc76ec559b30660d53d09822db9
                          • Opcode Fuzzy Hash: a8c2da6f69e5c4a3beb534702e38b18a351c038a3ced3b04c6075bfbce06b17b
                          • Instruction Fuzzy Hash: EE21A2B0280385BFEB009F22EC89B663F6AF75634AF504865F505831B1DF71AC108B25
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • mciSendStringW.WINMM(status PlayMe mode,?,00000100,00000000), ref: 00AEEA5D
                          • mciSendStringW.WINMM(close PlayMe,00000000,00000000,00000000), ref: 00AEEA73
                          • mciSendStringW.WINMM(?,00000000,00000000,00000000), ref: 00AEEA84
                          • mciSendStringW.WINMM(play PlayMe wait,00000000,00000000,00000000), ref: 00AEEA96
                          • mciSendStringW.WINMM(play PlayMe,00000000,00000000,00000000), ref: 00AEEAA7
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: SendString$_wcslen
                          • String ID: alias PlayMe$close PlayMe$open $play PlayMe$play PlayMe wait$status PlayMe mode
                          • API String ID: 2420728520-1007645807
                          • Opcode ID: 44335ba0be477467f3710686075d7c42d00257e5b97dcff0a4b3deb97ddeddee
                          • Instruction ID: 3de6210b5fb33fc1265e32b630ad58da9c072252730ceb795986b46b8f332a99
                          • Opcode Fuzzy Hash: 44335ba0be477467f3710686075d7c42d00257e5b97dcff0a4b3deb97ddeddee
                          • Instruction Fuzzy Hash: E1115131A9026979D720F7A2DD4ADFF6BBCEBD6B40F400469B401A20E1EEB00A05D6B1
                          APIs
                          • GetKeyboardState.USER32(?), ref: 00AEA012
                          • SetKeyboardState.USER32(?), ref: 00AEA07D
                          • GetAsyncKeyState.USER32(000000A0), ref: 00AEA09D
                          • GetKeyState.USER32(000000A0), ref: 00AEA0B4
                          • GetAsyncKeyState.USER32(000000A1), ref: 00AEA0E3
                          • GetKeyState.USER32(000000A1), ref: 00AEA0F4
                          • GetAsyncKeyState.USER32(00000011), ref: 00AEA120
                          • GetKeyState.USER32(00000011), ref: 00AEA12E
                          • GetAsyncKeyState.USER32(00000012), ref: 00AEA157
                          • GetKeyState.USER32(00000012), ref: 00AEA165
                          • GetAsyncKeyState.USER32(0000005B), ref: 00AEA18E
                          • GetKeyState.USER32(0000005B), ref: 00AEA19C
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: State$Async$Keyboard
                          • String ID:
                          • API String ID: 541375521-0
                          • Opcode ID: c2f07bed68065f22c28ad7a80d19eaae8ef4ac142486f6db4fa7d149eca17cf3
                          • Instruction ID: 36b76ebbc7507b0692e40402b3345dbc0ef93cc17ed1c51697c62cbbfb36e3a8
                          • Opcode Fuzzy Hash: c2f07bed68065f22c28ad7a80d19eaae8ef4ac142486f6db4fa7d149eca17cf3
                          • Instruction Fuzzy Hash: 6351BA30A047C829FB35EB6289157EBBFB59F22380F088599D5C2571C2DA54BA4CC766
                          APIs
                          • GetDlgItem.USER32(?,00000001), ref: 00AE5CE2
                          • GetWindowRect.USER32(00000000,?), ref: 00AE5CFB
                          • MoveWindow.USER32(?,0000000A,00000004,?,?,00000004,00000000), ref: 00AE5D59
                          • GetDlgItem.USER32(?,00000002), ref: 00AE5D69
                          • GetWindowRect.USER32(00000000,?), ref: 00AE5D7B
                          • MoveWindow.USER32(?,?,00000004,00000000,?,00000004,00000000), ref: 00AE5DCF
                          • GetDlgItem.USER32(?,000003E9), ref: 00AE5DDD
                          • GetWindowRect.USER32(00000000,?), ref: 00AE5DEF
                          • MoveWindow.USER32(?,0000000A,00000000,?,00000004,00000000), ref: 00AE5E31
                          • GetDlgItem.USER32(?,000003EA), ref: 00AE5E44
                          • MoveWindow.USER32(00000000,0000000A,0000000A,?,-00000005,00000000), ref: 00AE5E5A
                          • InvalidateRect.USER32(?,00000000,00000001), ref: 00AE5E67
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$ItemMoveRect$Invalidate
                          • String ID:
                          • API String ID: 3096461208-0
                          • Opcode ID: 47d5e379aea0d8ab258e806fb954a6188a8d6659fc40954be13ad667f80f4970
                          • Instruction ID: b9787a5aa7cbd3f319b3f9461d5f8fc919d04765253f8ced120d8b164c7547d0
                          • Opcode Fuzzy Hash: 47d5e379aea0d8ab258e806fb954a6188a8d6659fc40954be13ad667f80f4970
                          • Instruction Fuzzy Hash: CB510BB1E40609AFDF18CF69DD89AAEBBB5EB48314F548129F915E7290DB709E00CB50
                          APIs
                            • Part of subcall function 00A98F62: InvalidateRect.USER32(?,00000000,00000001,?,?,?,00A98BE8,?,00000000,?,?,?,?,00A98BBA,00000000,?), ref: 00A98FC5
                          • DestroyWindow.USER32(?), ref: 00A98C81
                          • KillTimer.USER32(00000000,?,?,?,?,00A98BBA,00000000,?), ref: 00A98D1B
                          • DestroyAcceleratorTable.USER32(00000000), ref: 00AD6973
                          • ImageList_Destroy.COMCTL32(00000000,?,?,?,?,?,?,00000000,?,?,?,?,00A98BBA,00000000,?), ref: 00AD69A1
                          • ImageList_Destroy.COMCTL32(?,?,?,?,?,?,?,00000000,?,?,?,?,00A98BBA,00000000,?), ref: 00AD69B8
                          • ImageList_Destroy.COMCTL32(00000000,?,?,?,?,?,?,?,?,00000000,?,?,?,?,00A98BBA,00000000), ref: 00AD69D4
                          • DeleteObject.GDI32(00000000), ref: 00AD69E6
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Destroy$ImageList_$AcceleratorDeleteInvalidateKillObjectRectTableTimerWindow
                          • String ID:
                          • API String ID: 641708696-0
                          • Opcode ID: f5d99702383586dc0b2d38cf412655252e0d1eface4a0d8f24f4f8e370c0e7f1
                          • Instruction ID: 6c60d689c445ade85e7134414f39a42944cb0a1b1f540366b48f7682c044a54b
                          • Opcode Fuzzy Hash: f5d99702383586dc0b2d38cf412655252e0d1eface4a0d8f24f4f8e370c0e7f1
                          • Instruction Fuzzy Hash: 8D619A30602700DFDF219F18CA58B697BF1FB46312F548959E0829B6A0CB79AD81CF90
                          APIs
                            • Part of subcall function 00A99944: GetWindowLongW.USER32(?,000000EB), ref: 00A99952
                          • GetSysColor.USER32(0000000F), ref: 00A99862
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ColorLongWindow
                          • String ID:
                          • API String ID: 259745315-0
                          • Opcode ID: 101e05584f6b205a4c3ad175a04856a0d889b6aeaeb54599c760456482cc6164
                          • Instruction ID: 539ddf47f6e2c974e04df7e6327e66dbfc7c64883ce9805506ca2e5259be129c
                          • Opcode Fuzzy Hash: 101e05584f6b205a4c3ad175a04856a0d889b6aeaeb54599c760456482cc6164
                          • Instruction Fuzzy Hash: 3841A131244640BFDF205F3C9C88BBA3BA5AB06331F54861DF9A2972E1EB319C42DB11
                          APIs
                          • GetModuleHandleW.KERNEL32(00000000,?,00000FFF,00000001,00000000,?,?,00ACF7F8,00000001,0000138C,00000001,?,00000001,00000000,?,?), ref: 00AE9717
                          • LoadStringW.USER32(00000000,?,00ACF7F8,00000001), ref: 00AE9720
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • GetModuleHandleW.KERNEL32(00000000,00000001,?,00000FFF,?,?,00ACF7F8,00000001,0000138C,00000001,?,00000001,00000000,?,?,00000000), ref: 00AE9742
                          • LoadStringW.USER32(00000000,?,00ACF7F8,00000001), ref: 00AE9745
                          • MessageBoxW.USER32(00000000,00000000,?,00011010), ref: 00AE9866
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: HandleLoadModuleString$Message_wcslen
                          • String ID: Error: $%s (%d) : ==> %s: %s %s$Line %d (File "%s"):$Line %d:$^ ERROR
                          • API String ID: 747408836-2268648507
                          • Opcode ID: 902412c40225de4f6ee1dedda4c6050ebe8e316be5edf67290bdc9f967518346
                          • Instruction ID: c7b6dea2fd2338b1b61f43260b7bd6d4015ab5e09d1a22b80faa0b87c131cb28
                          • Opcode Fuzzy Hash: 902412c40225de4f6ee1dedda4c6050ebe8e316be5edf67290bdc9f967518346
                          • Instruction Fuzzy Hash: 8B413972900209AADF04FBE1CE86EEFB778EF15740F540065F605760A2EB256F49CBA1
                          APIs
                            • Part of subcall function 00A86B57: _wcslen.LIBCMT ref: 00A86B6A
                          • WNetAddConnection2W.MPR(?,?,?,00000000), ref: 00AE07A2
                          • RegConnectRegistryW.ADVAPI32(?,80000002,?), ref: 00AE07BE
                          • RegOpenKeyExW.ADVAPI32(?,?,00000000,00020019,?,?,SOFTWARE\Classes\), ref: 00AE07DA
                          • RegQueryValueExW.ADVAPI32(?,00000000,00000000,00000000,?,?,?,SOFTWARE\Classes\), ref: 00AE0804
                          • CLSIDFromString.OLE32(?,000001FE,?,SOFTWARE\Classes\), ref: 00AE082C
                          • RegCloseKey.ADVAPI32(?,?,SOFTWARE\Classes\), ref: 00AE0837
                          • RegCloseKey.ADVAPI32(?,?,SOFTWARE\Classes\), ref: 00AE083C
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Close$ConnectConnection2FromOpenQueryRegistryStringValue_wcslen
                          • String ID: SOFTWARE\Classes\$\CLSID$\IPC$
                          • API String ID: 323675364-22481851
                          • Opcode ID: c37257b2ad16f5fce27d5824d843287fbd3a9e003b08f160003282fcda22bb69
                          • Instruction ID: 3eb0a83ea9400bda350efba4d293edcc320c589497ce2b3a82468510c888287b
                          • Opcode Fuzzy Hash: c37257b2ad16f5fce27d5824d843287fbd3a9e003b08f160003282fcda22bb69
                          • Instruction Fuzzy Hash: D8413672C10229ABDF21EFA4DC85DEEB7B8FF14340F444129E901A71A1EB709E44CBA0
                          APIs
                          • MoveWindow.USER32(?,?,?,000000FF,000000FF,00000000,?,?,000000FF,000000FF,?,?,static,00000000,00000000,?), ref: 00B1403B
                          • CreateCompatibleDC.GDI32(00000000), ref: 00B14042
                          • SendMessageW.USER32(?,00000173,00000000,00000000), ref: 00B14055
                          • SelectObject.GDI32(00000000,00000000), ref: 00B1405D
                          • GetPixel.GDI32(00000000,00000000,00000000), ref: 00B14068
                          • DeleteDC.GDI32(00000000), ref: 00B14072
                          • GetWindowLongW.USER32(?,000000EC), ref: 00B1407C
                          • SetLayeredWindowAttributes.USER32(?,?,00000000,00000001,?,00000000,?), ref: 00B14092
                          • DestroyWindow.USER32(?,?,?,000000FF,000000FF,?,?,static,00000000,00000000,?,?,00000000,00000000,?), ref: 00B1409E
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$AttributesCompatibleCreateDeleteDestroyLayeredLongMessageMoveObjectPixelSelectSend
                          • String ID: static
                          • API String ID: 2559357485-2160076837
                          • Opcode ID: 7992d29e18439bc08681610df50d7fd32c46211edf13494552cb53d3c285f175
                          • Instruction ID: d833afd53b70fa8674016b2fe2162acc53c83ab21a6eb48fae0a17409fdfb599
                          • Opcode Fuzzy Hash: 7992d29e18439bc08681610df50d7fd32c46211edf13494552cb53d3c285f175
                          • Instruction Fuzzy Hash: 41317A32540219BBDF219FA4CC09FDA3FA9FF0D720F514250FA18A60A0CB75D860DB50
                          APIs
                          • VariantInit.OLEAUT32(?), ref: 00B03C5C
                          • CoInitialize.OLE32(00000000), ref: 00B03C8A
                          • CoUninitialize.OLE32 ref: 00B03C94
                          • _wcslen.LIBCMT ref: 00B03D2D
                          • GetRunningObjectTable.OLE32(00000000,?), ref: 00B03DB1
                          • SetErrorMode.KERNEL32(00000001,00000029), ref: 00B03ED5
                          • CoGetInstanceFromFile.OLE32(00000000,?,00000000,00000015,00000002,?,00000001,?), ref: 00B03F0E
                          • CoGetObject.OLE32(?,00000000,00B1FB98,?), ref: 00B03F2D
                          • SetErrorMode.KERNEL32(00000000), ref: 00B03F40
                          • SetErrorMode.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 00B03FC4
                          • VariantClear.OLEAUT32(?), ref: 00B03FD8
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorMode$ObjectVariant$ClearFileFromInitInitializeInstanceRunningTableUninitialize_wcslen
                          • String ID:
                          • API String ID: 429561992-0
                          • Opcode ID: 0e8e7a36c8a90c11b85345ea7fe026d581accc1de5e3e71c1f1e8b7b2d461b58
                          • Instruction ID: 6a4f36ba264e1f9c9be5fad0d5758878501e333d280804aac711621c67f7a423
                          • Opcode Fuzzy Hash: 0e8e7a36c8a90c11b85345ea7fe026d581accc1de5e3e71c1f1e8b7b2d461b58
                          • Instruction Fuzzy Hash: B2C158716083019FD700DF68C98896BBBE9FF89B44F14499DF98A9B290DB31ED05CB52
                          APIs
                          • CoInitialize.OLE32(00000000), ref: 00AF7AF3
                          • SHGetSpecialFolderLocation.SHELL32(00000000,00000000,?), ref: 00AF7B8F
                          • SHGetDesktopFolder.SHELL32(?), ref: 00AF7BA3
                          • CoCreateInstance.OLE32(00B1FD08,00000000,00000001,00B46E6C,?), ref: 00AF7BEF
                          • SHCreateShellItem.SHELL32(00000000,00000000,?,00000003), ref: 00AF7C74
                          • CoTaskMemFree.OLE32(?,?), ref: 00AF7CCC
                          • SHBrowseForFolderW.SHELL32(?), ref: 00AF7D57
                          • SHGetPathFromIDListW.SHELL32(00000000,?), ref: 00AF7D7A
                          • CoTaskMemFree.OLE32(00000000), ref: 00AF7D81
                          • CoTaskMemFree.OLE32(00000000), ref: 00AF7DD6
                          • CoUninitialize.OLE32 ref: 00AF7DDC
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FolderFreeTask$Create$BrowseDesktopFromInitializeInstanceItemListLocationPathShellSpecialUninitialize
                          • String ID:
                          • API String ID: 2762341140-0
                          • Opcode ID: aa387e7a807b47f1da173c1d34bc58d4a0c79a7515f85171c768b7a14ff33fb8
                          • Instruction ID: 2d1002ffbb8d72a92cb3f8b6c57bfb1cfafa060b6261ff331a64f90359242507
                          • Opcode Fuzzy Hash: aa387e7a807b47f1da173c1d34bc58d4a0c79a7515f85171c768b7a14ff33fb8
                          • Instruction Fuzzy Hash: 13C11975A04109AFCB14DFA4C884DAEBBF9FF49304B148499F91A9B361DB30EE45CB90
                          APIs
                          • SendMessageW.USER32(?,00000158,000000FF,00000158), ref: 00B15504
                          • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 00B15515
                          • CharNextW.USER32(00000158), ref: 00B15544
                          • SendMessageW.USER32(?,0000014B,00000000,00000000), ref: 00B15585
                          • SendMessageW.USER32(?,00000158,000000FF,0000014E), ref: 00B1559B
                          • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 00B155AC
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$CharNext
                          • String ID:
                          • API String ID: 1350042424-0
                          • Opcode ID: 6f712d179ee1abbb77e4474f2ee6a2326de9cebd4f196f2f0f3ec02da869527b
                          • Instruction ID: da4fb2cf9f83562637600dad741cbe5de6e2624434fb342e5726de11f71b1358
                          • Opcode Fuzzy Hash: 6f712d179ee1abbb77e4474f2ee6a2326de9cebd4f196f2f0f3ec02da869527b
                          • Instruction Fuzzy Hash: F8619170900608EFDF209F54CC85AFE7BF9EB89761F908185F525AB294D7709AC0DB61
                          APIs
                          • SafeArrayAllocDescriptorEx.OLEAUT32(0000000C,?,?), ref: 00ADFAAF
                          • SafeArrayAllocData.OLEAUT32(?), ref: 00ADFB08
                          • VariantInit.OLEAUT32(?), ref: 00ADFB1A
                          • SafeArrayAccessData.OLEAUT32(?,?), ref: 00ADFB3A
                          • VariantCopy.OLEAUT32(?,?), ref: 00ADFB8D
                          • SafeArrayUnaccessData.OLEAUT32(?), ref: 00ADFBA1
                          • VariantClear.OLEAUT32(?), ref: 00ADFBB6
                          • SafeArrayDestroyData.OLEAUT32(?), ref: 00ADFBC3
                          • SafeArrayDestroyDescriptor.OLEAUT32(?), ref: 00ADFBCC
                          • VariantClear.OLEAUT32(?), ref: 00ADFBDE
                          • SafeArrayDestroyDescriptor.OLEAUT32(?), ref: 00ADFBE9
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ArraySafe$DataVariant$DescriptorDestroy$AllocClear$AccessCopyInitUnaccess
                          • String ID:
                          • API String ID: 2706829360-0
                          • Opcode ID: 8aa1c35b41f1135fb6433f372d5fbca1d2acb6b1b32033bdbe6e60eff54fd41b
                          • Instruction ID: 8d95a49ff1063c929d5641cdb6cdfee287d59a64fa78c88bf2d4d549f308acd6
                          • Opcode Fuzzy Hash: 8aa1c35b41f1135fb6433f372d5fbca1d2acb6b1b32033bdbe6e60eff54fd41b
                          • Instruction Fuzzy Hash: A3414135A042199FDB00DFA8D8549EEBFB9EF48354F50806AE947A7361DB30A945CFA0
                          APIs
                          • GetKeyboardState.USER32(?), ref: 00AE9CA1
                          • GetAsyncKeyState.USER32(000000A0), ref: 00AE9D22
                          • GetKeyState.USER32(000000A0), ref: 00AE9D3D
                          • GetAsyncKeyState.USER32(000000A1), ref: 00AE9D57
                          • GetKeyState.USER32(000000A1), ref: 00AE9D6C
                          • GetAsyncKeyState.USER32(00000011), ref: 00AE9D84
                          • GetKeyState.USER32(00000011), ref: 00AE9D96
                          • GetAsyncKeyState.USER32(00000012), ref: 00AE9DAE
                          • GetKeyState.USER32(00000012), ref: 00AE9DC0
                          • GetAsyncKeyState.USER32(0000005B), ref: 00AE9DD8
                          • GetKeyState.USER32(0000005B), ref: 00AE9DEA
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: State$Async$Keyboard
                          • String ID:
                          • API String ID: 541375521-0
                          • Opcode ID: 5e742045dd96577b84df19f1196685d5c7a05340071868b9ef249b99f8440573
                          • Instruction ID: 9987e9ac32632df8c290c9ab8fcac1c0f25c81a407ab97b18b03bbf02c41affc
                          • Opcode Fuzzy Hash: 5e742045dd96577b84df19f1196685d5c7a05340071868b9ef249b99f8440573
                          • Instruction Fuzzy Hash: FB41F7345047DA6DFF30976288443F7BEE16F21344F48805ADAC6575C2EBA4A9C8C7A2
                          APIs
                          • WSAStartup.WSOCK32(00000101,?), ref: 00B005BC
                          • inet_addr.WSOCK32(?), ref: 00B0061C
                          • gethostbyname.WSOCK32(?), ref: 00B00628
                          • IcmpCreateFile.IPHLPAPI ref: 00B00636
                          • IcmpSendEcho.IPHLPAPI(?,?,?,00000005,00000000,?,00000029,00000FA0), ref: 00B006C6
                          • IcmpSendEcho.IPHLPAPI(00000000,00000000,?,00000005,00000000,?,00000029,00000FA0), ref: 00B006E5
                          • IcmpCloseHandle.IPHLPAPI(?), ref: 00B007B9
                          • WSACleanup.WSOCK32 ref: 00B007BF
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Icmp$EchoSend$CleanupCloseCreateFileHandleStartupgethostbynameinet_addr
                          • String ID: Ping
                          • API String ID: 1028309954-2246546115
                          • Opcode ID: cef7a40cd78dff839ddd8c0c8a95255fbf51371969f271366b9824d05c12b763
                          • Instruction ID: 2a299c2353ae6b5b01f84c9f5b8eef6348d41af5dbb1fee34eafe5e847eb4c1f
                          • Opcode Fuzzy Hash: cef7a40cd78dff839ddd8c0c8a95255fbf51371969f271366b9824d05c12b763
                          • Instruction Fuzzy Hash: DB91A0356182019FD720EF15C988F1ABFE0EF45318F1485A9F46A9B6A2CB34ED45CF91
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$BuffCharLower
                          • String ID: cdecl$none$stdcall$winapi
                          • API String ID: 707087890-567219261
                          • Opcode ID: bf6b9ee75be8aa36bed365100ec6fa7cbfa9bbd63af8f9f39ddcdd7ffb73c4dd
                          • Instruction ID: ee20b571c686cdb141eca6c226e26c7d3dbf46cb454085f4f37c3da10f453971
                          • Opcode Fuzzy Hash: bf6b9ee75be8aa36bed365100ec6fa7cbfa9bbd63af8f9f39ddcdd7ffb73c4dd
                          • Instruction Fuzzy Hash: FF519131A005169BCF14DF68C9808BEBBE6FF65720B2542A9E4A6E72C4DF30DE40C790
                          APIs
                          • CoInitialize.OLE32 ref: 00B03774
                          • CoUninitialize.OLE32 ref: 00B0377F
                          • CoCreateInstance.OLE32(?,00000000,00000017,00B1FB78,?), ref: 00B037D9
                          • IIDFromString.OLE32(?,?), ref: 00B0384C
                          • VariantInit.OLEAUT32(?), ref: 00B038E4
                          • VariantClear.OLEAUT32(?), ref: 00B03936
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Variant$ClearCreateFromInitInitializeInstanceStringUninitialize
                          • String ID: Failed to create object$Invalid parameter$NULL Pointer assignment
                          • API String ID: 636576611-1287834457
                          • Opcode ID: 17b67178a7c4cacbbd825bfca415490ae1baedd4b2865dc00bd6480dc062ed3c
                          • Instruction ID: 16f6cb9824d35892059359dffaf7be1fe66f59d7066c2357df68145bc61ead4f
                          • Opcode Fuzzy Hash: 17b67178a7c4cacbbd825bfca415490ae1baedd4b2865dc00bd6480dc062ed3c
                          • Instruction Fuzzy Hash: 9A61A370608301AFD711DF54C989F6ABBE8FF49B14F104989F5859B291D770EE48CB92
                          APIs
                          • LoadStringW.USER32(00000066,?,00000FFF,?), ref: 00AF33CF
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • LoadStringW.USER32(00000072,?,00000FFF,?), ref: 00AF33F0
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: LoadString$_wcslen
                          • String ID: Error: $"%s" (%d) : ==> %s:$"%s" (%d) : ==> %s:%s%s$Incorrect parameters to object property !$Line %d (File "%s"):$^ ERROR
                          • API String ID: 4099089115-3080491070
                          • Opcode ID: 2fbfbd7c9bbccf3fe2a09d264571932432549a7327d87583e63422e0c9664fca
                          • Instruction ID: 27c2ce8c49ae04d51a130435cea58fc9a74b5ccf3d86866e7b54d2f47fc53918
                          • Opcode Fuzzy Hash: 2fbfbd7c9bbccf3fe2a09d264571932432549a7327d87583e63422e0c9664fca
                          • Instruction Fuzzy Hash: 35517B72900209BADF14EBE0CE56EFEB7B8EF14740F1444A5F505720A2EB252F58DB61
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$BuffCharUpper
                          • String ID: APPEND$EXISTS$KEYS$REMOVE
                          • API String ID: 1256254125-769500911
                          • Opcode ID: d81b111fa894a2695e89ca815844d6c346a233d5a460f79eda2d929567599e28
                          • Instruction ID: a90fc1e335291cb91617f49d451905cbdd16effe949481fd3373ec8da7075f0a
                          • Opcode Fuzzy Hash: d81b111fa894a2695e89ca815844d6c346a233d5a460f79eda2d929567599e28
                          • Instruction Fuzzy Hash: 45411832A100679BCB206F7ECD945BFB7B5AFA1754B244529E421DB284F731CD81C7A0
                          APIs
                          • SetErrorMode.KERNEL32(00000001), ref: 00AF53A0
                          • GetDiskFreeSpaceW.KERNEL32(?,?,?,?,?,00000002,00000001), ref: 00AF5416
                          • GetLastError.KERNEL32 ref: 00AF5420
                          • SetErrorMode.KERNEL32(00000000,READY), ref: 00AF54A7
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Error$Mode$DiskFreeLastSpace
                          • String ID: INVALID$NOTREADY$READONLY$READY$UNKNOWN
                          • API String ID: 4194297153-14809454
                          • Opcode ID: b8261a329d86d1a1fbfbeb7a3beea92b6d6258dc5d712901a6819da7e1490afa
                          • Instruction ID: ae4787d808a1d06cfa7c8952798de3f12869e3b763ebb2d51b64e76e767133e7
                          • Opcode Fuzzy Hash: b8261a329d86d1a1fbfbeb7a3beea92b6d6258dc5d712901a6819da7e1490afa
                          • Instruction Fuzzy Hash: 71319F75E006099FD710DFA8C584ABABBB5EF05306F148069F605DB292DB31DE82CBA1
                          APIs
                          • CreateMenu.USER32 ref: 00B13C79
                          • SetMenu.USER32(?,00000000), ref: 00B13C88
                          • GetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 00B13D10
                          • IsMenu.USER32(?), ref: 00B13D24
                          • CreatePopupMenu.USER32 ref: 00B13D2E
                          • InsertMenuItemW.USER32(?,?,00000001,00000030), ref: 00B13D5B
                          • DrawMenuBar.USER32 ref: 00B13D63
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Menu$CreateItem$DrawInfoInsertPopup
                          • String ID: 0$F
                          • API String ID: 161812096-3044882817
                          • Opcode ID: 2257f957548198ef77dc086a2e0e4ed7fe4486f5bf1bf247019bc1dfb46f490c
                          • Instruction ID: 43c85edb0cf309fa80f3b2f06c1e6fcd30ede949e45ebd8ea01b73fcf1ae2b72
                          • Opcode Fuzzy Hash: 2257f957548198ef77dc086a2e0e4ed7fe4486f5bf1bf247019bc1dfb46f490c
                          • Instruction Fuzzy Hash: 15418A74A01209EFDB14CF64E885BEA7BF6FF49304F544068E91697360EB30AA10CB90
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00AE3CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00AE3CCA
                          • SendMessageW.USER32(?,0000018C,000000FF,00020000), ref: 00AE1F64
                          • GetDlgCtrlID.USER32 ref: 00AE1F6F
                          • GetParent.USER32 ref: 00AE1F8B
                          • SendMessageW.USER32(00000000,?,00000111,?), ref: 00AE1F8E
                          • GetDlgCtrlID.USER32(?), ref: 00AE1F97
                          • GetParent.USER32(?), ref: 00AE1FAB
                          • SendMessageW.USER32(00000000,?,00000111,?), ref: 00AE1FAE
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$CtrlParent$ClassName_wcslen
                          • String ID: ComboBox$ListBox
                          • API String ID: 711023334-1403004172
                          • Opcode ID: 869a3598a4d9ce246c2b7afae85305d7bef2d5f68d05a2c0e47abc348100ded7
                          • Instruction ID: 2680076f29887799beb794f608d82be819ed3d655fff18587d135c222fadddcd
                          • Opcode Fuzzy Hash: 869a3598a4d9ce246c2b7afae85305d7bef2d5f68d05a2c0e47abc348100ded7
                          • Instruction Fuzzy Hash: D321D171940214BFCF04AFA1CC85DFEBBB8EF05310F104156F961A72A1DB359918DBA0
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00AE3CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00AE3CCA
                          • SendMessageW.USER32(?,00000186,00020000,00000000), ref: 00AE2043
                          • GetDlgCtrlID.USER32 ref: 00AE204E
                          • GetParent.USER32 ref: 00AE206A
                          • SendMessageW.USER32(00000000,?,00000111,?), ref: 00AE206D
                          • GetDlgCtrlID.USER32(?), ref: 00AE2076
                          • GetParent.USER32(?), ref: 00AE208A
                          • SendMessageW.USER32(00000000,?,00000111,?), ref: 00AE208D
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$CtrlParent$ClassName_wcslen
                          • String ID: ComboBox$ListBox
                          • API String ID: 711023334-1403004172
                          • Opcode ID: edbda34ff1eb531d8bfaa7414cf0fc9f4400fec5f5687ce6c8e63c812bc4c369
                          • Instruction ID: 8f448849d15e069677618622a396f8f0813c16945f7ce7b376eca1d17046d5cd
                          • Opcode Fuzzy Hash: edbda34ff1eb531d8bfaa7414cf0fc9f4400fec5f5687ce6c8e63c812bc4c369
                          • Instruction Fuzzy Hash: D921F3B1940218BFCF11AFA1CC85EFEBFB8EF09300F104045F951A71A1DA758918DB60
                          APIs
                          • SendMessageW.USER32(?,0000101F,00000000,00000000), ref: 00B13A9D
                          • SendMessageW.USER32(00000000,?,0000101F,00000000), ref: 00B13AA0
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B13AC7
                          • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00B13AEA
                          • SendMessageW.USER32(?,0000104D,00000000,00000007), ref: 00B13B62
                          • SendMessageW.USER32(?,00001074,00000000,00000007), ref: 00B13BAC
                          • SendMessageW.USER32(?,00001057,00000000,00000000), ref: 00B13BC7
                          • SendMessageW.USER32(?,0000101D,00001004,00000000), ref: 00B13BE2
                          • SendMessageW.USER32(?,0000101E,00001004,00000000), ref: 00B13BF6
                          • SendMessageW.USER32(?,00001008,00000000,00000007), ref: 00B13C13
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$LongWindow
                          • String ID:
                          • API String ID: 312131281-0
                          • Opcode ID: 511b5a2263af9db45be409f2c885d119b076a8419d2bd7c2955e5c9b4d48c123
                          • Instruction ID: bd7e74062b76cdc4631d6d3226109617229da247a9d91b2760b126f3cb2e3884
                          • Opcode Fuzzy Hash: 511b5a2263af9db45be409f2c885d119b076a8419d2bd7c2955e5c9b4d48c123
                          • Instruction Fuzzy Hash: F3615B75900248AFDB10DFA8CC81FEE77F8EB09714F104199FA15A72A1D774AE85DB50
                          APIs
                          • GetCurrentThreadId.KERNEL32 ref: 00AEB151
                          • GetForegroundWindow.USER32(00000000,?,?,?,?,?,00AEA1E1,?,00000001), ref: 00AEB165
                          • GetWindowThreadProcessId.USER32(00000000), ref: 00AEB16C
                          • AttachThreadInput.USER32(00000000,00000000,00000001,?,?,?,?,?,00AEA1E1,?,00000001), ref: 00AEB17B
                          • GetWindowThreadProcessId.USER32(?,00000000), ref: 00AEB18D
                          • AttachThreadInput.USER32(?,00000000,00000001,?,?,?,?,?,00AEA1E1,?,00000001), ref: 00AEB1A6
                          • AttachThreadInput.USER32(00000000,00000000,00000001,?,?,?,?,?,00AEA1E1,?,00000001), ref: 00AEB1B8
                          • AttachThreadInput.USER32(00000000,00000000,?,?,?,?,?,00AEA1E1,?,00000001), ref: 00AEB1FD
                          • AttachThreadInput.USER32(?,?,00000000,?,?,?,?,?,00AEA1E1,?,00000001), ref: 00AEB212
                          • AttachThreadInput.USER32(00000000,?,00000000,?,?,?,?,?,00AEA1E1,?,00000001), ref: 00AEB21D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Thread$AttachInput$Window$Process$CurrentForeground
                          • String ID:
                          • API String ID: 2156557900-0
                          • Opcode ID: 3bb40374342963d48e786b3cc43b9a87dadfe54ea147bf1fff8a3ce3eab12db3
                          • Instruction ID: 87f2008ab10391ec8a6df669d8b0f644966dbc8399be626fb4a394ee4e968b6c
                          • Opcode Fuzzy Hash: 3bb40374342963d48e786b3cc43b9a87dadfe54ea147bf1fff8a3ce3eab12db3
                          • Instruction Fuzzy Hash: A331BB75560344BFDB129F25DC58BAF7BA9BF517A2F648008FA00D72A0DBB49A408F74
                          APIs
                          • _free.LIBCMT ref: 00AB2C94
                            • Part of subcall function 00AB29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000), ref: 00AB29DE
                            • Part of subcall function 00AB29C8: GetLastError.KERNEL32(00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000,00000000), ref: 00AB29F0
                          • _free.LIBCMT ref: 00AB2CA0
                          • _free.LIBCMT ref: 00AB2CAB
                          • _free.LIBCMT ref: 00AB2CB6
                          • _free.LIBCMT ref: 00AB2CC1
                          • _free.LIBCMT ref: 00AB2CCC
                          • _free.LIBCMT ref: 00AB2CD7
                          • _free.LIBCMT ref: 00AB2CE2
                          • _free.LIBCMT ref: 00AB2CED
                          • _free.LIBCMT ref: 00AB2CFB
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free$ErrorFreeHeapLast
                          • String ID:
                          • API String ID: 776569668-0
                          • Opcode ID: 50c223c0a47512d6f9cae30164502de825c919affc2e5dcb679888b71b846d1c
                          • Instruction ID: b81bf8882f4cef83c85d38486ea20b9c05f3509535c971f7694da3c79e112ea6
                          • Opcode Fuzzy Hash: 50c223c0a47512d6f9cae30164502de825c919affc2e5dcb679888b71b846d1c
                          • Instruction Fuzzy Hash: 5F114676510108BFCB02EF54DA42EDD3BA9FF45350F5149A6F9485B222DA31EE509B90
                          APIs
                          • GetCurrentDirectoryW.KERNEL32(00007FFF,?), ref: 00AF7FAD
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00AF7FC1
                          • GetFileAttributesW.KERNEL32(?), ref: 00AF7FEB
                          • SetFileAttributesW.KERNEL32(?,00000000), ref: 00AF8005
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00AF8017
                          • SetCurrentDirectoryW.KERNEL32(?), ref: 00AF8060
                          • SetCurrentDirectoryW.KERNEL32(?,?,?,?,?), ref: 00AF80B0
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CurrentDirectory$AttributesFile
                          • String ID: *.*
                          • API String ID: 769691225-438819550
                          • Opcode ID: 40f605e9f8f7c712e84caa7bcfd3ac2b86eeb4b7d01e8f1156fa11f3f871c8d9
                          • Instruction ID: 285d4c5ac6ff0f111153e589cebee56ef2d021db9216dafebb9d64201b558946
                          • Opcode Fuzzy Hash: 40f605e9f8f7c712e84caa7bcfd3ac2b86eeb4b7d01e8f1156fa11f3f871c8d9
                          • Instruction Fuzzy Hash: B381CE725082099BCB20EF94C844ABEB3E8BF89314F54485FFA85C7250EB34DD49CB92
                          APIs
                          • SetWindowLongW.USER32(?,000000EB), ref: 00A85C7A
                            • Part of subcall function 00A85D0A: GetClientRect.USER32(?,?), ref: 00A85D30
                            • Part of subcall function 00A85D0A: GetWindowRect.USER32(?,?), ref: 00A85D71
                            • Part of subcall function 00A85D0A: ScreenToClient.USER32(?,?), ref: 00A85D99
                          • GetDC.USER32 ref: 00AC46F5
                          • SendMessageW.USER32(?,00000031,00000000,00000000), ref: 00AC4708
                          • SelectObject.GDI32(00000000,00000000), ref: 00AC4716
                          • SelectObject.GDI32(00000000,00000000), ref: 00AC472B
                          • ReleaseDC.USER32(?,00000000), ref: 00AC4733
                          • MoveWindow.USER32(?,?,?,?,?,?,?,00000031,00000000,00000000), ref: 00AC47C4
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$ClientObjectRectSelect$LongMessageMoveReleaseScreenSend
                          • String ID: U
                          • API String ID: 4009187628-3372436214
                          • Opcode ID: 7890387852bffeeadd7d036b0d8a5ef72f19ac7c63af7b25a7925bf70e7eea7b
                          • Instruction ID: 13f08f46055dc75eed670ad275f763c1a09d3136d6ad81cf6c0b6d8bdcdb4f53
                          • Opcode Fuzzy Hash: 7890387852bffeeadd7d036b0d8a5ef72f19ac7c63af7b25a7925bf70e7eea7b
                          • Instruction Fuzzy Hash: C971DC31800205DFCF219F64C994FEA3BB6FF4A324F154269ED565A2AAC7308C81DF60
                          APIs
                          • LoadStringW.USER32(00000066,?,00000FFF,00000000), ref: 00AF35E4
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • LoadStringW.USER32(00B52390,?,00000FFF,?), ref: 00AF360A
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: LoadString$_wcslen
                          • String ID: Error: $"%s" (%d) : ==> %s:$"%s" (%d) : ==> %s:%s%s$Line %d (File "%s"):$^ ERROR
                          • API String ID: 4099089115-2391861430
                          • Opcode ID: acc6c48e15b0991f5d0e2614210d702044dafb0720462982bbd3143f8b2793b6
                          • Instruction ID: 84998b5e2b64ab291253d393d1bac4436199644691224083246456a3e6341f3b
                          • Opcode Fuzzy Hash: acc6c48e15b0991f5d0e2614210d702044dafb0720462982bbd3143f8b2793b6
                          • Instruction Fuzzy Hash: B951387280020ABADF14FBE0CE46AFEBB78AF14300F144165F205761A1EB311B99DBA1
                          APIs
                          • InternetOpenUrlW.WININET(?,?,00000000,00000000,?,00000000), ref: 00AFC272
                          • HttpSendRequestW.WININET(00000000,00000000,00000000,00000000,00000000), ref: 00AFC29A
                          • HttpQueryInfoW.WININET(00000000,00000005,?,?,?), ref: 00AFC2CA
                          • GetLastError.KERNEL32 ref: 00AFC322
                          • SetEvent.KERNEL32(?), ref: 00AFC336
                          • InternetCloseHandle.WININET(00000000), ref: 00AFC341
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: HttpInternet$CloseErrorEventHandleInfoLastOpenQueryRequestSend
                          • String ID:
                          • API String ID: 3113390036-3916222277
                          • Opcode ID: 817b8518391de8d6a81c01b252dd06a9636dd0eecf247cb6c50f8da75494aecf
                          • Instruction ID: c2984343db4b57b7bd34ad1e1904b6bcd2d1f6370b55649710f32be0caf9e040
                          • Opcode Fuzzy Hash: 817b8518391de8d6a81c01b252dd06a9636dd0eecf247cb6c50f8da75494aecf
                          • Instruction Fuzzy Hash: 7F31937150020CAFD7219FA68E88ABBBBFCEB49794B54851DF546D7240DB30DD049B61
                          APIs
                          • GetModuleHandleW.KERNEL32(00000000,?,?,00000FFF,00000000,?,00AC3AAF,?,?,Bad directive syntax error,00B1CC08,00000000,00000010,?,?,>>>AUTOIT SCRIPT<<<), ref: 00AE98BC
                          • LoadStringW.USER32(00000000,?,00AC3AAF,?), ref: 00AE98C3
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • MessageBoxW.USER32(00000000,00000001,00000001,00011010), ref: 00AE9987
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: HandleLoadMessageModuleString_wcslen
                          • String ID: Error: $%s (%d) : ==> %s.: %s %s$.$Line %d (File "%s"):$Line %d:
                          • API String ID: 858772685-4153970271
                          • Opcode ID: 754de4a4dd8abfe1333d11cc85e447843b4edc78aa61020dc29dc7f96eb94bb4
                          • Instruction ID: cf4f4caf865f645f178607cad1308c1e5c5ba48297445d9e3c25b394652a0afa
                          • Opcode Fuzzy Hash: 754de4a4dd8abfe1333d11cc85e447843b4edc78aa61020dc29dc7f96eb94bb4
                          • Instruction Fuzzy Hash: 21218B3294021AAFCF15AF90CD0AEFE7779FF19700F044469F515660A2EB719A28EB51
                          APIs
                          • GetParent.USER32 ref: 00AE20AB
                          • GetClassNameW.USER32(00000000,?,00000100), ref: 00AE20C0
                          • SendMessageW.USER32(00000000,00000111,0000702B,00000000), ref: 00AE214D
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClassMessageNameParentSend
                          • String ID: SHELLDLL_DefView$details$largeicons$list$smallicons
                          • API String ID: 1290815626-3381328864
                          • Opcode ID: e67ceb04e60e382137b78e1bc46428a8eaccfdc828a2a9e5334a1d75a5e2f12e
                          • Instruction ID: 76d1f888f6869c703dc9fbd2690cc86011fe220cde5411045954be26e72063ef
                          • Opcode Fuzzy Hash: e67ceb04e60e382137b78e1bc46428a8eaccfdc828a2a9e5334a1d75a5e2f12e
                          • Instruction Fuzzy Hash: C2112C766C4706BAF6116721DC07EE637DCCB05364B200256F704A60F2FFB15A016714
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 9c424790cac348a14454be649df833163f6625fa79526c29771ca227f02e36df
                          • Instruction ID: 90b35a5ce29e0745b5f6dc5bf96f849258c754789f70bf6f0acfe4fce8e70d69
                          • Opcode Fuzzy Hash: 9c424790cac348a14454be649df833163f6625fa79526c29771ca227f02e36df
                          • Instruction Fuzzy Hash: A8C1D174A04349AFDF11EFACD841BEEBBB8AF1A310F144199E915A7393CB349941CB61
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free$EnvironmentVariable___from_strstr_to_strchr
                          • String ID:
                          • API String ID: 1282221369-0
                          • Opcode ID: 610884864a5ee428ed05713462a48a745cb37a2b55dcd7d5190a777e87c6101f
                          • Instruction ID: 8c195e4fad89231056323bafd89f5aaacf40ce8ebdb3e697cd28dd00d3648680
                          • Opcode Fuzzy Hash: 610884864a5ee428ed05713462a48a745cb37a2b55dcd7d5190a777e87c6101f
                          • Instruction Fuzzy Hash: FD610571A04301AFDB25BFB89981FFA7BADEF05320F0445AEF94597283EA319D019790
                          APIs
                          • SendMessageW.USER32(?,00002001,00000000,00000000), ref: 00B15186
                          • ShowWindow.USER32(?,00000000), ref: 00B151C7
                          • ShowWindow.USER32(?,00000005,?,00000000), ref: 00B151CD
                          • SetFocus.USER32(?,?,00000005,?,00000000), ref: 00B151D1
                            • Part of subcall function 00B16FBA: DeleteObject.GDI32(00000000), ref: 00B16FE6
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B1520D
                          • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00B1521A
                          • InvalidateRect.USER32(?,00000000,00000001,?,00000001), ref: 00B1524D
                          • SendMessageW.USER32(?,00001001,00000000,000000FE), ref: 00B15287
                          • SendMessageW.USER32(?,00001026,00000000,000000FE), ref: 00B15296
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$MessageSend$LongShow$DeleteFocusInvalidateObjectRect
                          • String ID:
                          • API String ID: 3210457359-0
                          • Opcode ID: 5e4cdc0bfacffb8856b69b6ed50ac4eb7edfd87bc02472576d4e4265747785e1
                          • Instruction ID: 8728193f9f9ba54eaa7f485167b4150f3b8dac4d296c9425819cdaef599fa8d3
                          • Opcode Fuzzy Hash: 5e4cdc0bfacffb8856b69b6ed50ac4eb7edfd87bc02472576d4e4265747785e1
                          • Instruction Fuzzy Hash: 2251B431A90A08FEEF319F24CC45BD93BE5EB86321F948195F515A72E0C7B599D0DB80
                          APIs
                          • LoadImageW.USER32(00000000,?,?,00000010,00000010,00000010), ref: 00AD6890
                          • ExtractIconExW.SHELL32(?,?,00000000,00000000,00000001), ref: 00AD68A9
                          • LoadImageW.USER32(00000000,?,00000001,00000000,00000000,00000050), ref: 00AD68B9
                          • ExtractIconExW.SHELL32(?,?,?,00000000,00000001), ref: 00AD68D1
                          • SendMessageW.USER32(00000000,00000080,00000000,00000000), ref: 00AD68F2
                          • DestroyIcon.USER32(00000000,?,00000010,00000010,00000010,?,?,?,?,?,00A98874,00000000,00000000,00000000,000000FF,00000000), ref: 00AD6901
                          • SendMessageW.USER32(00000000,00000080,00000001,00000000), ref: 00AD691E
                          • DestroyIcon.USER32(00000000,?,00000010,00000010,00000010,?,?,?,?,?,00A98874,00000000,00000000,00000000,000000FF,00000000), ref: 00AD692D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Icon$DestroyExtractImageLoadMessageSend
                          • String ID:
                          • API String ID: 1268354404-0
                          • Opcode ID: 817be64d3d35708523f4b2567fc6c69cafd0b6eccdc767da8523757f17115ae0
                          • Instruction ID: 8b24ee6fecc4e9434bbe67f7e7a7ad94c9ae6b4f09a76907502cc34aaf6e1c32
                          • Opcode Fuzzy Hash: 817be64d3d35708523f4b2567fc6c69cafd0b6eccdc767da8523757f17115ae0
                          • Instruction Fuzzy Hash: A0517470600209AFDF20CF28CC95BAE7BF6EB58760F144519F906972A0DB74E990DB50
                          APIs
                          • InternetConnectW.WININET(?,?,?,?,?,?,00000000,00000000), ref: 00AFC182
                          • GetLastError.KERNEL32 ref: 00AFC195
                          • SetEvent.KERNEL32(?), ref: 00AFC1A9
                            • Part of subcall function 00AFC253: InternetOpenUrlW.WININET(?,?,00000000,00000000,?,00000000), ref: 00AFC272
                            • Part of subcall function 00AFC253: GetLastError.KERNEL32 ref: 00AFC322
                            • Part of subcall function 00AFC253: SetEvent.KERNEL32(?), ref: 00AFC336
                            • Part of subcall function 00AFC253: InternetCloseHandle.WININET(00000000), ref: 00AFC341
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Internet$ErrorEventLast$CloseConnectHandleOpen
                          • String ID:
                          • API String ID: 337547030-0
                          • Opcode ID: b49c422d4fa8061d4339af2a7e13a22f0c841eca0c225d697623c1bc5313d636
                          • Instruction ID: d5032df0d4e663be10b6b1a22542a5a292e5ad89ae8b14db57c24a8f2395088b
                          • Opcode Fuzzy Hash: b49c422d4fa8061d4339af2a7e13a22f0c841eca0c225d697623c1bc5313d636
                          • Instruction Fuzzy Hash: F9318D7114060DAFDB21AFE6DE44AF6BBF8FF18320B00851DFA5683611DB30E9149BA0
                          APIs
                            • Part of subcall function 00AE3A3D: GetWindowThreadProcessId.USER32(?,00000000), ref: 00AE3A57
                            • Part of subcall function 00AE3A3D: GetCurrentThreadId.KERNEL32 ref: 00AE3A5E
                            • Part of subcall function 00AE3A3D: AttachThreadInput.USER32(00000000,?,00000000,00000000,?,00AE25B3), ref: 00AE3A65
                          • MapVirtualKeyW.USER32(00000025,00000000), ref: 00AE25BD
                          • PostMessageW.USER32(?,00000100,00000025,00000000), ref: 00AE25DB
                          • Sleep.KERNEL32(00000000,?,00000100,00000025,00000000), ref: 00AE25DF
                          • MapVirtualKeyW.USER32(00000025,00000000), ref: 00AE25E9
                          • PostMessageW.USER32(?,00000100,00000027,00000000), ref: 00AE2601
                          • Sleep.KERNEL32(00000000,?,00000100,00000027,00000000), ref: 00AE2605
                          • MapVirtualKeyW.USER32(00000025,00000000), ref: 00AE260F
                          • PostMessageW.USER32(?,00000101,00000027,00000000), ref: 00AE2623
                          • Sleep.KERNEL32(00000000,?,00000101,00000027,00000000,?,00000100,00000027,00000000), ref: 00AE2627
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessagePostSleepThreadVirtual$AttachCurrentInputProcessWindow
                          • String ID:
                          • API String ID: 2014098862-0
                          • Opcode ID: f85cefd9f3f26655ddf71319ed4e28de45a02c2b0cf5df08dc183b4cad3094f0
                          • Instruction ID: a165cd63ec9510f17e5e4d2cf27826669df9d6746bf2e8aba2f04be89137d2ad
                          • Opcode Fuzzy Hash: f85cefd9f3f26655ddf71319ed4e28de45a02c2b0cf5df08dc183b4cad3094f0
                          • Instruction Fuzzy Hash: D001D4313D0354BBFB1067699C8EF993F99DB4EB52F604011F318AF0D5CDE224448A69
                          APIs
                          • GetProcessHeap.KERNEL32(00000008,0000000C,?,00000000,?,00AE1449,?,?,00000000), ref: 00AE180C
                          • HeapAlloc.KERNEL32(00000000,?,00AE1449,?,?,00000000), ref: 00AE1813
                          • GetCurrentProcess.KERNEL32(00000000,00000000,00000000,00000002,?,00AE1449,?,?,00000000), ref: 00AE1828
                          • GetCurrentProcess.KERNEL32(?,00000000,?,00AE1449,?,?,00000000), ref: 00AE1830
                          • DuplicateHandle.KERNEL32(00000000,?,00AE1449,?,?,00000000), ref: 00AE1833
                          • GetCurrentProcess.KERNEL32(00000000,00000000,00000000,00000002,?,00AE1449,?,?,00000000), ref: 00AE1843
                          • GetCurrentProcess.KERNEL32(00AE1449,00000000,?,00AE1449,?,?,00000000), ref: 00AE184B
                          • DuplicateHandle.KERNEL32(00000000,?,00AE1449,?,?,00000000), ref: 00AE184E
                          • CreateThread.KERNEL32(00000000,00000000,00AE1874,00000000,00000000,00000000), ref: 00AE1868
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process$Current$DuplicateHandleHeap$AllocCreateThread
                          • String ID:
                          • API String ID: 1957940570-0
                          • Opcode ID: 6ea89ef34c2a53c2314a838de8d95348326a0c57da3546bf38bbf7956cafc706
                          • Instruction ID: 605e8968f4f7f7fadcfeb4a6a7389ca6b35c393ad60edc59d3c484314930b441
                          • Opcode Fuzzy Hash: 6ea89ef34c2a53c2314a838de8d95348326a0c57da3546bf38bbf7956cafc706
                          • Instruction Fuzzy Hash: D501BFB52C0344BFE710AB65DC4DF977FACEB89B11F508411FA05DB191CA709810CB20
                          APIs
                            • Part of subcall function 00AED4DC: CreateToolhelp32Snapshot.KERNEL32 ref: 00AED501
                            • Part of subcall function 00AED4DC: Process32FirstW.KERNEL32(00000000,?), ref: 00AED50F
                            • Part of subcall function 00AED4DC: CloseHandle.KERNEL32(00000000), ref: 00AED5DC
                          • OpenProcess.KERNEL32(00000001,00000000,?), ref: 00B0A16D
                          • GetLastError.KERNEL32 ref: 00B0A180
                          • OpenProcess.KERNEL32(00000001,00000000,?), ref: 00B0A1B3
                          • TerminateProcess.KERNEL32(00000000,00000000), ref: 00B0A268
                          • GetLastError.KERNEL32(00000000), ref: 00B0A273
                          • CloseHandle.KERNEL32(00000000), ref: 00B0A2C4
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process$CloseErrorHandleLastOpen$CreateFirstProcess32SnapshotTerminateToolhelp32
                          • String ID: SeDebugPrivilege
                          • API String ID: 2533919879-2896544425
                          • Opcode ID: cbaf2eac452bcc4a39b905c2e307caa5075e92c8cc77a028f02cf956aecd113d
                          • Instruction ID: c6e9c73e9b9b8445aafd6d10074f7e9e783c2db2fcd412b4f3c1b846419e135e
                          • Opcode Fuzzy Hash: cbaf2eac452bcc4a39b905c2e307caa5075e92c8cc77a028f02cf956aecd113d
                          • Instruction Fuzzy Hash: 81616A30204342AFE720DF19C594F16BBE1AF54318F54889CE4668B6A3CB72ED49CB92
                          APIs
                          • SendMessageW.USER32(00000000,00001036,00000010,00000010), ref: 00B13925
                          • SendMessageW.USER32(00000000,00001036,00000000,?), ref: 00B1393A
                          • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000000,00000013), ref: 00B13954
                          • _wcslen.LIBCMT ref: 00B13999
                          • SendMessageW.USER32(?,00001057,00000000,?), ref: 00B139C6
                          • SendMessageW.USER32(?,00001061,?,0000000F), ref: 00B139F4
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$Window_wcslen
                          • String ID: SysListView32
                          • API String ID: 2147712094-78025650
                          • Opcode ID: d1789386db441fcf889065c141258ef34a3aafc26127b3370eb0862ee0fa74c9
                          • Instruction ID: 0ca923eeb6146bb31e5fa3705616ec77a841181a60ff88a38c0d6fe665e046cf
                          • Opcode Fuzzy Hash: d1789386db441fcf889065c141258ef34a3aafc26127b3370eb0862ee0fa74c9
                          • Instruction Fuzzy Hash: 6941C431A00218ABEF219F64CC45FEA7BE9EF08750F500566F959E7281E7719E80CB90
                          APIs
                          • GetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 00AEBCFD
                          • IsMenu.USER32(00000000), ref: 00AEBD1D
                          • CreatePopupMenu.USER32 ref: 00AEBD53
                          • GetMenuItemCount.USER32(00C45E30), ref: 00AEBDA4
                          • InsertMenuItemW.USER32(00C45E30,?,00000001,00000030), ref: 00AEBDCC
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Menu$Item$CountCreateInfoInsertPopup
                          • String ID: 0$2
                          • API String ID: 93392585-3793063076
                          • Opcode ID: 38e84baeb3ff4f7e475dc65e6af821107e88c9151232d626889f6753f2fe8978
                          • Instruction ID: 0bbdb9e15fe1df37dfc9136a7a0886d2fcbb256ec644c70a7e0a61cca36f8f8a
                          • Opcode Fuzzy Hash: 38e84baeb3ff4f7e475dc65e6af821107e88c9151232d626889f6753f2fe8978
                          • Instruction Fuzzy Hash: CE519C70A102899BDF20CFAADDC8BAFBBF9AF55314F248229E411D7291D7709941CB71
                          APIs
                          • LoadIconW.USER32(00000000,00007F03), ref: 00AEC913
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: IconLoad
                          • String ID: blank$info$question$stop$warning
                          • API String ID: 2457776203-404129466
                          • Opcode ID: f094d8ad83e019ac2dd21fe353c605cd1ed63c468d9c801c3ab1a9251c2c9fac
                          • Instruction ID: e9ea3da781bcf42dfab73aab87d442adde9d37f858d1ed34d91da4132a09d3ca
                          • Opcode Fuzzy Hash: f094d8ad83e019ac2dd21fe353c605cd1ed63c468d9c801c3ab1a9251c2c9fac
                          • Instruction Fuzzy Hash: F5112C32689346BAE7019B55DD83CEE77ECDF16374B60006AF900A72D3E7B45E016269
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CleanupStartup_strcatgethostbynamegethostnameinet_ntoa
                          • String ID: 0.0.0.0
                          • API String ID: 642191829-3771769585
                          • Opcode ID: 470f4d506b90740264ad1cb2dff873f2a1f67f92e28818845a8734294324042f
                          • Instruction ID: c342bbfbc3919013d245e5d08d1b4309a1c8c9e38a5b16d4849cd6d84185a3d6
                          • Opcode Fuzzy Hash: 470f4d506b90740264ad1cb2dff873f2a1f67f92e28818845a8734294324042f
                          • Instruction Fuzzy Hash: 0811D371904215AFCB20AB61DD4AEEF7BBCDF56711F0001A9F545EB0D1EFB18E818AA0
                          APIs
                            • Part of subcall function 00A99BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 00A99BB2
                          • GetSystemMetrics.USER32(0000000F), ref: 00B19FC7
                          • GetSystemMetrics.USER32(0000000F), ref: 00B19FE7
                          • MoveWindow.USER32(00000003,?,?,?,?,00000000,?,?,?), ref: 00B1A224
                          • SendMessageW.USER32(00000003,00000142,00000000,0000FFFF), ref: 00B1A242
                          • SendMessageW.USER32(00000003,00000469,?,00000000), ref: 00B1A263
                          • ShowWindow.USER32(00000003,00000000), ref: 00B1A282
                          • InvalidateRect.USER32(?,00000000,00000001), ref: 00B1A2A7
                          • DefDlgProcW.USER32(?,00000005,?,?), ref: 00B1A2CA
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$MessageMetricsSendSystem$InvalidateLongMoveProcRectShow
                          • String ID:
                          • API String ID: 1211466189-0
                          • Opcode ID: 283a1de3c9da73ee6ae14ca0fffb4911aa75b8fa884640890be8bc6b67f0eac5
                          • Instruction ID: 557a9be006253e1ceb831bfa6da6a7099ac61fd0020efa2140779c4fbde84fa8
                          • Opcode Fuzzy Hash: 283a1de3c9da73ee6ae14ca0fffb4911aa75b8fa884640890be8bc6b67f0eac5
                          • Instruction Fuzzy Hash: 36B1B731601215EBCF14CF68C9857EE7BF2FF48701F5880A9EC49AB295DB31A980CB91
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$LocalTime
                          • String ID:
                          • API String ID: 952045576-0
                          • Opcode ID: b5729f8759112dcf4c64d9f938e3adf026942de542abcde844c992d712b5b36b
                          • Instruction ID: a92afc3b3ddc2db6d58a36d4efdbc4d7af36c1a384196ebea148f2d7b586efa7
                          • Opcode Fuzzy Hash: b5729f8759112dcf4c64d9f938e3adf026942de542abcde844c992d712b5b36b
                          • Instruction Fuzzy Hash: C241B265C10258B6DB11EBF5CC8AACFB7ACAF46310F508462F518E3161FB34E255C7A5
                          APIs
                          • ShowWindow.USER32(FFFFFFFF,000000FF,?,00000000,?,00AD682C,00000004,00000000,00000000), ref: 00A9F953
                          • ShowWindow.USER32(FFFFFFFF,00000006,?,00000000,?,00AD682C,00000004,00000000,00000000), ref: 00ADF3D1
                          • ShowWindow.USER32(FFFFFFFF,000000FF,?,00000000,?,00AD682C,00000004,00000000,00000000), ref: 00ADF454
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ShowWindow
                          • String ID:
                          • API String ID: 1268545403-0
                          • Opcode ID: 31fea9b5cb9831b3a10c7b703678aa0b312a6129384cbcc38afa92b41ef5fada
                          • Instruction ID: 89beb3174bdbe663bad00a75c7a4601b4b1429d39857e2da9e993c3597ed6fa5
                          • Opcode Fuzzy Hash: 31fea9b5cb9831b3a10c7b703678aa0b312a6129384cbcc38afa92b41ef5fada
                          • Instruction Fuzzy Hash: D741F831718680BECF399B2DCD8876B7FE2AB56314F54843DE497D7660CA71A880CB11
                          APIs
                          • DeleteObject.GDI32(00000000), ref: 00B12D1B
                          • GetDC.USER32(00000000), ref: 00B12D23
                          • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00B12D2E
                          • ReleaseDC.USER32(00000000,00000000), ref: 00B12D3A
                          • CreateFontW.GDI32(?,00000000,00000000,00000000,?,00000000,00000000,00000000,00000001,00000004,00000000,?,00000000,?), ref: 00B12D76
                          • SendMessageW.USER32(?,00000030,00000000,00000001), ref: 00B12D87
                          • MoveWindow.USER32(?,?,?,?,?,00000000,?,?,00B15A65,?,?,000000FF,00000000,?,000000FF,?), ref: 00B12DC2
                          • SendMessageW.USER32(?,00000142,00000000,00000000), ref: 00B12DE1
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$CapsCreateDeleteDeviceFontMoveObjectReleaseWindow
                          • String ID:
                          • API String ID: 3864802216-0
                          • Opcode ID: 8b58bb1c28b99336d496936f5065bda119660b7bdde84234f4b81686f183adba
                          • Instruction ID: 4ea0c0e766f9ff87952661941d78c4f005ec3ebd9c9a632aa1ee4943a8821dc1
                          • Opcode Fuzzy Hash: 8b58bb1c28b99336d496936f5065bda119660b7bdde84234f4b81686f183adba
                          • Instruction Fuzzy Hash: F0316B72241214BFEB158F50DC8AFEB3FA9EB09715F4480A5FE089B291CA759C50CBA4
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _memcmp
                          • String ID:
                          • API String ID: 2931989736-0
                          • Opcode ID: 2a82d3c0362c2cfee96e1c051ecbbb9b3cf9dcc925cdd04d78b967983ac98a36
                          • Instruction ID: c4249a8884e0308e8c64560a4b23ec1d0b8d76208525fd85b31c9377fd0275c9
                          • Opcode Fuzzy Hash: 2a82d3c0362c2cfee96e1c051ecbbb9b3cf9dcc925cdd04d78b967983ac98a36
                          • Instruction Fuzzy Hash: 7B219871E409457796149A326E92FFB33ACAE11388F580020FD045F5C1F761ED50C1F5
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID: NULL Pointer assignment$Not an Object type
                          • API String ID: 0-572801152
                          • Opcode ID: 1ef8327a3305c29b19722276bb3a27c0cbfc1c36b4a77d9bd8ff0c39ee8a01c7
                          • Instruction ID: 70cafdfd61bc3f623b0edaa95ca9333e16721f6d1ebc5b91e48326115c868b65
                          • Opcode Fuzzy Hash: 1ef8327a3305c29b19722276bb3a27c0cbfc1c36b4a77d9bd8ff0c39ee8a01c7
                          • Instruction Fuzzy Hash: BFD17D75A0060A9FDF20CF98C881AAEBBF5FF48344F1484A9E915AB691E770DD45CF90
                          APIs
                          • GetCPInfo.KERNEL32(?,?), ref: 00AC15CE
                          • MultiByteToWideChar.KERNEL32(?,00000009,?,?,00000000,00000000), ref: 00AC1651
                          • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 00AC16E4
                          • MultiByteToWideChar.KERNEL32(?,00000009,?,?,00000000,00000000), ref: 00AC16FB
                            • Part of subcall function 00AB3820: RtlAllocateHeap.NTDLL(00000000,?,00B51444,?,00A9FDF5,?,?,00A8A976,00000010,00B51440,00A813FC,?,00A813C6,?,00A81129), ref: 00AB3852
                          • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 00AC1777
                          • __freea.LIBCMT ref: 00AC17A2
                          • __freea.LIBCMT ref: 00AC17AE
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ByteCharMultiWide$__freea$AllocateHeapInfo
                          • String ID:
                          • API String ID: 2829977744-0
                          • Opcode ID: 1ae1371ac1f310c2194e0c5de66d62454a6f9198de54e8a769ee33d5e9bc7106
                          • Instruction ID: 6ffaa93b93273f3a45bb86edc5de0d70dc46750a9a48aa35e5d07896af5be96e
                          • Opcode Fuzzy Hash: 1ae1371ac1f310c2194e0c5de66d62454a6f9198de54e8a769ee33d5e9bc7106
                          • Instruction Fuzzy Hash: 23919272F0021A9ADF208F64C991FEE7BB5AF4A710F1A465DE801E7242DB35DD41CBA0
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Variant$ClearInit
                          • String ID: Incorrect Object type in FOR..IN loop$Null Object assignment in FOR..IN loop
                          • API String ID: 2610073882-625585964
                          • Opcode ID: 8ab4aa64ccaf44769def17bba46d5daa005ceaf6f9e8d62af42a0799f7dc543e
                          • Instruction ID: e924d1cfdfd3667b2cecfe3025e582b8c767575d4673d534f7b8e892b0b56f69
                          • Opcode Fuzzy Hash: 8ab4aa64ccaf44769def17bba46d5daa005ceaf6f9e8d62af42a0799f7dc543e
                          • Instruction Fuzzy Hash: 4B9171B1A00215ABDF20CFA5D884FAE7BF8EF46714F108599F615AB281D7709D45CFA0
                          APIs
                          • SafeArrayGetVartype.OLEAUT32(00000001,?), ref: 00AF125C
                          • SafeArrayAccessData.OLEAUT32(00000000,?), ref: 00AF1284
                          • SafeArrayUnaccessData.OLEAUT32(00000001), ref: 00AF12A8
                          • SafeArrayAccessData.OLEAUT32(00000001,?), ref: 00AF12D8
                          • SafeArrayAccessData.OLEAUT32(00000001,?), ref: 00AF135F
                          • SafeArrayAccessData.OLEAUT32(00000001,?), ref: 00AF13C4
                          • SafeArrayAccessData.OLEAUT32(00000001,?), ref: 00AF1430
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ArraySafe$Data$Access$UnaccessVartype
                          • String ID:
                          • API String ID: 2550207440-0
                          • Opcode ID: 034d2239e80d2831b745c60463b99156eba8eac40b1350fc0cadf87c68a84408
                          • Instruction ID: 2b8016729c61b2b6cd2ae7ae0f9c5a8b58c9c77f86a96d8ad3d7fc6309ad911b
                          • Opcode Fuzzy Hash: 034d2239e80d2831b745c60463b99156eba8eac40b1350fc0cadf87c68a84408
                          • Instruction Fuzzy Hash: 3A919B75A00219EFDB009FE8C884BBEB7B5FF45325F108029FA51EB291D774A941CB90
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ObjectSelect$BeginCreatePath
                          • String ID:
                          • API String ID: 3225163088-0
                          • Opcode ID: 75b6758c37a516b77df585e0b808d3b8d2aa1d1857e3bae9695e266779e4e0a8
                          • Instruction ID: 05adddf305d93eb692145fb58f4191380a02fe1da68225f99a2aa5e782af5267
                          • Opcode Fuzzy Hash: 75b6758c37a516b77df585e0b808d3b8d2aa1d1857e3bae9695e266779e4e0a8
                          • Instruction Fuzzy Hash: B7912571A40219AFCF15CFA9C888AEFBBB8FF49320F14805AE515B7251D774AA41CB60
                          APIs
                          • VariantInit.OLEAUT32(?), ref: 00B0396B
                          • CharUpperBuffW.USER32(?,?), ref: 00B03A7A
                          • _wcslen.LIBCMT ref: 00B03A8A
                          • VariantClear.OLEAUT32(?), ref: 00B03C1F
                            • Part of subcall function 00AF0CDF: VariantInit.OLEAUT32(00000000), ref: 00AF0D1F
                            • Part of subcall function 00AF0CDF: VariantCopy.OLEAUT32(?,?), ref: 00AF0D28
                            • Part of subcall function 00AF0CDF: VariantClear.OLEAUT32(?), ref: 00AF0D34
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Variant$ClearInit$BuffCharCopyUpper_wcslen
                          • String ID: AUTOIT.ERROR$Incorrect Parameter format
                          • API String ID: 4137639002-1221869570
                          • Opcode ID: a8d0330efa1b973a7899c1ca1e61321992df2f33dd9a5e26f150229c90eb1837
                          • Instruction ID: ffd7055cab0d4932fa257945345eba5d30f400fc0d4f122fbaf54107ae8a8fe8
                          • Opcode Fuzzy Hash: a8d0330efa1b973a7899c1ca1e61321992df2f33dd9a5e26f150229c90eb1837
                          • Instruction Fuzzy Hash: 6C916D756083059FC704EF24C58496ABBE8FF89714F14886DF48A97391DB30EE45CB92
                          APIs
                            • Part of subcall function 00AE000E: CLSIDFromProgID.OLE32(?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?,?,?,00AE035E), ref: 00AE002B
                            • Part of subcall function 00AE000E: ProgIDFromCLSID.OLE32(?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?,?), ref: 00AE0046
                            • Part of subcall function 00AE000E: lstrcmpiW.KERNEL32(?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?,?), ref: 00AE0054
                            • Part of subcall function 00AE000E: CoTaskMemFree.OLE32(00000000,?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?), ref: 00AE0064
                          • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000002,00000003,00000000,00000000,00000000,00000001,?,?), ref: 00B04C51
                          • _wcslen.LIBCMT ref: 00B04D59
                          • CoCreateInstanceEx.OLE32(?,00000000,00000015,?,00000001,?), ref: 00B04DCF
                          • CoTaskMemFree.OLE32(?), ref: 00B04DDA
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FreeFromProgTask$CreateInitializeInstanceSecurity_wcslenlstrcmpi
                          • String ID: NULL Pointer assignment
                          • API String ID: 614568839-2785691316
                          • Opcode ID: 69863e8fd24fd2d9a7fb778132130fd242e086a0110f96377122c0284bd292ff
                          • Instruction ID: c089354ce97d44ef83dda7543df6dcda61e58c972502c2e73f3831b6964c32f5
                          • Opcode Fuzzy Hash: 69863e8fd24fd2d9a7fb778132130fd242e086a0110f96377122c0284bd292ff
                          • Instruction Fuzzy Hash: 1E9108B1D002199FDF14EFA4D891AEEBBB8FF08310F1085AAE515A7291DB709E44CF60
                          APIs
                          • GetMenu.USER32(?), ref: 00B12183
                          • GetMenuItemCount.USER32(00000000), ref: 00B121B5
                          • GetMenuStringW.USER32(00000000,00000000,?,00007FFF,00000400), ref: 00B121DD
                          • _wcslen.LIBCMT ref: 00B12213
                          • GetMenuItemID.USER32(?,?), ref: 00B1224D
                          • GetSubMenu.USER32(?,?), ref: 00B1225B
                            • Part of subcall function 00AE3A3D: GetWindowThreadProcessId.USER32(?,00000000), ref: 00AE3A57
                            • Part of subcall function 00AE3A3D: GetCurrentThreadId.KERNEL32 ref: 00AE3A5E
                            • Part of subcall function 00AE3A3D: AttachThreadInput.USER32(00000000,?,00000000,00000000,?,00AE25B3), ref: 00AE3A65
                          • PostMessageW.USER32(?,00000111,00000000,00000000), ref: 00B122E3
                            • Part of subcall function 00AEE97B: Sleep.KERNEL32 ref: 00AEE9F3
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Menu$Thread$Item$AttachCountCurrentInputMessagePostProcessSleepStringWindow_wcslen
                          • String ID:
                          • API String ID: 4196846111-0
                          • Opcode ID: a2fa5e5f60585717f918f5cbbf70990e461519c85ef7de364079f858279fa99d
                          • Instruction ID: 428a61531886a0d090a21dd661f797baf87ab8c82afc2ff2e61a53cda697754b
                          • Opcode Fuzzy Hash: a2fa5e5f60585717f918f5cbbf70990e461519c85ef7de364079f858279fa99d
                          • Instruction Fuzzy Hash: E6718E75A00205AFCB14EF64C985AEEBBF5EF48310F548499E916EB341DB34ED918B90
                          APIs
                          • IsWindow.USER32(00C45D68), ref: 00B17F37
                          • IsWindowEnabled.USER32(00C45D68), ref: 00B17F43
                          • SendMessageW.USER32(00000000,0000041C,00000000,00000000), ref: 00B1801E
                          • SendMessageW.USER32(00C45D68,000000B0,?,?), ref: 00B18051
                          • IsDlgButtonChecked.USER32(?,?), ref: 00B18089
                          • GetWindowLongW.USER32(00C45D68,000000EC), ref: 00B180AB
                          • SendMessageW.USER32(?,000000A1,00000002,00000000), ref: 00B180C3
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSendWindow$ButtonCheckedEnabledLong
                          • String ID:
                          • API String ID: 4072528602-0
                          • Opcode ID: 4f900cc3f5fba26b45ce6f1cf165a0b3afbb412b39a02d648be82b4e7a590ebb
                          • Instruction ID: a1a2a3acbe649f9ca54a9358354fcd4493c7c5a70f833c317597be6049a95809
                          • Opcode Fuzzy Hash: 4f900cc3f5fba26b45ce6f1cf165a0b3afbb412b39a02d648be82b4e7a590ebb
                          • Instruction Fuzzy Hash: 76718C75688244AFEB219F64C884FEB7BF5FF09300F944499E94597261CF31AC86CB50
                          APIs
                          • GetParent.USER32(?), ref: 00AEAEF9
                          • GetKeyboardState.USER32(?), ref: 00AEAF0E
                          • SetKeyboardState.USER32(?), ref: 00AEAF6F
                          • PostMessageW.USER32(?,00000101,00000010,?), ref: 00AEAF9D
                          • PostMessageW.USER32(?,00000101,00000011,?), ref: 00AEAFBC
                          • PostMessageW.USER32(?,00000101,00000012,?), ref: 00AEAFFD
                          • PostMessageW.USER32(?,00000101,0000005B,?), ref: 00AEB020
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessagePost$KeyboardState$Parent
                          • String ID:
                          • API String ID: 87235514-0
                          • Opcode ID: ba8c6f9fecfc001594a1366413411907ebc897a0444972a422d9ff3a7f848319
                          • Instruction ID: 3dbdad5f087ea29f9fa104131b5a580390b5cf2aaf67f49517f0515b1fcd7677
                          • Opcode Fuzzy Hash: ba8c6f9fecfc001594a1366413411907ebc897a0444972a422d9ff3a7f848319
                          • Instruction Fuzzy Hash: 2C51D0A06147D53DFB36833A8C49BBBBEE95B06304F088489E1D9468C2C798FCC8D761
                          APIs
                          • GetParent.USER32(00000000), ref: 00AEAD19
                          • GetKeyboardState.USER32(?), ref: 00AEAD2E
                          • SetKeyboardState.USER32(?), ref: 00AEAD8F
                          • PostMessageW.USER32(00000000,00000100,00000010,?), ref: 00AEADBB
                          • PostMessageW.USER32(00000000,00000100,00000011,?), ref: 00AEADD8
                          • PostMessageW.USER32(00000000,00000100,00000012,?), ref: 00AEAE17
                          • PostMessageW.USER32(00000000,00000100,0000005B,?), ref: 00AEAE38
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessagePost$KeyboardState$Parent
                          • String ID:
                          • API String ID: 87235514-0
                          • Opcode ID: e7ad555341498913255d94c54d13815c8b22b13a9a0a411a60532afb442631dd
                          • Instruction ID: fb12c8d31b1959c96cba565b666ca97158e4b4c7c0d193f33b8faa075e596704
                          • Opcode Fuzzy Hash: e7ad555341498913255d94c54d13815c8b22b13a9a0a411a60532afb442631dd
                          • Instruction Fuzzy Hash: 185107A16047E53DFB3383368C95BBABEA95F56300F088488E1D9468C3D794FC88D762
                          APIs
                          • GetConsoleCP.KERNEL32(00AC3CD6,?,?,?,?,?,?,?,?,00AB5BA3,?,?,00AC3CD6,?,?), ref: 00AB5470
                          • __fassign.LIBCMT ref: 00AB54EB
                          • __fassign.LIBCMT ref: 00AB5506
                          • WideCharToMultiByte.KERNEL32(?,00000000,?,00000001,00AC3CD6,00000005,00000000,00000000), ref: 00AB552C
                          • WriteFile.KERNEL32(?,00AC3CD6,00000000,00AB5BA3,00000000,?,?,?,?,?,?,?,?,?,00AB5BA3,?), ref: 00AB554B
                          • WriteFile.KERNEL32(?,?,00000001,00AB5BA3,00000000,?,?,?,?,?,?,?,?,?,00AB5BA3,?), ref: 00AB5584
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FileWrite__fassign$ByteCharConsoleMultiWide
                          • String ID:
                          • API String ID: 1324828854-0
                          • Opcode ID: fa206fdd3fc7ee432d339159fceb2e3a9c49637bd79aec5c25fd4a0983ab85f0
                          • Instruction ID: f066c3551422a2f8f85cb259e97f9cba160f0bd7057ff639023a0b1fbe1ce307
                          • Opcode Fuzzy Hash: fa206fdd3fc7ee432d339159fceb2e3a9c49637bd79aec5c25fd4a0983ab85f0
                          • Instruction Fuzzy Hash: A751BF71E00649AFDB20CFA8D885BEEBBF9EF09301F14415AE955E7292D7309A51CB60
                          APIs
                          • _ValidateLocalCookies.LIBCMT ref: 00AA2D4B
                          • ___except_validate_context_record.LIBVCRUNTIME ref: 00AA2D53
                          • _ValidateLocalCookies.LIBCMT ref: 00AA2DE1
                          • __IsNonwritableInCurrentImage.LIBCMT ref: 00AA2E0C
                          • _ValidateLocalCookies.LIBCMT ref: 00AA2E61
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                          • String ID: csm
                          • API String ID: 1170836740-1018135373
                          • Opcode ID: f364b4f7cbfa69832d9600beae3845694824d17409871ef0639f5791381c6564
                          • Instruction ID: a27f7aecd0757d635e92c0fd1b71d632f79d56c5594d406691bf2b13e19bd828
                          • Opcode Fuzzy Hash: f364b4f7cbfa69832d9600beae3845694824d17409871ef0639f5791381c6564
                          • Instruction Fuzzy Hash: 7B419134A01209ABCF10DF6CC845BAEBBB5BF46324F148155E8146B3E2DB35EE65CB90
                          APIs
                            • Part of subcall function 00B0304E: inet_addr.WSOCK32(?,?,?,?,?,00000000), ref: 00B0307A
                            • Part of subcall function 00B0304E: _wcslen.LIBCMT ref: 00B0309B
                          • socket.WSOCK32(00000002,00000001,00000006,?,?,00000000), ref: 00B01112
                          • WSAGetLastError.WSOCK32 ref: 00B01121
                          • WSAGetLastError.WSOCK32 ref: 00B011C9
                          • closesocket.WSOCK32(00000000), ref: 00B011F9
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorLast$_wcslenclosesocketinet_addrsocket
                          • String ID:
                          • API String ID: 2675159561-0
                          • Opcode ID: 28f7e58d1beb436bb77a438190dc4603ae59e685b0ef43ae1c8014a078c844ff
                          • Instruction ID: 1f199bc151f6ded3ae336795f167eccd753475120e141b9509c1d88307ea698d
                          • Opcode Fuzzy Hash: 28f7e58d1beb436bb77a438190dc4603ae59e685b0ef43ae1c8014a078c844ff
                          • Instruction Fuzzy Hash: 5241D431600204AFDB189F18C885BAABFE9FF45364F148499F916AB2D1CB70ED41CBE1
                          APIs
                            • Part of subcall function 00AEDDE0: GetFullPathNameW.KERNEL32(00000000,00007FFF,?,?,?,?,?,?,00AECF22,?), ref: 00AEDDFD
                            • Part of subcall function 00AEDDE0: GetFullPathNameW.KERNEL32(?,00007FFF,?,?,?,?,?,00AECF22,?), ref: 00AEDE16
                          • lstrcmpiW.KERNEL32(?,?), ref: 00AECF45
                          • MoveFileW.KERNEL32(?,?), ref: 00AECF7F
                          • _wcslen.LIBCMT ref: 00AED005
                          • _wcslen.LIBCMT ref: 00AED01B
                          • SHFileOperationW.SHELL32(?), ref: 00AED061
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FileFullNamePath_wcslen$MoveOperationlstrcmpi
                          • String ID: \*.*
                          • API String ID: 3164238972-1173974218
                          • Opcode ID: 263831deb5bf0131bcc677008a724b29a93534d833894c63ce08835ed37eea54
                          • Instruction ID: 630c379226dab82280476a5adb9bb0ed34fa9da337709ac16b8dd744e3fdd157
                          • Opcode Fuzzy Hash: 263831deb5bf0131bcc677008a724b29a93534d833894c63ce08835ed37eea54
                          • Instruction Fuzzy Hash: D04166719452585FDF12EFA5CA81ADEB7B9AF08380F0000E6E505EB142EB34AB89CB50
                          APIs
                          • SendMessageW.USER32(?,000000F0,00000000,00000000), ref: 00B12E1C
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B12E4F
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B12E84
                          • SendMessageW.USER32(?,000000F1,00000000,00000000), ref: 00B12EB6
                          • SendMessageW.USER32(?,000000F1,00000001,00000000), ref: 00B12EE0
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B12EF1
                          • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00B12F0B
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: LongWindow$MessageSend
                          • String ID:
                          • API String ID: 2178440468-0
                          • Opcode ID: 81873ccef01359d34b1cdbc889ed0cb849a4c38e3b76feb794657f5c0584c1c7
                          • Instruction ID: 77902a1c814d46a161814715da69112ae71d8bc077161537370991ef7349f97a
                          • Opcode Fuzzy Hash: 81873ccef01359d34b1cdbc889ed0cb849a4c38e3b76feb794657f5c0584c1c7
                          • Instruction Fuzzy Hash: A8311232644250AFEB21CF58DC85FA53BE1FB9A711F9541A4F9108F2B2CB71ACA1DB41
                          APIs
                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 00AE7769
                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 00AE778F
                          • SysAllocString.OLEAUT32(00000000), ref: 00AE7792
                          • SysAllocString.OLEAUT32(?), ref: 00AE77B0
                          • SysFreeString.OLEAUT32(?), ref: 00AE77B9
                          • StringFromGUID2.OLE32(?,?,00000028), ref: 00AE77DE
                          • SysAllocString.OLEAUT32(?), ref: 00AE77EC
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: String$Alloc$ByteCharMultiWide$FreeFrom
                          • String ID:
                          • API String ID: 3761583154-0
                          • Opcode ID: 31762f319ac8ae8d5524f632c7c636b378a008523373293a329f9121bdad5eae
                          • Instruction ID: 84bb08ac18b8dc18ce65f7d0c89e6bfbd3949054e2b3476f448f9838ec28f384
                          • Opcode Fuzzy Hash: 31762f319ac8ae8d5524f632c7c636b378a008523373293a329f9121bdad5eae
                          • Instruction Fuzzy Hash: 1D219076608219AFDF10DFA9CC88CFF77ACEB097647448025FA15DB250DA70DC428764
                          APIs
                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 00AE7842
                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 00AE7868
                          • SysAllocString.OLEAUT32(00000000), ref: 00AE786B
                          • SysAllocString.OLEAUT32 ref: 00AE788C
                          • SysFreeString.OLEAUT32 ref: 00AE7895
                          • StringFromGUID2.OLE32(?,?,00000028), ref: 00AE78AF
                          • SysAllocString.OLEAUT32(?), ref: 00AE78BD
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: String$Alloc$ByteCharMultiWide$FreeFrom
                          • String ID:
                          • API String ID: 3761583154-0
                          • Opcode ID: 4dc7755c9337d8478e7daa2f796d91b1b4ec8725ae4488d92ff3cafebf4b7536
                          • Instruction ID: eb428820d84f8d62cfa07c556135f6b935c922cd7f65c13209f9166b80628179
                          • Opcode Fuzzy Hash: 4dc7755c9337d8478e7daa2f796d91b1b4ec8725ae4488d92ff3cafebf4b7536
                          • Instruction Fuzzy Hash: 4821AF76608214AFEF10AFA9DC88DAE77ECEB193607508125F915CB2A1DA70DC81CB64
                          APIs
                          • GetStdHandle.KERNEL32(0000000C), ref: 00AF04F2
                          • CreatePipe.KERNEL32(?,?,0000000C,00000000), ref: 00AF052E
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CreateHandlePipe
                          • String ID: nul
                          • API String ID: 1424370930-2873401336
                          • Opcode ID: f8a4e94e81c2bd6d9eedaa15f8cb8d0c1d57e7942e27c82f6cfb083be23b9c5b
                          • Instruction ID: cf5a795d7368619755e09b2de4a500693898e33b10ff1d0b08a81421ad8ad00d
                          • Opcode Fuzzy Hash: f8a4e94e81c2bd6d9eedaa15f8cb8d0c1d57e7942e27c82f6cfb083be23b9c5b
                          • Instruction Fuzzy Hash: BA216075500309ABDF209FA9DC44EAA7BB4AF44764F208A19FAA1D72E1D7B0D940CF60
                          APIs
                          • GetStdHandle.KERNEL32(000000F6), ref: 00AF05C6
                          • CreatePipe.KERNEL32(?,?,0000000C,00000000), ref: 00AF0601
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CreateHandlePipe
                          • String ID: nul
                          • API String ID: 1424370930-2873401336
                          • Opcode ID: 3cb54f6b65b03e851ec099d0b02fa1968b5cbfed21e389d913a0ed84a343990c
                          • Instruction ID: 9c3ea0ed3394fa2f867e2547f34b14bcc45af6e81a789f9dda77291a1a07a7e7
                          • Opcode Fuzzy Hash: 3cb54f6b65b03e851ec099d0b02fa1968b5cbfed21e389d913a0ed84a343990c
                          • Instruction Fuzzy Hash: 2321A6755003199BDB208FA88C04EAA7BE4AF95760F204B19FAA1E72D1DBF09960CB50
                          APIs
                            • Part of subcall function 00A8600E: CreateWindowExW.USER32(?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 00A8604C
                            • Part of subcall function 00A8600E: GetStockObject.GDI32(00000011), ref: 00A86060
                            • Part of subcall function 00A8600E: SendMessageW.USER32(00000000,00000030,00000000), ref: 00A8606A
                          • SendMessageW.USER32(00000000,00002001,00000000,FF000000), ref: 00B14112
                          • SendMessageW.USER32(?,00000409,00000000,FF000000), ref: 00B1411F
                          • SendMessageW.USER32(?,00000402,00000000,00000000), ref: 00B1412A
                          • SendMessageW.USER32(?,00000401,00000000,00640000), ref: 00B14139
                          • SendMessageW.USER32(?,00000404,00000001,00000000), ref: 00B14145
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$CreateObjectStockWindow
                          • String ID: Msctls_Progress32
                          • API String ID: 1025951953-3636473452
                          • Opcode ID: 6b25d1206ab618c745eca03cf022429a10d589f70d423fd37611b0a4be0c7688
                          • Instruction ID: b15544229e22a3b1cf830a8621630e5c4b61ace8272b9ee0962aa6c5693e0d84
                          • Opcode Fuzzy Hash: 6b25d1206ab618c745eca03cf022429a10d589f70d423fd37611b0a4be0c7688
                          • Instruction Fuzzy Hash: CB11B2B2140219BEEF119F64CC85EE77FADEF09798F008110BB18A6050CB729C61DBA4
                          APIs
                            • Part of subcall function 00ABD7A3: _free.LIBCMT ref: 00ABD7CC
                          • _free.LIBCMT ref: 00ABD82D
                            • Part of subcall function 00AB29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000), ref: 00AB29DE
                            • Part of subcall function 00AB29C8: GetLastError.KERNEL32(00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000,00000000), ref: 00AB29F0
                          • _free.LIBCMT ref: 00ABD838
                          • _free.LIBCMT ref: 00ABD843
                          • _free.LIBCMT ref: 00ABD897
                          • _free.LIBCMT ref: 00ABD8A2
                          • _free.LIBCMT ref: 00ABD8AD
                          • _free.LIBCMT ref: 00ABD8B8
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free$ErrorFreeHeapLast
                          • String ID:
                          • API String ID: 776569668-0
                          • Opcode ID: d5e9bbcb1dbdafe4c8d3bd98f36014f41f46dc5d4a3df644b036f3c2391e0fc8
                          • Instruction ID: 7627fd8b8bcd8941fe5ba718860ee3779f140c146e87d6a7afa717973869af4d
                          • Opcode Fuzzy Hash: d5e9bbcb1dbdafe4c8d3bd98f36014f41f46dc5d4a3df644b036f3c2391e0fc8
                          • Instruction Fuzzy Hash: 75111971940B44BBDA21BFB0CE47FCB7BDCAF44700F404C26B29DAA493EA65B5458760
                          APIs
                          • GetModuleHandleW.KERNEL32(00000000,?,?,00000100,00000000), ref: 00AEDA74
                          • LoadStringW.USER32(00000000), ref: 00AEDA7B
                          • GetModuleHandleW.KERNEL32(00000000,00001389,?,00000100), ref: 00AEDA91
                          • LoadStringW.USER32(00000000), ref: 00AEDA98
                          • MessageBoxW.USER32(00000000,?,?,00011010), ref: 00AEDADC
                          Strings
                          • %s (%d) : ==> %s: %s %s, xrefs: 00AEDAB9
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: HandleLoadModuleString$Message
                          • String ID: %s (%d) : ==> %s: %s %s
                          • API String ID: 4072794657-3128320259
                          • Opcode ID: dd6d765ffd23e42e18eeb817ebee24edf15613813ed4c132a0b94322fc60e90c
                          • Instruction ID: 2e4d3e51758aa231a855a3f2bf5cdcbf1c297741e10022ec7a318b1867509af5
                          • Opcode Fuzzy Hash: dd6d765ffd23e42e18eeb817ebee24edf15613813ed4c132a0b94322fc60e90c
                          • Instruction Fuzzy Hash: E50186F6540208BFEB509BA09D89EE7377CE708701F8044A1B706E7041EA749E844F74
                          APIs
                          • InterlockedExchange.KERNEL32(00C43250,00C43250), ref: 00AF097B
                          • EnterCriticalSection.KERNEL32(00C43230,00000000), ref: 00AF098D
                          • TerminateThread.KERNEL32(?,000001F6), ref: 00AF099B
                          • WaitForSingleObject.KERNEL32(?,000003E8), ref: 00AF09A9
                          • CloseHandle.KERNEL32(?), ref: 00AF09B8
                          • InterlockedExchange.KERNEL32(00C43250,000001F6), ref: 00AF09C8
                          • LeaveCriticalSection.KERNEL32(00C43230), ref: 00AF09CF
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CriticalExchangeInterlockedSection$CloseEnterHandleLeaveObjectSingleTerminateThreadWait
                          • String ID:
                          • API String ID: 3495660284-0
                          • Opcode ID: d4bda4307dfd8225ac81e3488e2a2616df72073150d6d2584b05e4b350e12ae9
                          • Instruction ID: 361feb85cf4f31612c2f9905d5574ac0df9effc2aa8d9a28d04e8e07098a81bf
                          • Opcode Fuzzy Hash: d4bda4307dfd8225ac81e3488e2a2616df72073150d6d2584b05e4b350e12ae9
                          • Instruction Fuzzy Hash: 05F01D31482612BBD7515B94EE88AE67E35BF01702F905015F201518A1DB749465CF90
                          APIs
                          • GetClientRect.USER32(?,?), ref: 00A85D30
                          • GetWindowRect.USER32(?,?), ref: 00A85D71
                          • ScreenToClient.USER32(?,?), ref: 00A85D99
                          • GetClientRect.USER32(?,?), ref: 00A85ED7
                          • GetWindowRect.USER32(?,?), ref: 00A85EF8
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Rect$Client$Window$Screen
                          • String ID:
                          • API String ID: 1296646539-0
                          • Opcode ID: 4c233fb6629d74862b0a701bd72164863af2e2690482cc56f11ed31ca63cde6b
                          • Instruction ID: a296f5ab2ebc63c359e720453230cc4568dea249bef8ae05a6ff688dd7ebf28f
                          • Opcode Fuzzy Hash: 4c233fb6629d74862b0a701bd72164863af2e2690482cc56f11ed31ca63cde6b
                          • Instruction Fuzzy Hash: DEB15835A00A4ADBDB14DFB9C880BEAB7F1FF58310F14841AECA9D7250DB34AA51DB54
                          APIs
                          • __allrem.LIBCMT ref: 00AB00BA
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00AB00D6
                          • __allrem.LIBCMT ref: 00AB00ED
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00AB010B
                          • __allrem.LIBCMT ref: 00AB0122
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00AB0140
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@
                          • String ID:
                          • API String ID: 1992179935-0
                          • Opcode ID: c0aa086816e9a6b10c8594d9af3fc1b6618250ddc70608c46d0048b3e4fbc764
                          • Instruction ID: c40d3176f160e4d1aa8a065752494190d0be2c4929efa6c321be3b223aa06877
                          • Opcode Fuzzy Hash: c0aa086816e9a6b10c8594d9af3fc1b6618250ddc70608c46d0048b3e4fbc764
                          • Instruction Fuzzy Hash: 0A81C472A007069FE728AB68DD41FAB73EDAF42364F24462EF551D76C2E7B0D9008790
                          APIs
                            • Part of subcall function 00B03149: select.WSOCK32(00000000,?,00000000,00000000,?,?,?,00000000,?,?,?,00B0101C,00000000,?,?,00000000), ref: 00B03195
                          • __WSAFDIsSet.WSOCK32(00000000,?,00000000,00000000,?,00000064,00000000), ref: 00B01DC0
                          • #17.WSOCK32(00000000,?,?,00000000,?,00000010), ref: 00B01DE1
                          • WSAGetLastError.WSOCK32 ref: 00B01DF2
                          • inet_ntoa.WSOCK32(?), ref: 00B01E8C
                          • htons.WSOCK32(?,?,?,?,?), ref: 00B01EDB
                          • _strlen.LIBCMT ref: 00B01F35
                            • Part of subcall function 00AE39E8: _strlen.LIBCMT ref: 00AE39F2
                            • Part of subcall function 00A86D9E: MultiByteToWideChar.KERNEL32(00000000,00000001,?,?,00000000,00000000,00000002,?,?,?,?,00A9CF58,?,?,?), ref: 00A86DBA
                            • Part of subcall function 00A86D9E: MultiByteToWideChar.KERNEL32(00000000,00000001,?,?,00000000,?,?,?,00A9CF58,?,?,?), ref: 00A86DED
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ByteCharMultiWide_strlen$ErrorLasthtonsinet_ntoaselect
                          • String ID:
                          • API String ID: 1923757996-0
                          • Opcode ID: ef8033ef4525ae246275c9a257deb82ee274d1417993f05242964c1def6f3480
                          • Instruction ID: 71880350eff5d1d0e6000fe77fb18ffa9a74f4a01d51babe0b216f5851ef9706
                          • Opcode Fuzzy Hash: ef8033ef4525ae246275c9a257deb82ee274d1417993f05242964c1def6f3480
                          • Instruction Fuzzy Hash: B0A1E031204341AFD728EF28C895E2A7BE5EF85318F54899CF4565B2E2DB31ED42CB91
                          APIs
                          • MultiByteToWideChar.KERNEL32(00000001,00000000,?,?,00000000,00000000,?,00AA82D9,00AA82D9,?,?,?,00AB644F,00000001,00000001,8BE85006), ref: 00AB6258
                          • MultiByteToWideChar.KERNEL32(00000001,00000001,?,?,00000000,?,?,?,?,00AB644F,00000001,00000001,8BE85006,?,?,?), ref: 00AB62DE
                          • WideCharToMultiByte.KERNEL32(00000001,00000000,00000000,00000000,?,8BE85006,00000000,00000000,?,00000400,00000000,?,00000000,00000000,00000000,00000000), ref: 00AB63D8
                          • __freea.LIBCMT ref: 00AB63E5
                            • Part of subcall function 00AB3820: RtlAllocateHeap.NTDLL(00000000,?,00B51444,?,00A9FDF5,?,?,00A8A976,00000010,00B51440,00A813FC,?,00A813C6,?,00A81129), ref: 00AB3852
                          • __freea.LIBCMT ref: 00AB63EE
                          • __freea.LIBCMT ref: 00AB6413
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ByteCharMultiWide__freea$AllocateHeap
                          • String ID:
                          • API String ID: 1414292761-0
                          • Opcode ID: a36dfd9f7c267c8a35026dabae8843c3ff91ac0ef5b1734827786e8a4b91b463
                          • Instruction ID: e15b9b5736a8dc993ab518367dae161aa0cbe93eefd0493466eb608c9497cf49
                          • Opcode Fuzzy Hash: a36dfd9f7c267c8a35026dabae8843c3ff91ac0ef5b1734827786e8a4b91b463
                          • Instruction Fuzzy Hash: E551BF72A00216ABEB258F64DD81EEF7BADEB44750F154629FC05DB142EB38DC54C6A0
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00B0C998: CharUpperBuffW.USER32(?,?,?,?,?,?,?,00B0B6AE,?,?), ref: 00B0C9B5
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0C9F1
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0CA68
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0CA9E
                          • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 00B0BCCA
                          • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 00B0BD25
                          • RegCloseKey.ADVAPI32(00000000), ref: 00B0BD6A
                          • RegEnumValueW.ADVAPI32(?,-00000001,?,?,00000000,?,00000000,00000000), ref: 00B0BD99
                          • RegCloseKey.ADVAPI32(?,?,00000000), ref: 00B0BDF3
                          • RegCloseKey.ADVAPI32(?), ref: 00B0BDFF
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$Close$BuffCharConnectEnumOpenRegistryUpperValue
                          • String ID:
                          • API String ID: 1120388591-0
                          • Opcode ID: 9cda10f7ee77f79caa02e68cb7cf2c07a4a8d70bf6beeb765864771f7513dc9d
                          • Instruction ID: bfef971cf8a59749b392cbe099a489505d3302fa8fdf688503875b14c8b6dfa4
                          • Opcode Fuzzy Hash: 9cda10f7ee77f79caa02e68cb7cf2c07a4a8d70bf6beeb765864771f7513dc9d
                          • Instruction Fuzzy Hash: 1481C430208241EFD714DF24C885E6ABBE5FF84308F1489ACF4598B2A2DB31ED45CB92
                          APIs
                          • VariantInit.OLEAUT32(00000035), ref: 00ADF7B9
                          • SysAllocString.OLEAUT32(00000001), ref: 00ADF860
                          • VariantCopy.OLEAUT32(00ADFA64,00000000), ref: 00ADF889
                          • VariantClear.OLEAUT32(00ADFA64), ref: 00ADF8AD
                          • VariantCopy.OLEAUT32(00ADFA64,00000000), ref: 00ADF8B1
                          • VariantClear.OLEAUT32(?), ref: 00ADF8BB
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Variant$ClearCopy$AllocInitString
                          • String ID:
                          • API String ID: 3859894641-0
                          • Opcode ID: 8c3024e5a9792dff622c09dc58c1aab861d285fdae632426337179d88f9b1426
                          • Instruction ID: b8c84c0dbe44eaee2a14ef51fd4ab6fa1c41c7981546c64fbed2b833c6b4f750
                          • Opcode Fuzzy Hash: 8c3024e5a9792dff622c09dc58c1aab861d285fdae632426337179d88f9b1426
                          • Instruction Fuzzy Hash: DE51C231A50310BECF24AB65D8A5B3AB3E8EF45710B248467E907DF391DB708D40CBA6
                          APIs
                            • Part of subcall function 00A87620: _wcslen.LIBCMT ref: 00A87625
                            • Part of subcall function 00A86B57: _wcslen.LIBCMT ref: 00A86B6A
                          • GetOpenFileNameW.COMDLG32(00000058), ref: 00AF94E5
                          • _wcslen.LIBCMT ref: 00AF9506
                          • _wcslen.LIBCMT ref: 00AF952D
                          • GetSaveFileNameW.COMDLG32(00000058), ref: 00AF9585
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$FileName$OpenSave
                          • String ID: X
                          • API String ID: 83654149-3081909835
                          • Opcode ID: 296acb02ab25626be02828253dcf1b508271702b4d4d0c70e598234a3c2e2a40
                          • Instruction ID: 1ab59cdafdf72a0c5e6b07afcb10d17dc82c285870e0fc96e0b1b5a3dffb7b48
                          • Opcode Fuzzy Hash: 296acb02ab25626be02828253dcf1b508271702b4d4d0c70e598234a3c2e2a40
                          • Instruction Fuzzy Hash: 12E1BE716083018FD724EF64C981B6BB7E4BF85314F04896DF9999B2A2DB31ED05CB92
                          APIs
                            • Part of subcall function 00A99BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 00A99BB2
                          • BeginPaint.USER32(?,?,?), ref: 00A99241
                          • GetWindowRect.USER32(?,?), ref: 00A992A5
                          • ScreenToClient.USER32(?,?), ref: 00A992C2
                          • SetViewportOrgEx.GDI32(00000000,?,?,00000000), ref: 00A992D3
                          • EndPaint.USER32(?,?,?,?,?), ref: 00A99321
                          • Rectangle.GDI32(00000000,00000000,00000000,?,?), ref: 00AD71EA
                            • Part of subcall function 00A99339: BeginPath.GDI32(00000000), ref: 00A99357
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: BeginPaintWindow$ClientLongPathRectRectangleScreenViewport
                          • String ID:
                          • API String ID: 3050599898-0
                          • Opcode ID: 9fd3a12844867f5b1613da075d0c29b5eceb05cc9f1432b3f1db015d4bd30d54
                          • Instruction ID: 0aaae6c153c77d77c89dd1fac1154679ba30404478267c87f6536bedd8b11ca5
                          • Opcode Fuzzy Hash: 9fd3a12844867f5b1613da075d0c29b5eceb05cc9f1432b3f1db015d4bd30d54
                          • Instruction Fuzzy Hash: 9D418E70204300AFDB21DF28C885FAB7BF8EB56321F14066DF9558B2B1DB719846DB61
                          APIs
                          • InterlockedExchange.KERNEL32(?,000001F5), ref: 00AF080C
                          • ReadFile.KERNEL32(?,?,0000FFFF,?,00000000), ref: 00AF0847
                          • EnterCriticalSection.KERNEL32(?), ref: 00AF0863
                          • LeaveCriticalSection.KERNEL32(?), ref: 00AF08DC
                          • ReadFile.KERNEL32(?,?,0000FFFF,00000000,00000000), ref: 00AF08F3
                          • InterlockedExchange.KERNEL32(?,000001F6), ref: 00AF0921
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CriticalExchangeFileInterlockedReadSection$EnterLeave
                          • String ID:
                          • API String ID: 3368777196-0
                          • Opcode ID: 1873e8cf3cbd58960f5a935b9442c44f7edea5bf06af501a47e71bc7a696fcaf
                          • Instruction ID: 6423b650f4bdd81d1de55846323c92d5b5a7fdb15cd712697b960d6420d9cf20
                          • Opcode Fuzzy Hash: 1873e8cf3cbd58960f5a935b9442c44f7edea5bf06af501a47e71bc7a696fcaf
                          • Instruction Fuzzy Hash: 2B415971A00209AFDF14AF94DC85AAA77B8FF04310F1480A5ED00AB297DB30DE64DBA4
                          APIs
                          • ShowWindow.USER32(FFFFFFFF,00000000,?,00000000,00000000,?,00ADF3AB,00000000,?,?,00000000,?,00AD682C,00000004,00000000,00000000), ref: 00B1824C
                          • EnableWindow.USER32(?,00000000), ref: 00B18272
                          • ShowWindow.USER32(FFFFFFFF,00000000), ref: 00B182D1
                          • ShowWindow.USER32(?,00000004), ref: 00B182E5
                          • EnableWindow.USER32(?,00000001), ref: 00B1830B
                          • SendMessageW.USER32(?,0000130C,00000000,00000000), ref: 00B1832F
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Show$Enable$MessageSend
                          • String ID:
                          • API String ID: 642888154-0
                          • Opcode ID: 9eb161576aa122233e778abd93b8c5735db7aa5f597dfea22672cb43aacef142
                          • Instruction ID: c2c1a99d1786e1c9f2797adc249fbbc96541d1c84396b6f178d6509a1695d069
                          • Opcode Fuzzy Hash: 9eb161576aa122233e778abd93b8c5735db7aa5f597dfea22672cb43aacef142
                          • Instruction Fuzzy Hash: 8A41B234601644EFDB22CF18D899BE47BE0FB4A715F5841E9F5184B2A2CB71AC81CF90
                          APIs
                          • IsWindowVisible.USER32(?), ref: 00AE4C95
                          • SendMessageW.USER32(?,0000000E,00000000,00000000), ref: 00AE4CB2
                          • SendMessageW.USER32(?,0000000D,00000001,00000000), ref: 00AE4CEA
                          • _wcslen.LIBCMT ref: 00AE4D08
                          • CharUpperBuffW.USER32(00000000,00000000,?,?,?,?), ref: 00AE4D10
                          • _wcsstr.LIBVCRUNTIME ref: 00AE4D1A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$BuffCharUpperVisibleWindow_wcslen_wcsstr
                          • String ID:
                          • API String ID: 72514467-0
                          • Opcode ID: b3812fd16e3d78d47000139b63bb591a36e4b887e8f333d3b5007567fcb9271a
                          • Instruction ID: 28eadf9c1aa6a141ad4e89bddae15ed639b47a8997e4fa5e9467c5744639a5ae
                          • Opcode Fuzzy Hash: b3812fd16e3d78d47000139b63bb591a36e4b887e8f333d3b5007567fcb9271a
                          • Instruction Fuzzy Hash: C921C9716042447FEB155B3A9D49E7B7FACDF49750F108029F805CB191DE65DC4196A0
                          APIs
                            • Part of subcall function 00A83AA2: GetFullPathNameW.KERNEL32(?,00007FFF,?,00000000,?,?,00A83A97,?,?,00A82E7F,?,?,?,00000000), ref: 00A83AC2
                          • _wcslen.LIBCMT ref: 00AF587B
                          • CoInitialize.OLE32(00000000), ref: 00AF5995
                          • CoCreateInstance.OLE32(00B1FCF8,00000000,00000001,00B1FB68,?), ref: 00AF59AE
                          • CoUninitialize.OLE32 ref: 00AF59CC
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CreateFullInitializeInstanceNamePathUninitialize_wcslen
                          • String ID: .lnk
                          • API String ID: 3172280962-24824748
                          • Opcode ID: f2982e31b4c69858720ba3ff7d09a7539d4775937a9dc4c5bd2ccf35576ff670
                          • Instruction ID: d425a1a16560f935cb02dae4504f06f652ac21328d55d758e547e0223683ff4c
                          • Opcode Fuzzy Hash: f2982e31b4c69858720ba3ff7d09a7539d4775937a9dc4c5bd2ccf35576ff670
                          • Instruction Fuzzy Hash: 9CD17471A087059FC718EF64C58492ABBE1FF89710F14885DFA8A9B361DB31EC45CB92
                          APIs
                            • Part of subcall function 00AE0FB4: GetTokenInformation.ADVAPI32(?,00000002,?,00000000,?), ref: 00AE0FCA
                            • Part of subcall function 00AE0FB4: GetLastError.KERNEL32(?,00000002,?,00000000,?), ref: 00AE0FD6
                            • Part of subcall function 00AE0FB4: GetProcessHeap.KERNEL32(00000008,?,?,00000002,?,00000000,?), ref: 00AE0FE5
                            • Part of subcall function 00AE0FB4: HeapAlloc.KERNEL32(00000000,?,00000002,?,00000000,?), ref: 00AE0FEC
                            • Part of subcall function 00AE0FB4: GetTokenInformation.ADVAPI32(?,00000002,00000000,?,?,?,00000002,?,00000000,?), ref: 00AE1002
                          • GetLengthSid.ADVAPI32(?,00000000,00AE1335), ref: 00AE17AE
                          • GetProcessHeap.KERNEL32(00000008,00000000), ref: 00AE17BA
                          • HeapAlloc.KERNEL32(00000000), ref: 00AE17C1
                          • CopySid.ADVAPI32(00000000,00000000,?), ref: 00AE17DA
                          • GetProcessHeap.KERNEL32(00000000,00000000,00AE1335), ref: 00AE17EE
                          • HeapFree.KERNEL32(00000000), ref: 00AE17F5
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Heap$Process$AllocInformationToken$CopyErrorFreeLastLength
                          • String ID:
                          • API String ID: 3008561057-0
                          • Opcode ID: 12e4c4722c1c92fab6fbc71cc2f0c107dc39fb726de4470648b4e202a8632fb4
                          • Instruction ID: c3ba629bd7b4458a00da76b2ff7d42c035f21ca432366961c7feffd39e327245
                          • Opcode Fuzzy Hash: 12e4c4722c1c92fab6fbc71cc2f0c107dc39fb726de4470648b4e202a8632fb4
                          • Instruction Fuzzy Hash: 51118B32684215FFDB109FA5CC49FEE7BB9EB46755F608018F981A7210DB36A944CF60
                          APIs
                          • GetCurrentProcess.KERNEL32(0000000A,00000004), ref: 00AE14FF
                          • OpenProcessToken.ADVAPI32(00000000), ref: 00AE1506
                          • CreateEnvironmentBlock.USERENV(?,00000004,00000001), ref: 00AE1515
                          • CloseHandle.KERNEL32(00000004), ref: 00AE1520
                          • CreateProcessWithLogonW.ADVAPI32(?,?,?,00000000,00000000,?,?,00000000,?,?,?), ref: 00AE154F
                          • DestroyEnvironmentBlock.USERENV(00000000), ref: 00AE1563
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process$BlockCreateEnvironment$CloseCurrentDestroyHandleLogonOpenTokenWith
                          • String ID:
                          • API String ID: 1413079979-0
                          • Opcode ID: 83920c9b7897d048b4356cc22c68426079c3debc72a956854f4563c64e8865bb
                          • Instruction ID: 945887c71a6d70925096ce95ec89b4994816fffcb644aba296a4dd3df7d57272
                          • Opcode Fuzzy Hash: 83920c9b7897d048b4356cc22c68426079c3debc72a956854f4563c64e8865bb
                          • Instruction Fuzzy Hash: 6F1129B2540259ABDF118F98ED49FDE7BB9EF48744F048015FA05A21A0C7758E60DB60
                          APIs
                          • GetLastError.KERNEL32(?,?,00AA3379,00AA2FE5), ref: 00AA3390
                          • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 00AA339E
                          • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 00AA33B7
                          • SetLastError.KERNEL32(00000000,?,00AA3379,00AA2FE5), ref: 00AA3409
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorLastValue___vcrt_
                          • String ID:
                          • API String ID: 3852720340-0
                          • Opcode ID: a0c0429874d4ab4d62d521308618e54b4e618b3ecf62a56ff57fc029513298f7
                          • Instruction ID: 6c8d6fb14b0c67852ee7375bd3d4fadcdca05d0821f8ec4240137f9be1e236f0
                          • Opcode Fuzzy Hash: a0c0429874d4ab4d62d521308618e54b4e618b3ecf62a56ff57fc029513298f7
                          • Instruction Fuzzy Hash: 1701473760E311BFAEA62B747D856672E94EB0B7793300229F4208B2F0EF114E015154
                          APIs
                          • GetLastError.KERNEL32(?,?,00AB5686,00AC3CD6,?,00000000,?,00AB5B6A,?,?,?,?,?,00AAE6D1,?,00B48A48), ref: 00AB2D78
                          • _free.LIBCMT ref: 00AB2DAB
                          • _free.LIBCMT ref: 00AB2DD3
                          • SetLastError.KERNEL32(00000000,?,?,?,?,00AAE6D1,?,00B48A48,00000010,00A84F4A,?,?,00000000,00AC3CD6), ref: 00AB2DE0
                          • SetLastError.KERNEL32(00000000,?,?,?,?,00AAE6D1,?,00B48A48,00000010,00A84F4A,?,?,00000000,00AC3CD6), ref: 00AB2DEC
                          • _abort.LIBCMT ref: 00AB2DF2
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorLast$_free$_abort
                          • String ID:
                          • API String ID: 3160817290-0
                          • Opcode ID: fd5f3b9ba71b4d8319908ecb37fdab7a8dcc7ddbd7bec3fe2676eef5d097d542
                          • Instruction ID: fc5930b48c97609acc16879e1a26d36a835b27104895df6986ab3881421357a5
                          • Opcode Fuzzy Hash: fd5f3b9ba71b4d8319908ecb37fdab7a8dcc7ddbd7bec3fe2676eef5d097d542
                          • Instruction Fuzzy Hash: 32F0C83654560027D6123738BD0AFEA2B6DBFC67A1F24451AF824931D7EE3489014360
                          APIs
                            • Part of subcall function 00A99639: ExtCreatePen.GDI32(?,?,00000000,00000000,00000000,?,00000000), ref: 00A99693
                            • Part of subcall function 00A99639: SelectObject.GDI32(?,00000000), ref: 00A996A2
                            • Part of subcall function 00A99639: BeginPath.GDI32(?), ref: 00A996B9
                            • Part of subcall function 00A99639: SelectObject.GDI32(?,00000000), ref: 00A996E2
                          • MoveToEx.GDI32(?,-00000002,00000000,00000000), ref: 00B18A4E
                          • LineTo.GDI32(?,00000003,00000000), ref: 00B18A62
                          • MoveToEx.GDI32(?,00000000,-00000002,00000000), ref: 00B18A70
                          • LineTo.GDI32(?,00000000,00000003), ref: 00B18A80
                          • EndPath.GDI32(?), ref: 00B18A90
                          • StrokePath.GDI32(?), ref: 00B18AA0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Path$LineMoveObjectSelect$BeginCreateStroke
                          • String ID:
                          • API String ID: 43455801-0
                          • Opcode ID: 2bbfb1e3c53164749ed2953778e1006540d263323ffda9cbb104f7d9253ebba0
                          • Instruction ID: 84d33a33dad3f9b984e26e50338a38f40026862de4b134c3f8943c8ec6edfae0
                          • Opcode Fuzzy Hash: 2bbfb1e3c53164749ed2953778e1006540d263323ffda9cbb104f7d9253ebba0
                          • Instruction Fuzzy Hash: 3B11F776040108FFDB129F94DC88FEA7FACEB08350F40C462BA199A1A1CB719D55DBA0
                          APIs
                          • GetDC.USER32(00000000), ref: 00AE5218
                          • GetDeviceCaps.GDI32(00000000,00000058), ref: 00AE5229
                          • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00AE5230
                          • ReleaseDC.USER32(00000000,00000000), ref: 00AE5238
                          • MulDiv.KERNEL32(000009EC,?,00000000), ref: 00AE524F
                          • MulDiv.KERNEL32(000009EC,00000001,?), ref: 00AE5261
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CapsDevice$Release
                          • String ID:
                          • API String ID: 1035833867-0
                          • Opcode ID: 261d303609e92646e519b46b81605d9c0a9ed2c6f305f5d72ddbc819b889ee1d
                          • Instruction ID: 8fa66d471bd509ebbdff77d62cd3610dad0281bd6ea62a542d527ecc60670c79
                          • Opcode Fuzzy Hash: 261d303609e92646e519b46b81605d9c0a9ed2c6f305f5d72ddbc819b889ee1d
                          • Instruction Fuzzy Hash: 85014475E40714BBEB105BB69C49A9EBF78EF48751F148065FA05E7281DA709900CB60
                          APIs
                          • MapVirtualKeyW.USER32(0000005B,00000000), ref: 00A81BF4
                          • MapVirtualKeyW.USER32(00000010,00000000), ref: 00A81BFC
                          • MapVirtualKeyW.USER32(000000A0,00000000), ref: 00A81C07
                          • MapVirtualKeyW.USER32(000000A1,00000000), ref: 00A81C12
                          • MapVirtualKeyW.USER32(00000011,00000000), ref: 00A81C1A
                          • MapVirtualKeyW.USER32(00000012,00000000), ref: 00A81C22
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Virtual
                          • String ID:
                          • API String ID: 4278518827-0
                          • Opcode ID: 580f707b4b934048841ed907b1f485c34641248c53dbebaa8d6ba2310df5f25b
                          • Instruction ID: cbda5377ca47c1bfd8ac3a91766ede3dec1dcee5a3b9916193161a64f873b013
                          • Opcode Fuzzy Hash: 580f707b4b934048841ed907b1f485c34641248c53dbebaa8d6ba2310df5f25b
                          • Instruction Fuzzy Hash: 7D0167B0942B5ABDE3008F6A8C85B52FFA8FF19354F00411BA15C4BA42C7F5A864CBE5
                          APIs
                          • PostMessageW.USER32(?,00000010,00000000,00000000), ref: 00AEEB30
                          • SendMessageTimeoutW.USER32(?,00000010,00000000,00000000,00000002,000001F4,?), ref: 00AEEB46
                          • GetWindowThreadProcessId.USER32(?,?), ref: 00AEEB55
                          • OpenProcess.KERNEL32(001F0FFF,00000000,?,?,?,?,00000010,00000000,00000000,00000002,000001F4,?,?,00000010,00000000,00000000), ref: 00AEEB64
                          • TerminateProcess.KERNEL32(00000000,00000000,?,?,?,00000010,00000000,00000000,00000002,000001F4,?,?,00000010,00000000,00000000), ref: 00AEEB6E
                          • CloseHandle.KERNEL32(00000000,?,?,?,00000010,00000000,00000000,00000002,000001F4,?,?,00000010,00000000,00000000), ref: 00AEEB75
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process$Message$CloseHandleOpenPostSendTerminateThreadTimeoutWindow
                          • String ID:
                          • API String ID: 839392675-0
                          • Opcode ID: 6576059906f0f0cd4a84e9046b05536280f522b40756dfb6f9dca5dfb1630777
                          • Instruction ID: b271a851385e8b2faa98fbd964a4a30fe020b89b791adaa439d2e83a19ea91bf
                          • Opcode Fuzzy Hash: 6576059906f0f0cd4a84e9046b05536280f522b40756dfb6f9dca5dfb1630777
                          • Instruction Fuzzy Hash: D1F03072680158BBE72157529C0DEEF3E7CEFCAB11F408158F611E3091DBA05A01C6B5
                          APIs
                          • GetClientRect.USER32(?), ref: 00AD7452
                          • SendMessageW.USER32(?,00001328,00000000,?), ref: 00AD7469
                          • GetWindowDC.USER32(?), ref: 00AD7475
                          • GetPixel.GDI32(00000000,?,?), ref: 00AD7484
                          • ReleaseDC.USER32(?,00000000), ref: 00AD7496
                          • GetSysColor.USER32(00000005), ref: 00AD74B0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClientColorMessagePixelRectReleaseSendWindow
                          • String ID:
                          • API String ID: 272304278-0
                          • Opcode ID: b38f9855ba293a30a5336b2b6d546b377c80f7fefec4a9ef9b4d7cffc8320c97
                          • Instruction ID: c057263c196369b13403357d72787c84363ecad1ca5dcfe7d57b0f11d230bd01
                          • Opcode Fuzzy Hash: b38f9855ba293a30a5336b2b6d546b377c80f7fefec4a9ef9b4d7cffc8320c97
                          • Instruction Fuzzy Hash: 3D015231440215EFEB525FA4DC09BEA7FB6FB04321FA080A4F916A31A0CF311E51AB10
                          APIs
                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 00AE187F
                          • UnloadUserProfile.USERENV(?,?), ref: 00AE188B
                          • CloseHandle.KERNEL32(?), ref: 00AE1894
                          • CloseHandle.KERNEL32(?), ref: 00AE189C
                          • GetProcessHeap.KERNEL32(00000000,?), ref: 00AE18A5
                          • HeapFree.KERNEL32(00000000), ref: 00AE18AC
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CloseHandleHeap$FreeObjectProcessProfileSingleUnloadUserWait
                          • String ID:
                          • API String ID: 146765662-0
                          • Opcode ID: b4f788314fb77d54bc259720de87107d5748ad6600741d9f32dac8c3703c5ca4
                          • Instruction ID: 4be6d73b956bb1e9806e65697dddec0260e8a4c621bf1fd74b49d0d4793515ed
                          • Opcode Fuzzy Hash: b4f788314fb77d54bc259720de87107d5748ad6600741d9f32dac8c3703c5ca4
                          • Instruction Fuzzy Hash: F3E0E536484211BBDB015FA1ED0C98ABF3AFF49B22B90C220F225920B0CF729430DF50
                          APIs
                            • Part of subcall function 00A87620: _wcslen.LIBCMT ref: 00A87625
                          • GetMenuItemInfoW.USER32(?,?,00000000,?), ref: 00AEC6EE
                          • _wcslen.LIBCMT ref: 00AEC735
                          • SetMenuItemInfoW.USER32(?,?,00000000,?), ref: 00AEC79C
                          • SetMenuDefaultItem.USER32(?,000000FF,00000000), ref: 00AEC7CA
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ItemMenu$Info_wcslen$Default
                          • String ID: 0
                          • API String ID: 1227352736-4108050209
                          • Opcode ID: e1b97d79fab28c3f818be9535694d5eb233a7e4170c79412904bea233ba89753
                          • Instruction ID: 660a953d7a0b320aadf56da785d76a41a008da4b58761126d6bbbcaa5a8bcb66
                          • Opcode Fuzzy Hash: e1b97d79fab28c3f818be9535694d5eb233a7e4170c79412904bea233ba89753
                          • Instruction Fuzzy Hash: C851D5716043809BD715EF2AC985B6BBBE8AF49324F040A2DF995D31E0DB70DD46CB52
                          APIs
                          • ShellExecuteExW.SHELL32(0000003C), ref: 00B0AEA3
                            • Part of subcall function 00A87620: _wcslen.LIBCMT ref: 00A87625
                          • GetProcessId.KERNEL32(00000000), ref: 00B0AF38
                          • CloseHandle.KERNEL32(00000000), ref: 00B0AF67
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CloseExecuteHandleProcessShell_wcslen
                          • String ID: <$@
                          • API String ID: 146682121-1426351568
                          • Opcode ID: 32cad4c9500c3febe4ba5d15fe15ddb8684387ea50b352fc7e6fff3e25e48ecf
                          • Instruction ID: 56afc1410e5147de94487d5ee8ef4c2c17128ad85e3371ce3c7c858a4f086e82
                          • Opcode Fuzzy Hash: 32cad4c9500c3febe4ba5d15fe15ddb8684387ea50b352fc7e6fff3e25e48ecf
                          • Instruction Fuzzy Hash: EC715971A00615DFCB14EF54C584A9EBBF0FF08314F1488A9E856AB7A2CB74ED45CBA1
                          APIs
                          • CoCreateInstance.OLE32(?,00000000,00000005,?,?,?,?,?,?,?,?,?,?,?), ref: 00AE7206
                          • SetErrorMode.KERNEL32(00000001,?,?,?,?,?,?,?,?,?), ref: 00AE723C
                          • GetProcAddress.KERNEL32(?,DllGetClassObject), ref: 00AE724D
                          • SetErrorMode.KERNEL32(00000000,?,?,?,?,?,?,?,?,?), ref: 00AE72CF
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorMode$AddressCreateInstanceProc
                          • String ID: DllGetClassObject
                          • API String ID: 753597075-1075368562
                          • Opcode ID: 9ec3080c5e5b77d83bb63d750cd83e654426c3683c04b362721175ac20281e82
                          • Instruction ID: c3922e3cb985681aad3096665498e6778f6c3ab11f6f9bdc5fbf80c3b67838e8
                          • Opcode Fuzzy Hash: 9ec3080c5e5b77d83bb63d750cd83e654426c3683c04b362721175ac20281e82
                          • Instruction Fuzzy Hash: 46416D71A04245EFDB15CF55C884AEE7BB9EF45310F2480A9BE099F24AD7B1DE44CBA0
                          APIs
                          • GetMenuItemInfoW.USER32(?,000000FF,00000000,00000030), ref: 00B13E35
                          • IsMenu.USER32(?), ref: 00B13E4A
                          • InsertMenuItemW.USER32(?,?,00000001,00000030), ref: 00B13E92
                          • DrawMenuBar.USER32 ref: 00B13EA5
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Menu$Item$DrawInfoInsert
                          • String ID: 0
                          • API String ID: 3076010158-4108050209
                          • Opcode ID: 61c9628eb7d476b52fbd754df7a1a3f5c9689485a9de5c05ff097c97d8a0fc2c
                          • Instruction ID: 3d8acdc41e2394227b1372015beef4b777dc578685be406fa8b57af6e3a2fbd7
                          • Opcode Fuzzy Hash: 61c9628eb7d476b52fbd754df7a1a3f5c9689485a9de5c05ff097c97d8a0fc2c
                          • Instruction Fuzzy Hash: 13414A76A00309EFDB10DF54D884AEABBF9FF49750F4441A9E905A7290E730AE85CF60
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00AE3CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00AE3CCA
                          • SendMessageW.USER32(?,00000188,00000000,00000000), ref: 00AE1E66
                          • SendMessageW.USER32(?,0000018A,00000000,00000000), ref: 00AE1E79
                          • SendMessageW.USER32(?,00000189,?,00000000), ref: 00AE1EA9
                            • Part of subcall function 00A86B57: _wcslen.LIBCMT ref: 00A86B6A
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$_wcslen$ClassName
                          • String ID: ComboBox$ListBox
                          • API String ID: 2081771294-1403004172
                          • Opcode ID: 80ed36505a50c99cf1c6148f89dffb87065b1bbc2f0867561eeb1aa6b8a0f8d0
                          • Instruction ID: ddf55f4979181445febf193b3d9ba4a558a62e0427d5071bab85bddea01ddba0
                          • Opcode Fuzzy Hash: 80ed36505a50c99cf1c6148f89dffb87065b1bbc2f0867561eeb1aa6b8a0f8d0
                          • Instruction Fuzzy Hash: 76217871A40144BFDB14ABB6CD4ACFFBBB8EF41350B144519F821A31E1DB384E0A8720
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen
                          • String ID: HKEY_LOCAL_MACHINE$HKLM
                          • API String ID: 176396367-4004644295
                          • Opcode ID: bf6f51837b1ff7e3761d4d13aa3d1e32aab95ceea163c38b243305c82c85ca19
                          • Instruction ID: 7ae5777d5208230e6749e9898bb4aa061b97bdc466cb0d0ab4c6995139a4066a
                          • Opcode Fuzzy Hash: bf6f51837b1ff7e3761d4d13aa3d1e32aab95ceea163c38b243305c82c85ca19
                          • Instruction Fuzzy Hash: 2931F733B0016A4BCB20DF6C89501BF3FD1DBA1790B1542A9E8556B2DDEB70CE44D3A0
                          APIs
                          • SendMessageW.USER32(00000000,00000467,00000000,?), ref: 00B12F8D
                          • LoadLibraryW.KERNEL32(?), ref: 00B12F94
                          • SendMessageW.USER32(?,00000467,00000000,00000000), ref: 00B12FA9
                          • DestroyWindow.USER32(?), ref: 00B12FB1
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$DestroyLibraryLoadWindow
                          • String ID: SysAnimate32
                          • API String ID: 3529120543-1011021900
                          • Opcode ID: f72ecb5bb3c94583cc91ce673ab36cef24a78f71b15a41fea925d61aa8ffe2a7
                          • Instruction ID: a62f8c2378ad97cc13f2f64dee9748f72c69ca538c8d0d82ec1b363fe06f2523
                          • Opcode Fuzzy Hash: f72ecb5bb3c94583cc91ce673ab36cef24a78f71b15a41fea925d61aa8ffe2a7
                          • Instruction Fuzzy Hash: 46216A71204209ABEB104F64DC84EFB77F9EB59364F904658FA50D71A0D771DCA29760
                          APIs
                          • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,?,00AA4D1E,00AB28E9,?,00AA4CBE,00AB28E9,00B488B8,0000000C,00AA4E15,00AB28E9,00000002), ref: 00AA4D8D
                          • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00AA4DA0
                          • FreeLibrary.KERNEL32(00000000,?,?,?,00AA4D1E,00AB28E9,?,00AA4CBE,00AB28E9,00B488B8,0000000C,00AA4E15,00AB28E9,00000002,00000000), ref: 00AA4DC3
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AddressFreeHandleLibraryModuleProc
                          • String ID: CorExitProcess$mscoree.dll
                          • API String ID: 4061214504-1276376045
                          • Opcode ID: fc197995f3da20a1f803a7987253a4c56e285cfcc2e2fcab4076fb21c4b68aa7
                          • Instruction ID: ae363e3fd7d1776cc4225d9d09a9a4993c8a094c497185fad772ec176909b36b
                          • Opcode Fuzzy Hash: fc197995f3da20a1f803a7987253a4c56e285cfcc2e2fcab4076fb21c4b68aa7
                          • Instruction Fuzzy Hash: 70F03C35A80218BBDB119F94DC49BEEBFA5EF49751F4040A4B809A32A0CF719E50CB90
                          APIs
                          • LoadLibraryA.KERNEL32 ref: 00ADD3AD
                          • GetProcAddress.KERNEL32(00000000,GetSystemWow64DirectoryW), ref: 00ADD3BF
                          • FreeLibrary.KERNEL32(00000000), ref: 00ADD3E5
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Library$AddressFreeLoadProc
                          • String ID: GetSystemWow64DirectoryW$X64
                          • API String ID: 145871493-2590602151
                          • Opcode ID: 1d3aeaf93421fbfebbf30a953d8abcb8fdc008619497b41d4c4a9b2ca64c658f
                          • Instruction ID: 00ac5bcf8a6b975e3fa6ad3c1578dd68f903f9adb1895c06e5ea1ad3f4063d93
                          • Opcode Fuzzy Hash: 1d3aeaf93421fbfebbf30a953d8abcb8fdc008619497b41d4c4a9b2ca64c658f
                          • Instruction Fuzzy Hash: DCF055314C5A20ABD73017148C18EED7B70AF00702BA4C087F807FA318DF30CE808682
                          APIs
                          • LoadLibraryA.KERNEL32(kernel32.dll,?,?,00A84EDD,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84E9C
                          • GetProcAddress.KERNEL32(00000000,Wow64DisableWow64FsRedirection), ref: 00A84EAE
                          • FreeLibrary.KERNEL32(00000000,?,?,00A84EDD,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84EC0
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Library$AddressFreeLoadProc
                          • String ID: Wow64DisableWow64FsRedirection$kernel32.dll
                          • API String ID: 145871493-3689287502
                          • Opcode ID: 1a367b8077c281265af25e17abe02863e92dcfe061aec8b9d04cb172ab391529
                          • Instruction ID: 03b7434c5cdd4181407a344d5b23d4ce28abeddab8d04186398b51f886fe1501
                          • Opcode Fuzzy Hash: 1a367b8077c281265af25e17abe02863e92dcfe061aec8b9d04cb172ab391529
                          • Instruction Fuzzy Hash: 92E0CD35A855236BD3312B256C18BDF6A94AF85F627454115FC04F3114DF64CD0141A0
                          APIs
                          • LoadLibraryA.KERNEL32(kernel32.dll,?,?,00AC3CDE,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84E62
                          • GetProcAddress.KERNEL32(00000000,Wow64RevertWow64FsRedirection), ref: 00A84E74
                          • FreeLibrary.KERNEL32(00000000,?,?,00AC3CDE,?,00B51418,00000001,>>>AUTOIT NO CMDEXECUTE<<<,?,?,?,00000000), ref: 00A84E87
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Library$AddressFreeLoadProc
                          • String ID: Wow64RevertWow64FsRedirection$kernel32.dll
                          • API String ID: 145871493-1355242751
                          • Opcode ID: 1ef6c721cced8e3ec2ee4b20b2c810f8ec374ab6d6e020bf6cc5bc539804f888
                          • Instruction ID: 3b20489445cc3f30b94d434c12b42f6d28f98ba7531ff156146d258488b92e85
                          • Opcode Fuzzy Hash: 1ef6c721cced8e3ec2ee4b20b2c810f8ec374ab6d6e020bf6cc5bc539804f888
                          • Instruction Fuzzy Hash: 1BD012355826226756222B256C18ECB6E58AF89F513454565F905F3124CF60CE2186D0
                          APIs
                          • DeleteFileW.KERNEL32(?,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004), ref: 00AF2C05
                          • DeleteFileW.KERNEL32(?), ref: 00AF2C87
                          • CopyFileW.KERNEL32(?,?,00000000,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004,00000001), ref: 00AF2C9D
                          • DeleteFileW.KERNEL32(?,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004), ref: 00AF2CAE
                          • DeleteFileW.KERNEL32(?,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004,00000001,?,?,00000004), ref: 00AF2CC0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: File$Delete$Copy
                          • String ID:
                          • API String ID: 3226157194-0
                          • Opcode ID: 17b26b463a8f62e86e3de783b1aeec1f22b20ed83c69420e546116911dc94a32
                          • Instruction ID: 777463fde0cdc58254c19feea553f5b1f66282cbc349eba5df0bec708d5f58fb
                          • Opcode Fuzzy Hash: 17b26b463a8f62e86e3de783b1aeec1f22b20ed83c69420e546116911dc94a32
                          • Instruction Fuzzy Hash: 03B11C71D0011DABDF11EBE4CD85EEEBBBDEF49350F1040A6FA09A7191EB309A448B61
                          APIs
                          • GetCurrentProcessId.KERNEL32 ref: 00B0A427
                          • OpenProcess.KERNEL32(00000410,00000000,00000000), ref: 00B0A435
                          • GetProcessIoCounters.KERNEL32(00000000,?), ref: 00B0A468
                          • CloseHandle.KERNEL32(?), ref: 00B0A63D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process$CloseCountersCurrentHandleOpen
                          • String ID:
                          • API String ID: 3488606520-0
                          • Opcode ID: e41cd924810e932e462354c39ce61b9144555b9f187cb9526d9aefc5b92dd6fb
                          • Instruction ID: 6740545734124a24a559615ceb5a9feff304adcd197dfbc20c04f007c715b5b4
                          • Opcode Fuzzy Hash: e41cd924810e932e462354c39ce61b9144555b9f187cb9526d9aefc5b92dd6fb
                          • Instruction Fuzzy Hash: C4A19071604300AFE720EF24D986F2ABBE5AF84714F14885DF55A9B3D2DB71EC418B92
                          APIs
                            • Part of subcall function 00AEDDE0: GetFullPathNameW.KERNEL32(00000000,00007FFF,?,?,?,?,?,?,00AECF22,?), ref: 00AEDDFD
                            • Part of subcall function 00AEDDE0: GetFullPathNameW.KERNEL32(?,00007FFF,?,?,?,?,?,00AECF22,?), ref: 00AEDE16
                            • Part of subcall function 00AEE199: GetFileAttributesW.KERNEL32(?,00AECF95), ref: 00AEE19A
                          • lstrcmpiW.KERNEL32(?,?), ref: 00AEE473
                          • MoveFileW.KERNEL32(?,?), ref: 00AEE4AC
                          • _wcslen.LIBCMT ref: 00AEE5EB
                          • _wcslen.LIBCMT ref: 00AEE603
                          • SHFileOperationW.SHELL32(?,?,?,?,?,?), ref: 00AEE650
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: File$FullNamePath_wcslen$AttributesMoveOperationlstrcmpi
                          • String ID:
                          • API String ID: 3183298772-0
                          • Opcode ID: 7981b746887fc97c421dd940dd5d0c72fb31a6563c3b62fafa66ff6b69ed98f8
                          • Instruction ID: de06c2eb19446bfea6a7a9181b1722f4a6bd2ddcc23ef07ad9ea2a6257e9e7fa
                          • Opcode Fuzzy Hash: 7981b746887fc97c421dd940dd5d0c72fb31a6563c3b62fafa66ff6b69ed98f8
                          • Instruction Fuzzy Hash: 9F5184B24083859BC724EBA5DD819EFB3ECAF85340F00491EF589D3191EF75A68C8766
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00B0C998: CharUpperBuffW.USER32(?,?,?,?,?,?,?,00B0B6AE,?,?), ref: 00B0C9B5
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0C9F1
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0CA68
                            • Part of subcall function 00B0C998: _wcslen.LIBCMT ref: 00B0CA9E
                          • RegConnectRegistryW.ADVAPI32(?,?,?), ref: 00B0BAA5
                          • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 00B0BB00
                          • RegEnumKeyExW.ADVAPI32(?,-00000001,?,?,00000000,00000000,00000000,?), ref: 00B0BB63
                          • RegCloseKey.ADVAPI32(?,?), ref: 00B0BBA6
                          • RegCloseKey.ADVAPI32(00000000), ref: 00B0BBB3
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$Close$BuffCharConnectEnumOpenRegistryUpper
                          • String ID:
                          • API String ID: 826366716-0
                          • Opcode ID: 57dc7a22487f33c6967ea564a76f57acde8d283ca3b660a4f81a4e58086a23ff
                          • Instruction ID: 93e404fe81816cd3c5a98c9758be9507c0c2a2a515c94e3ac7f241104bc384d0
                          • Opcode Fuzzy Hash: 57dc7a22487f33c6967ea564a76f57acde8d283ca3b660a4f81a4e58086a23ff
                          • Instruction Fuzzy Hash: 4961AF31208241EFD714DF24C494E2ABBE5FF84308F54899DF49A8B2A2DB31ED45CB92
                          APIs
                          • VariantInit.OLEAUT32(?), ref: 00AE8BCD
                          • VariantClear.OLEAUT32 ref: 00AE8C3E
                          • VariantClear.OLEAUT32 ref: 00AE8C9D
                          • VariantClear.OLEAUT32(?), ref: 00AE8D10
                          • VariantChangeType.OLEAUT32(?,?,00000000,00000013), ref: 00AE8D3B
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Variant$Clear$ChangeInitType
                          • String ID:
                          • API String ID: 4136290138-0
                          • Opcode ID: ea9952aa76042f6bb8bf0c24e7f720ac5bbdeae056f448a7159cecdc353fe54a
                          • Instruction ID: 2a62e9bb59bad4a7a9b58f7c504b4cb91ef708d4312242c51507de3f9a22b46c
                          • Opcode Fuzzy Hash: ea9952aa76042f6bb8bf0c24e7f720ac5bbdeae056f448a7159cecdc353fe54a
                          • Instruction Fuzzy Hash: 26518CB5A00219EFCB10CF59C894AAAB7F5FF89310B118559F909DB350E734E911CF90
                          APIs
                          • GetPrivateProfileSectionW.KERNEL32(00000003,?,00007FFF,?), ref: 00AF8BAE
                          • GetPrivateProfileSectionW.KERNEL32(?,00000003,00000003,?), ref: 00AF8BDA
                          • WritePrivateProfileSectionW.KERNEL32(?,?,?), ref: 00AF8C32
                          • WritePrivateProfileStringW.KERNEL32(00000003,00000000,00000000,?), ref: 00AF8C57
                          • WritePrivateProfileStringW.KERNEL32(00000000,00000000,00000000,?), ref: 00AF8C5F
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: PrivateProfile$SectionWrite$String
                          • String ID:
                          • API String ID: 2832842796-0
                          • Opcode ID: 8fce00487294202627f0a07032dc8b1cbcd366f5bd6df60b73b2c268a792dd10
                          • Instruction ID: 85b0b36b29dbc306cdd12570d54f391fd2b8a8f47cad396897cb45ecd2d8a32e
                          • Opcode Fuzzy Hash: 8fce00487294202627f0a07032dc8b1cbcd366f5bd6df60b73b2c268a792dd10
                          • Instruction Fuzzy Hash: 8A514C35A002199FCB05EF64C981E6DBBF5FF49314F088458E94AAB362DB35ED51CBA0
                          APIs
                          • LoadLibraryW.KERNEL32(?,00000000,?), ref: 00B08F40
                          • GetProcAddress.KERNEL32(00000000,?), ref: 00B08FD0
                          • GetProcAddress.KERNEL32(00000000,00000000), ref: 00B08FEC
                          • GetProcAddress.KERNEL32(00000000,?), ref: 00B09032
                          • FreeLibrary.KERNEL32(00000000), ref: 00B09052
                            • Part of subcall function 00A9F6C9: WideCharToMultiByte.KERNEL32(00000000,00000000,?,?,00000000,00000000,00000000,00000000,?,00000000,?,?,?,00AF1043,?,753CE610), ref: 00A9F6E6
                            • Part of subcall function 00A9F6C9: WideCharToMultiByte.KERNEL32(00000000,00000000,?,?,00000000,00ADFA64,00000000,00000000,?,?,00AF1043,?,753CE610,?,00ADFA64), ref: 00A9F70D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AddressProc$ByteCharLibraryMultiWide$FreeLoad
                          • String ID:
                          • API String ID: 666041331-0
                          • Opcode ID: a8ea8fbb1f1de1e226b2c96c3288f3f4a8cc030eede75cc9dd71c5bace279d27
                          • Instruction ID: 462e5ac9dc48093d5ad9e7cd186fefb6bfc01131696cfe2d3ae22e2a6997c01f
                          • Opcode Fuzzy Hash: a8ea8fbb1f1de1e226b2c96c3288f3f4a8cc030eede75cc9dd71c5bace279d27
                          • Instruction Fuzzy Hash: 30513E35604205DFC715EF64C5948ADBFF1FF49314B0880A9E84AAB3A2DB31EE85CB91
                          APIs
                          • SetWindowLongW.USER32(00000002,000000F0,?), ref: 00B16C33
                          • SetWindowLongW.USER32(?,000000EC,?), ref: 00B16C4A
                          • SendMessageW.USER32(00000002,00001036,00000000,?), ref: 00B16C73
                          • ShowWindow.USER32(00000002,00000000,00000002,00000002,?,?,?,?,?,?,?,00AFAB79,00000000,00000000), ref: 00B16C98
                          • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000000,00000027,00000002,?,00000001,00000002,00000002,?,?,?), ref: 00B16CC7
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Long$MessageSendShow
                          • String ID:
                          • API String ID: 3688381893-0
                          • Opcode ID: 733e076b760cbf200ced192820f32e513d17b1f33f62c3a4fc2a4e9753298a09
                          • Instruction ID: e32fdaecfa1e3d0a2c549cc5c7590e1504b196778a0ff515192a2c72dafa1d9b
                          • Opcode Fuzzy Hash: 733e076b760cbf200ced192820f32e513d17b1f33f62c3a4fc2a4e9753298a09
                          • Instruction Fuzzy Hash: E241D435A04104AFD724CF28CC99FEA7FE5EB09350F9542A8F895A72E0D771AD81CA80
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free
                          • String ID:
                          • API String ID: 269201875-0
                          • Opcode ID: 27eeac6136b17cc5f5c70c5f5d6cf43338e8c4f4cf0653c2be2b446e535ebb9a
                          • Instruction ID: 0e0716294fe24a09a67ce261fa2431c79917d66b3a784acd8ae7a07252fd72d9
                          • Opcode Fuzzy Hash: 27eeac6136b17cc5f5c70c5f5d6cf43338e8c4f4cf0653c2be2b446e535ebb9a
                          • Instruction Fuzzy Hash: A941D372A00200AFCB24DF78C981B9DB7F9EF89714F15456AE515EB396DB31AD01CB80
                          APIs
                          • GetCursorPos.USER32(?), ref: 00A99141
                          • ScreenToClient.USER32(00000000,?), ref: 00A9915E
                          • GetAsyncKeyState.USER32(00000001), ref: 00A99183
                          • GetAsyncKeyState.USER32(00000002), ref: 00A9919D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: AsyncState$ClientCursorScreen
                          • String ID:
                          • API String ID: 4210589936-0
                          • Opcode ID: e237c95fe0b4c058997f1355cf9a760d3a666157be8a9d14a60a06210216e2f8
                          • Instruction ID: 4836c946d6df03d26a5bb94cf34bf39c8524d3f578cda88aa508efb0cfaf3499
                          • Opcode Fuzzy Hash: e237c95fe0b4c058997f1355cf9a760d3a666157be8a9d14a60a06210216e2f8
                          • Instruction Fuzzy Hash: 90414F71A0851AFBDF199F68C844BEEB7B5FB05320F20831AF429A72E0D7305990CB91
                          APIs
                          • GetInputState.USER32 ref: 00AF38CB
                          • TranslateAcceleratorW.USER32(?,00000000,?), ref: 00AF3922
                          • TranslateMessage.USER32(?), ref: 00AF394B
                          • DispatchMessageW.USER32(?), ref: 00AF3955
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00AF3966
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Message$Translate$AcceleratorDispatchInputPeekState
                          • String ID:
                          • API String ID: 2256411358-0
                          • Opcode ID: 89e302939c1342fa42bd672d286b904e558a0850f5a21c0ec907b47bfd5c07cb
                          • Instruction ID: cb9eb31274cbb6fef1c34ba3b7246e09af8607833cc6378fe40ae862fd2fa509
                          • Opcode Fuzzy Hash: 89e302939c1342fa42bd672d286b904e558a0850f5a21c0ec907b47bfd5c07cb
                          • Instruction Fuzzy Hash: 71311E7250434A9EEF35CBB4D8A8BB63BE8DB15341F04459DF662C3190E7F49A85CB11
                          APIs
                          • InternetQueryDataAvailable.WININET(?,?,00000000,00000000,00000000,?,00000000,?,?,?,00AFC21E,00000000), ref: 00AFCF38
                          • InternetReadFile.WININET(?,00000000,?,?), ref: 00AFCF6F
                          • GetLastError.KERNEL32(?,00000000,?,?,?,00AFC21E,00000000), ref: 00AFCFB4
                          • SetEvent.KERNEL32(?,?,00000000,?,?,?,00AFC21E,00000000), ref: 00AFCFC8
                          • SetEvent.KERNEL32(?,?,00000000,?,?,?,00AFC21E,00000000), ref: 00AFCFF2
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: EventInternet$AvailableDataErrorFileLastQueryRead
                          • String ID:
                          • API String ID: 3191363074-0
                          • Opcode ID: cdf0d77c2a681c1a42108ee3a9cc5022bbf9aa4ba7a1aca7bf807cbc610a2ebc
                          • Instruction ID: 5b709dfc957fbc4d7c34ab07e0da4f5fbbe16cb2c1fdc879a9204121187b1e71
                          • Opcode Fuzzy Hash: cdf0d77c2a681c1a42108ee3a9cc5022bbf9aa4ba7a1aca7bf807cbc610a2ebc
                          • Instruction Fuzzy Hash: 54314F7160430DAFDB20DFE6CA849BABBF9EB14364B10842EF616D3141DB30AE40DB60
                          APIs
                          • GetWindowRect.USER32(?,?), ref: 00AE1915
                          • PostMessageW.USER32(00000001,00000201,00000001), ref: 00AE19C1
                          • Sleep.KERNEL32(00000000,?,?,?), ref: 00AE19C9
                          • PostMessageW.USER32(00000001,00000202,00000000), ref: 00AE19DA
                          • Sleep.KERNEL32(00000000,?,?,?,?), ref: 00AE19E2
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessagePostSleep$RectWindow
                          • String ID:
                          • API String ID: 3382505437-0
                          • Opcode ID: 3971b212f5ec276a9e7a16d2f2a676acc1f8fa73716be0172895381254c3082b
                          • Instruction ID: d789a68f0eed2b5f351014072024aef0e1938ef186b1bbfa7281cec5964bfa68
                          • Opcode Fuzzy Hash: 3971b212f5ec276a9e7a16d2f2a676acc1f8fa73716be0172895381254c3082b
                          • Instruction Fuzzy Hash: 9C31B471A00269EFCB04CFA9CD99ADE7BB5EB44315F108225F921A72D1C7709D54CB90
                          APIs
                          • SendMessageW.USER32(?,00001053,000000FF,?), ref: 00B15745
                          • SendMessageW.USER32(?,00001074,?,00000001), ref: 00B1579D
                          • _wcslen.LIBCMT ref: 00B157AF
                          • _wcslen.LIBCMT ref: 00B157BA
                          • SendMessageW.USER32(?,00001002,00000000,?), ref: 00B15816
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$_wcslen
                          • String ID:
                          • API String ID: 763830540-0
                          • Opcode ID: f6e49acb1a137e0454f8cf7509379a56cac75674a6f0afce038b436edcf33bce
                          • Instruction ID: a97766e1fbfe3f1bad3007c4c7a7bfeb4663ad3fdcf1ba95977bcf69f3b52584
                          • Opcode Fuzzy Hash: f6e49acb1a137e0454f8cf7509379a56cac75674a6f0afce038b436edcf33bce
                          • Instruction Fuzzy Hash: EE218071904618DADB309F64CC85AEEBBB8EB85324F508296E929AB2C4D77099C5CF50
                          APIs
                          • IsWindow.USER32(00000000), ref: 00B00951
                          • GetForegroundWindow.USER32 ref: 00B00968
                          • GetDC.USER32(00000000), ref: 00B009A4
                          • GetPixel.GDI32(00000000,?,00000003), ref: 00B009B0
                          • ReleaseDC.USER32(00000000,00000003), ref: 00B009E8
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$ForegroundPixelRelease
                          • String ID:
                          • API String ID: 4156661090-0
                          • Opcode ID: f07b92292e6324ec8d8498fbea986a9a6684b01e2577853344dede085c937d50
                          • Instruction ID: 6e8ea8a6a847f00cabeee0e35aa0d6dcf6991a29e057cc597bd81afae73b44c0
                          • Opcode Fuzzy Hash: f07b92292e6324ec8d8498fbea986a9a6684b01e2577853344dede085c937d50
                          • Instruction Fuzzy Hash: FF219075600204AFD704EF69D984AAEBBF9EF49700F04806CF94AE73A2CB70AD04CB50
                          APIs
                          • GetEnvironmentStringsW.KERNEL32 ref: 00ABCDC6
                          • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00ABCDE9
                            • Part of subcall function 00AB3820: RtlAllocateHeap.NTDLL(00000000,?,00B51444,?,00A9FDF5,?,?,00A8A976,00000010,00B51440,00A813FC,?,00A813C6,?,00A81129), ref: 00AB3852
                          • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,00000000,?,00000000,00000000), ref: 00ABCE0F
                          • _free.LIBCMT ref: 00ABCE22
                          • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00ABCE31
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ByteCharEnvironmentMultiStringsWide$AllocateFreeHeap_free
                          • String ID:
                          • API String ID: 336800556-0
                          • Opcode ID: 6014825eea41aeb24d223e3f978a11d6aa36e864b36e6420e48e76078a166447
                          • Instruction ID: 3eaa0d68974c7e756c7d314b79a04b5c5f0ff7f80a29480bdac3de7ffa9d2314
                          • Opcode Fuzzy Hash: 6014825eea41aeb24d223e3f978a11d6aa36e864b36e6420e48e76078a166447
                          • Instruction Fuzzy Hash: 4F018472601215BFA7211BB66C88DFB6E6DEEC6BB13154129F905DB202EE61CD0191B0
                          APIs
                          • ExtCreatePen.GDI32(?,?,00000000,00000000,00000000,?,00000000), ref: 00A99693
                          • SelectObject.GDI32(?,00000000), ref: 00A996A2
                          • BeginPath.GDI32(?), ref: 00A996B9
                          • SelectObject.GDI32(?,00000000), ref: 00A996E2
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ObjectSelect$BeginCreatePath
                          • String ID:
                          • API String ID: 3225163088-0
                          • Opcode ID: ac18532dc8eb660fdbf408b971bf60ff1929c6c276c7a5db71d9cf67f5f88f04
                          • Instruction ID: 59adc968cde40dea268567ddd64219d2c079fabb4b2bc9ceafe1156b6de5d7a4
                          • Opcode Fuzzy Hash: ac18532dc8eb660fdbf408b971bf60ff1929c6c276c7a5db71d9cf67f5f88f04
                          • Instruction Fuzzy Hash: 4F217F70902305FBDF119F6CEC087EA3BB9BB11356F50465AF511A71A0DBB05892CBA4
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _memcmp
                          • String ID:
                          • API String ID: 2931989736-0
                          • Opcode ID: 377e10da8d06425eafaeddf0fa78b9be2ce0be3a80790b6c427b05b3fb55d81e
                          • Instruction ID: a11453c039b6fbb4b989f382362dada0e7f7fd78b213e447bcc2e93a89c2377d
                          • Opcode Fuzzy Hash: 377e10da8d06425eafaeddf0fa78b9be2ce0be3a80790b6c427b05b3fb55d81e
                          • Instruction Fuzzy Hash: 88019671A45645FA96089622AE52FFB739CDB21398F404420FD04AF281F761ED60C2F0
                          APIs
                          • GetSysColor.USER32(00000008), ref: 00A998CC
                          • SetTextColor.GDI32(?,?), ref: 00A998D6
                          • SetBkMode.GDI32(?,00000001), ref: 00A998E9
                          • GetStockObject.GDI32(00000005), ref: 00A998F1
                          • GetWindowLongW.USER32(?,000000EB), ref: 00A99952
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Color$LongModeObjectStockTextWindow
                          • String ID:
                          • API String ID: 1860813098-0
                          • Opcode ID: 6358800a50537e99923de9cfcb0af1dfaf62842f354182060d461b4106a7d4ea
                          • Instruction ID: 11c7452de585697ac1dca59cbe677ca6e47f5e589b730769b18a0f3ec656a5cf
                          • Opcode Fuzzy Hash: 6358800a50537e99923de9cfcb0af1dfaf62842f354182060d461b4106a7d4ea
                          • Instruction Fuzzy Hash: 79110632286250BFCF224F69EC59AEA3FA4EB13321B08815DF5929B1B1DA310851CB51
                          APIs
                          • GetLastError.KERNEL32(?,?,?,00AAF2DE,00AB3863,00B51444,?,00A9FDF5,?,?,00A8A976,00000010,00B51440,00A813FC,?,00A813C6), ref: 00AB2DFD
                          • _free.LIBCMT ref: 00AB2E32
                          • _free.LIBCMT ref: 00AB2E59
                          • SetLastError.KERNEL32(00000000,00A81129), ref: 00AB2E66
                          • SetLastError.KERNEL32(00000000,00A81129), ref: 00AB2E6F
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorLast$_free
                          • String ID:
                          • API String ID: 3170660625-0
                          • Opcode ID: 787991e857f8ca1b2660bc6d28eaaea9e216a3864a12fa37e449647718f08da9
                          • Instruction ID: 35894d302398b84493de645329ef39f3fd855a18afdc696d5bf4970ff4919902
                          • Opcode Fuzzy Hash: 787991e857f8ca1b2660bc6d28eaaea9e216a3864a12fa37e449647718f08da9
                          • Instruction Fuzzy Hash: 3F01F4362456006BCA1327366D45FEB2E7DBBD67A1B24442AF825A31D3EE34CC014320
                          APIs
                          • CLSIDFromProgID.OLE32(?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?,?,?,00AE035E), ref: 00AE002B
                          • ProgIDFromCLSID.OLE32(?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?,?), ref: 00AE0046
                          • lstrcmpiW.KERNEL32(?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?,?), ref: 00AE0054
                          • CoTaskMemFree.OLE32(00000000,?,00000000,?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?), ref: 00AE0064
                          • CLSIDFromString.OLE32(?,?,?,?,?,00000000,?,?,?,-C000001E,00000001,?,00ADFF41,80070057,?,?), ref: 00AE0070
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: From$Prog$FreeStringTasklstrcmpi
                          • String ID:
                          • API String ID: 3897988419-0
                          • Opcode ID: 0d11e1540472c3dd245ccb32b05ac71a8fbee63e164217a040798684927339b7
                          • Instruction ID: f20db1bef8667e29c516852707c903b8e5389cbb580180434945a47bf55ecc38
                          • Opcode Fuzzy Hash: 0d11e1540472c3dd245ccb32b05ac71a8fbee63e164217a040798684927339b7
                          • Instruction Fuzzy Hash: 6C018B72640204BFDB109F6AEC44FAA7EADEB44792F148124F905D3210EBB1DD808BA0
                          APIs
                          • QueryPerformanceCounter.KERNEL32(?), ref: 00AEE997
                          • QueryPerformanceFrequency.KERNEL32(?), ref: 00AEE9A5
                          • Sleep.KERNEL32(00000000), ref: 00AEE9AD
                          • QueryPerformanceCounter.KERNEL32(?), ref: 00AEE9B7
                          • Sleep.KERNEL32 ref: 00AEE9F3
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: PerformanceQuery$CounterSleep$Frequency
                          • String ID:
                          • API String ID: 2833360925-0
                          • Opcode ID: c6bb8ba3378e481de85ac1c9ac6fb43325b1935ed0103866f977cf493c5576e4
                          • Instruction ID: 9978ca1550389634ed1fad4e8d9a2865eb5022575d19cfd641aa41f5d464bff0
                          • Opcode Fuzzy Hash: c6bb8ba3378e481de85ac1c9ac6fb43325b1935ed0103866f977cf493c5576e4
                          • Instruction Fuzzy Hash: 8B015731C41629EBCF00EBE6DC49AEDFBB8FB08700F404546E502B2242CF309660CBA1
                          APIs
                          • GetUserObjectSecurity.USER32(?,00000004,?,00000000,?), ref: 00AE1114
                          • GetLastError.KERNEL32(?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE1120
                          • GetProcessHeap.KERNEL32(00000008,?,?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE112F
                          • HeapAlloc.KERNEL32(00000000,?,00000000,00000000,?,?,00AE0B9B,?,?,?), ref: 00AE1136
                          • GetUserObjectSecurity.USER32(?,00000004,00000000,?,?), ref: 00AE114D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: HeapObjectSecurityUser$AllocErrorLastProcess
                          • String ID:
                          • API String ID: 842720411-0
                          • Opcode ID: 3147ee3ac9c5c2bd7422c81bc6e132186575f61bd5756130fcd68f37b67b3ff5
                          • Instruction ID: 2bbc37d7a0953b9ec9a16f757ebf9183139287088e0b232f8f45a324179e90bd
                          • Opcode Fuzzy Hash: 3147ee3ac9c5c2bd7422c81bc6e132186575f61bd5756130fcd68f37b67b3ff5
                          • Instruction Fuzzy Hash: 88018C79240315BFDB125FA5DC49EAA3F6EEF8A3A4B608418FA41D3360DF71DC108A60
                          APIs
                          • GetTokenInformation.ADVAPI32(?,00000002,?,00000000,?), ref: 00AE0FCA
                          • GetLastError.KERNEL32(?,00000002,?,00000000,?), ref: 00AE0FD6
                          • GetProcessHeap.KERNEL32(00000008,?,?,00000002,?,00000000,?), ref: 00AE0FE5
                          • HeapAlloc.KERNEL32(00000000,?,00000002,?,00000000,?), ref: 00AE0FEC
                          • GetTokenInformation.ADVAPI32(?,00000002,00000000,?,?,?,00000002,?,00000000,?), ref: 00AE1002
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: HeapInformationToken$AllocErrorLastProcess
                          • String ID:
                          • API String ID: 44706859-0
                          • Opcode ID: b64adef362e4bab5f3eaab3a91ced02045238b115df6a276cce20604c8ea956a
                          • Instruction ID: 0599f8858e6bd5347f3068577427488947c367306394a18f483f199cae4ca098
                          • Opcode Fuzzy Hash: b64adef362e4bab5f3eaab3a91ced02045238b115df6a276cce20604c8ea956a
                          • Instruction Fuzzy Hash: D6F04F39180351BBD7214FA59C4DF963F6EEF89761F518414FA46D7291CE70DC508A60
                          APIs
                          • GetTokenInformation.ADVAPI32(?,00000003(TokenIntegrityLevel),?,00000000,?), ref: 00AE102A
                          • GetLastError.KERNEL32(?,TokenIntegrityLevel,?,00000000,?), ref: 00AE1036
                          • GetProcessHeap.KERNEL32(00000008,?,?,TokenIntegrityLevel,?,00000000,?), ref: 00AE1045
                          • HeapAlloc.KERNEL32(00000000,?,TokenIntegrityLevel,?,00000000,?), ref: 00AE104C
                          • GetTokenInformation.ADVAPI32(?,00000003(TokenIntegrityLevel),00000000,?,?,?,TokenIntegrityLevel,?,00000000,?), ref: 00AE1062
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: HeapInformationToken$AllocErrorLastProcess
                          • String ID:
                          • API String ID: 44706859-0
                          • Opcode ID: 4aeb1997a1a636d2aff7b484af1c9da893cedb78fa7d61cc77091d96370af5f9
                          • Instruction ID: 564541ce1ac2ac51411ab834aa1f08228160ff6cabc7d4de2e99bc39917d3ad9
                          • Opcode Fuzzy Hash: 4aeb1997a1a636d2aff7b484af1c9da893cedb78fa7d61cc77091d96370af5f9
                          • Instruction Fuzzy Hash: 74F0CD39280311FBDB211FA5EC4CF963FAEEF89761FA14424FA05D7250CE30D8408A60
                          APIs
                          • CloseHandle.KERNEL32(?,?,?,?,00AF017D,?,00AF32FC,?,00000001,00AC2592,?), ref: 00AF0324
                          • CloseHandle.KERNEL32(?,?,?,?,00AF017D,?,00AF32FC,?,00000001,00AC2592,?), ref: 00AF0331
                          • CloseHandle.KERNEL32(?,?,?,?,00AF017D,?,00AF32FC,?,00000001,00AC2592,?), ref: 00AF033E
                          • CloseHandle.KERNEL32(?,?,?,?,00AF017D,?,00AF32FC,?,00000001,00AC2592,?), ref: 00AF034B
                          • CloseHandle.KERNEL32(?,?,?,?,00AF017D,?,00AF32FC,?,00000001,00AC2592,?), ref: 00AF0358
                          • CloseHandle.KERNEL32(?,?,?,?,00AF017D,?,00AF32FC,?,00000001,00AC2592,?), ref: 00AF0365
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CloseHandle
                          • String ID:
                          • API String ID: 2962429428-0
                          • Opcode ID: d9593229e84e15a2f6edf8c374911def4f3f5a89c2381d8640e0f97a7bda893b
                          • Instruction ID: f3962c675dcbc38231aef31e14269b8b59f208155ebec106a536f0771987399d
                          • Opcode Fuzzy Hash: d9593229e84e15a2f6edf8c374911def4f3f5a89c2381d8640e0f97a7bda893b
                          • Instruction Fuzzy Hash: 5A01A272800B199FC7309FA6D880822FBF5BF503153158A3FE29652932C771A954CF80
                          APIs
                          • _free.LIBCMT ref: 00ABD752
                            • Part of subcall function 00AB29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000), ref: 00AB29DE
                            • Part of subcall function 00AB29C8: GetLastError.KERNEL32(00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000,00000000), ref: 00AB29F0
                          • _free.LIBCMT ref: 00ABD764
                          • _free.LIBCMT ref: 00ABD776
                          • _free.LIBCMT ref: 00ABD788
                          • _free.LIBCMT ref: 00ABD79A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free$ErrorFreeHeapLast
                          • String ID:
                          • API String ID: 776569668-0
                          • Opcode ID: 18c80108d629e7fe1d5309067675945611ef12208ee26f28c49dbf5c0bbc2e88
                          • Instruction ID: 20f656032480a47cf80a2ef982af7c4d2efd118698702652951830a41b47ff0f
                          • Opcode Fuzzy Hash: 18c80108d629e7fe1d5309067675945611ef12208ee26f28c49dbf5c0bbc2e88
                          • Instruction Fuzzy Hash: 86F0F936545208BB8665EB68FAC6DDA7BDDBB85B10BA40C06F048E7503DF20FC808B64
                          APIs
                          • GetDlgItem.USER32(?,000003E9), ref: 00AE5C58
                          • GetWindowTextW.USER32(00000000,?,00000100), ref: 00AE5C6F
                          • MessageBeep.USER32(00000000), ref: 00AE5C87
                          • KillTimer.USER32(?,0000040A), ref: 00AE5CA3
                          • EndDialog.USER32(?,00000001), ref: 00AE5CBD
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: BeepDialogItemKillMessageTextTimerWindow
                          • String ID:
                          • API String ID: 3741023627-0
                          • Opcode ID: 3be428d2854df06d5dda760e51af0f9d5f936e609a7603b1b762336383a5293e
                          • Instruction ID: 35eb5401d913a36790158649032d779e4bf98ea1cbba9c16deb413e846fb6748
                          • Opcode Fuzzy Hash: 3be428d2854df06d5dda760e51af0f9d5f936e609a7603b1b762336383a5293e
                          • Instruction Fuzzy Hash: 1D018630940B44ABEB245B21ED5EFE67BB8BF44B09F505559A583A20E1DBF0A984CB90
                          APIs
                          • _free.LIBCMT ref: 00AB22BE
                            • Part of subcall function 00AB29C8: RtlFreeHeap.NTDLL(00000000,00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000), ref: 00AB29DE
                            • Part of subcall function 00AB29C8: GetLastError.KERNEL32(00000000,?,00ABD7D1,00000000,00000000,00000000,00000000,?,00ABD7F8,00000000,00000007,00000000,?,00ABDBF5,00000000,00000000), ref: 00AB29F0
                          • _free.LIBCMT ref: 00AB22D0
                          • _free.LIBCMT ref: 00AB22E3
                          • _free.LIBCMT ref: 00AB22F4
                          • _free.LIBCMT ref: 00AB2305
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free$ErrorFreeHeapLast
                          • String ID:
                          • API String ID: 776569668-0
                          • Opcode ID: 8ff7de0e92afed6589cb73576f91dd91daa362b7576854a7c87f63cb4a56c767
                          • Instruction ID: b7c7aaae89790982571653bfa834a917163902f45d34f81bec36f163914356ea
                          • Opcode Fuzzy Hash: 8ff7de0e92afed6589cb73576f91dd91daa362b7576854a7c87f63cb4a56c767
                          • Instruction Fuzzy Hash: F3F0D075411310AB8652BF58BD01B983F69B76DB52B050E87F418D7272CF310551ABA5
                          APIs
                          • EndPath.GDI32(?), ref: 00A995D4
                          • StrokeAndFillPath.GDI32(?,?,00AD71F7,00000000,?,?,?), ref: 00A995F0
                          • SelectObject.GDI32(?,00000000), ref: 00A99603
                          • DeleteObject.GDI32 ref: 00A99616
                          • StrokePath.GDI32(?), ref: 00A99631
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Path$ObjectStroke$DeleteFillSelect
                          • String ID:
                          • API String ID: 2625713937-0
                          • Opcode ID: de202c6e1d781feaa2e184da267d79593bac477b83590b1b0779b204224063ee
                          • Instruction ID: b5e9c7c09017a837f53f73ce343db84a60272f37f7cd810b4bb4348146307445
                          • Opcode Fuzzy Hash: de202c6e1d781feaa2e184da267d79593bac477b83590b1b0779b204224063ee
                          • Instruction Fuzzy Hash: 91F0F630145304EBDB125F6DED1C7AA3FA1AB05322F448658E565960F1CF3089A6DF64
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: __freea$_free
                          • String ID: a/p$am/pm
                          • API String ID: 3432400110-3206640213
                          • Opcode ID: 7bf1b06f2f6966e2bc6ed0fab9c062e2b45689bd28c5047deb3cca05287d77cf
                          • Instruction ID: e4034135509b6f9786048d5b00188adbf8412ca66a444d5ddcace7d1e96a6233
                          • Opcode Fuzzy Hash: 7bf1b06f2f6966e2bc6ed0fab9c062e2b45689bd28c5047deb3cca05287d77cf
                          • Instruction Fuzzy Hash: A2D1E431900205DADB649F68C865BFEB7F9FF05300FA84269E5019F653E7759D80CB91
                          APIs
                            • Part of subcall function 00AA0242: EnterCriticalSection.KERNEL32(00B5070C,00B51884,?,?,00A9198B,00B52518,?,?,?,00A812F9,00000000), ref: 00AA024D
                            • Part of subcall function 00AA0242: LeaveCriticalSection.KERNEL32(00B5070C,?,00A9198B,00B52518,?,?,?,00A812F9,00000000), ref: 00AA028A
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00AA00A3: __onexit.LIBCMT ref: 00AA00A9
                          • __Init_thread_footer.LIBCMT ref: 00B07BFB
                            • Part of subcall function 00AA01F8: EnterCriticalSection.KERNEL32(00B5070C,?,?,00A98747,00B52514), ref: 00AA0202
                            • Part of subcall function 00AA01F8: LeaveCriticalSection.KERNEL32(00B5070C,?,00A98747,00B52514), ref: 00AA0235
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CriticalSection$EnterLeave$Init_thread_footer__onexit_wcslen
                          • String ID: 5$G$Variable must be of type 'Object'.
                          • API String ID: 535116098-3733170431
                          • Opcode ID: ee5286182314c2ddd6b9568eec545c1305e118f89f3bd277969a4c88818d106a
                          • Instruction ID: 1bc5020ea696218fdb24db6883e53b68234fb66ecc0808c30185cabd7b6b1ea4
                          • Opcode Fuzzy Hash: ee5286182314c2ddd6b9568eec545c1305e118f89f3bd277969a4c88818d106a
                          • Instruction Fuzzy Hash: B1919BB0A44209AFDB14EF94D9909AEBBF1FF45300F148199F8069B291DB71AE45CB91
                          APIs
                            • Part of subcall function 00AEB403: WriteProcessMemory.KERNEL32(?,?,?,00000000,00000000,00000000,?,00AE21D0,?,?,00000034,00000800,?,00000034), ref: 00AEB42D
                          • SendMessageW.USER32(?,00001104,00000000,00000000), ref: 00AE2760
                            • Part of subcall function 00AEB3CE: ReadProcessMemory.KERNEL32(?,?,?,00000000,00000000,00000000,?,00AE21FF,?,?,00000800,?,00001073,00000000,?,?), ref: 00AEB3F8
                            • Part of subcall function 00AEB32A: GetWindowThreadProcessId.USER32(?,?), ref: 00AEB355
                            • Part of subcall function 00AEB32A: OpenProcess.KERNEL32(00000438,00000000,?,?,?,00AE2194,00000034,?,?,00001004,00000000,00000000), ref: 00AEB365
                            • Part of subcall function 00AEB32A: VirtualAllocEx.KERNEL32(00000000,00000000,?,00001000,00000004,?,?,00AE2194,00000034,?,?,00001004,00000000,00000000), ref: 00AEB37B
                          • SendMessageW.USER32(?,00001111,00000000,00000000), ref: 00AE27CD
                          • SendMessageW.USER32(?,00001111,00000000,00000000), ref: 00AE281A
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process$MessageSend$Memory$AllocOpenReadThreadVirtualWindowWrite
                          • String ID: @
                          • API String ID: 4150878124-2766056989
                          • Opcode ID: ca7d2252fdd29c0735d04e8f9d1d248e7a5134b1c29d3a57dd5e633ce5d09dc6
                          • Instruction ID: 5bf0e9eeb71c61454d5ed0347c20b5523b7bc21362d68c2290c67235c525883f
                          • Opcode Fuzzy Hash: ca7d2252fdd29c0735d04e8f9d1d248e7a5134b1c29d3a57dd5e633ce5d09dc6
                          • Instruction Fuzzy Hash: 92412C72900218AFDB10DFA5CD46BEEBBB8EF09700F108095FA55B7181DB706E45CBA1
                          APIs
                          • GetModuleFileNameW.KERNEL32(00000000,C:\Users\user\Desktop\file.exe,00000104), ref: 00AB1769
                          • _free.LIBCMT ref: 00AB1834
                          • _free.LIBCMT ref: 00AB183E
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free$FileModuleName
                          • String ID: C:\Users\user\Desktop\file.exe
                          • API String ID: 2506810119-1957095476
                          • Opcode ID: 1afdc9d994c085854c8444e96d12148a2686b6ed4991b84952c65adf0598e0db
                          • Instruction ID: 572627929f8a7f4d4da0b61099c63c3f7207513984cc4ba181db879b6bd95fc2
                          • Opcode Fuzzy Hash: 1afdc9d994c085854c8444e96d12148a2686b6ed4991b84952c65adf0598e0db
                          • Instruction Fuzzy Hash: 1E316D71A40258AFDB21DF999995EDEBBFCEB85310F9441A6F804D7212DA708E80CB90
                          APIs
                          • GetMenuItemInfoW.USER32(00000004,00000000,00000000,?), ref: 00AEC306
                          • DeleteMenu.USER32(?,00000007,00000000), ref: 00AEC34C
                          • DeleteMenu.USER32(?,00000000,00000000,?,00000000,00000000,00B51990,00C45E30), ref: 00AEC395
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Menu$Delete$InfoItem
                          • String ID: 0
                          • API String ID: 135850232-4108050209
                          • Opcode ID: dbc3dc96af4dcaab8a7965aa3b344d003ae26940c094baaab35a6797f5c856cc
                          • Instruction ID: a77b9f7111cf031f37d61865d5dfa5127be0c1312d5f41c4037338b5286eb6b5
                          • Opcode Fuzzy Hash: dbc3dc96af4dcaab8a7965aa3b344d003ae26940c094baaab35a6797f5c856cc
                          • Instruction Fuzzy Hash: 6B4191712043829FD724DF26D885F5AFBE8AF85320F14861DF9A59B2D2D730E905CB62
                          APIs
                          • SetWindowPos.USER32(00000000,00000000,00000000,00000000,00000000,00000000,00000013,?,?,SysTreeView32,00B1CC08,00000000,?,?,?,?), ref: 00B144AA
                          • GetWindowLongW.USER32 ref: 00B144C7
                          • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00B144D7
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Long
                          • String ID: SysTreeView32
                          • API String ID: 847901565-1698111956
                          • Opcode ID: 51aa60eca69fdbe60b021d3f57c38c2c4945bdf8c4ffd53c01b2fddfbbbcfbac
                          • Instruction ID: 44f242a32ee8d0e22b552f9a6c6be3451fa650e9a7a828fb41cd85ecda9dae71
                          • Opcode Fuzzy Hash: 51aa60eca69fdbe60b021d3f57c38c2c4945bdf8c4ffd53c01b2fddfbbbcfbac
                          • Instruction Fuzzy Hash: 58317C71250205ABDB209E38DC45BEA7BE9EB18324F608755F979932E0DB70AC909B50
                          APIs
                            • Part of subcall function 00B0335B: WideCharToMultiByte.KERNEL32(00000000,00000000,?,?,00000000,00000000,00000000,00000000,?,?,?,?,?,00B03077,?,?), ref: 00B03378
                          • inet_addr.WSOCK32(?,?,?,?,?,00000000), ref: 00B0307A
                          • _wcslen.LIBCMT ref: 00B0309B
                          • htons.WSOCK32(00000000,?,?,00000000), ref: 00B03106
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ByteCharMultiWide_wcslenhtonsinet_addr
                          • String ID: 255.255.255.255
                          • API String ID: 946324512-2422070025
                          • Opcode ID: 04f91f8924de47d29e179b19293d36fc3a821e45801c64ce38f868b0dea1e897
                          • Instruction ID: e40f5f661f350d4fd51d0ccb3644e9b235ed9f1d6b0945cd9094bba93f40cc3c
                          • Opcode Fuzzy Hash: 04f91f8924de47d29e179b19293d36fc3a821e45801c64ce38f868b0dea1e897
                          • Instruction Fuzzy Hash: ED31C4352002059FC710CF28C5C9FAABBE8EF54714F288099E8159B3D2DB72DE45C761
                          APIs
                          • SendMessageW.USER32(00000000,00001009,00000000,?), ref: 00B13F40
                          • SetWindowPos.USER32(?,00000000,?,?,?,?,00000004), ref: 00B13F54
                          • SendMessageW.USER32(?,00001002,00000000,?), ref: 00B13F78
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$Window
                          • String ID: SysMonthCal32
                          • API String ID: 2326795674-1439706946
                          • Opcode ID: 3d3cb17fc51caa721973bc06375b6be3224704b9e2e288b4f2dba7329aefed1b
                          • Instruction ID: 1daa0874d5ac77f5e9d657999ec622ff43715d739d6257b9b142316557688d2f
                          • Opcode Fuzzy Hash: 3d3cb17fc51caa721973bc06375b6be3224704b9e2e288b4f2dba7329aefed1b
                          • Instruction Fuzzy Hash: F721BF32640219BFDF218F54CC86FEA3BB9EB48714F110254FA157B1D0DAB1A991CB90
                          APIs
                          • SendMessageW.USER32(00000000,00000469,?,00000000), ref: 00B14705
                          • SendMessageW.USER32(00000000,00000465,00000000,80017FFF), ref: 00B14713
                          • DestroyWindow.USER32(00000000,00000000,?,?,?,00000000,msctls_updown32,00000000,00000000,00000000,00000000,00000000,00000000,?,?,00000000), ref: 00B1471A
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$DestroyWindow
                          • String ID: msctls_updown32
                          • API String ID: 4014797782-2298589950
                          • Opcode ID: 498bf55fe75f71717402195efd37039113af744455116bf1d4c42c9d3b84bb06
                          • Instruction ID: 239a2e4aa15faedb6d7430cda1cf2dba060e17c543c7b8ddbe46fb20c63c92c6
                          • Opcode Fuzzy Hash: 498bf55fe75f71717402195efd37039113af744455116bf1d4c42c9d3b84bb06
                          • Instruction Fuzzy Hash: 6D2130B5600209AFEB11DF68DCC1DA737EDEB5A7A4B540499FA009B291CB71EC51CB60
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen
                          • String ID: #OnAutoItStartRegister$#notrayicon$#requireadmin
                          • API String ID: 176396367-2734436370
                          • Opcode ID: 4b9d9da0150c9744faacef0cd11f62905f17f08c1f2ff45d56240f1bc0957860
                          • Instruction ID: 0a11f6d79302de643d296d36d6927ab008341e42472fa58e6954daee4d474c90
                          • Opcode Fuzzy Hash: 4b9d9da0150c9744faacef0cd11f62905f17f08c1f2ff45d56240f1bc0957860
                          • Instruction Fuzzy Hash: F5215772204791A6D731BB269D02FBBB3E89F91300F60442AF94997081EB95ED85C3A5
                          APIs
                          • SendMessageW.USER32(00000000,00000180,00000000,?), ref: 00B13840
                          • SendMessageW.USER32(?,00000186,00000000,00000000), ref: 00B13850
                          • MoveWindow.USER32(00000000,?,?,?,?,00000000,?,?,Listbox,00000000,00000000,?,?,?,?,?), ref: 00B13876
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend$MoveWindow
                          • String ID: Listbox
                          • API String ID: 3315199576-2633736733
                          • Opcode ID: ac895b39d2a53753877b5ef28811454bd14f5a07b5f2bca876406ebf754b425d
                          • Instruction ID: 80757cc722409ec062b4cabc88a1c84a2143462fe1a9365187eea6da09cb1b23
                          • Opcode Fuzzy Hash: ac895b39d2a53753877b5ef28811454bd14f5a07b5f2bca876406ebf754b425d
                          • Instruction Fuzzy Hash: F321AC72600218BBEF218F54CC81FEB3BEEEF89B50F508164F9009B190DA719C9287A0
                          APIs
                          • SetErrorMode.KERNEL32(00000001), ref: 00AF4A08
                          • GetVolumeInformationW.KERNEL32(?,?,00007FFF,?,00000000,00000000,00000000,00000000), ref: 00AF4A5C
                          • SetErrorMode.KERNEL32(00000000,?,?,00B1CC08), ref: 00AF4AD0
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorMode$InformationVolume
                          • String ID: %lu
                          • API String ID: 2507767853-685833217
                          • Opcode ID: 2048e27342b9b4796913cb25efd91d21077720e1547bebc80bbabda65d2e5660
                          • Instruction ID: 3b607f0b0b279553a4e2d8874e1bf37e2ccfc11ebf271021d8b29a095b762fca
                          • Opcode Fuzzy Hash: 2048e27342b9b4796913cb25efd91d21077720e1547bebc80bbabda65d2e5660
                          • Instruction Fuzzy Hash: 09312375A40109AFDB10EF54C985EAA7BF8EF09308F148099F509DB252DB71ED45CBA1
                          APIs
                          • SendMessageW.USER32(00000000,00000405,00000000,00000000), ref: 00B1424F
                          • SendMessageW.USER32(?,00000406,00000000,00640000), ref: 00B14264
                          • SendMessageW.USER32(?,00000414,0000000A,00000000), ref: 00B14271
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend
                          • String ID: msctls_trackbar32
                          • API String ID: 3850602802-1010561917
                          • Opcode ID: c7820a4f6b46011e5e969d9265e9be110c87da91633ce427f273d9c06323f389
                          • Instruction ID: 0b01477a86a320ca22bf44b4dae4edaea86c8a86b8379dbd8754208dd15bf91e
                          • Opcode Fuzzy Hash: c7820a4f6b46011e5e969d9265e9be110c87da91633ce427f273d9c06323f389
                          • Instruction Fuzzy Hash: 7F11CE31290208BEEF205E28CC06FEB3BECEB95B64F114524FA55E60A0D671DCA19B60
                          APIs
                            • Part of subcall function 00A86B57: _wcslen.LIBCMT ref: 00A86B6A
                            • Part of subcall function 00AE2DA7: SendMessageTimeoutW.USER32(?,00000000,00000000,00000000,00000002,00001388,?), ref: 00AE2DC5
                            • Part of subcall function 00AE2DA7: GetWindowThreadProcessId.USER32(?,00000000), ref: 00AE2DD6
                            • Part of subcall function 00AE2DA7: GetCurrentThreadId.KERNEL32 ref: 00AE2DDD
                            • Part of subcall function 00AE2DA7: AttachThreadInput.USER32(00000000,?,00000000,00000000), ref: 00AE2DE4
                          • GetFocus.USER32 ref: 00AE2F78
                            • Part of subcall function 00AE2DEE: GetParent.USER32(00000000), ref: 00AE2DF9
                          • GetClassNameW.USER32(?,?,00000100), ref: 00AE2FC3
                          • EnumChildWindows.USER32(?,00AE303B), ref: 00AE2FEB
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Thread$AttachChildClassCurrentEnumFocusInputMessageNameParentProcessSendTimeoutWindowWindows_wcslen
                          • String ID: %s%d
                          • API String ID: 1272988791-1110647743
                          • Opcode ID: 97401648eb29ba1abb402a51c7226c1b1da4f4d402c9321214c549b27bc14bcf
                          • Instruction ID: efc6d72d272da244775d9d9215a0d75c7888983d80aa7422ca570cef7e8a4bf9
                          • Opcode Fuzzy Hash: 97401648eb29ba1abb402a51c7226c1b1da4f4d402c9321214c549b27bc14bcf
                          • Instruction Fuzzy Hash: 1611B4756002456BDF147F758DC9FEE37AAAF94314F048075FA099B152DE309A458B60
                          APIs
                          • GetMenuItemInfoW.USER32(?,?,?,00000030), ref: 00B158C1
                          • SetMenuItemInfoW.USER32(?,?,?,00000030), ref: 00B158EE
                          • DrawMenuBar.USER32(?), ref: 00B158FD
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Menu$InfoItem$Draw
                          • String ID: 0
                          • API String ID: 3227129158-4108050209
                          • Opcode ID: 511717c657431dbff78b6d1e93383a2f7ab99f7fc2a3567800ac474a280c18d6
                          • Instruction ID: 046e64ad28a38bc30aadede0fcce2de28980be1b8d52025721961c323494180f
                          • Opcode Fuzzy Hash: 511717c657431dbff78b6d1e93383a2f7ab99f7fc2a3567800ac474a280c18d6
                          • Instruction Fuzzy Hash: 5B015B31600218EFDB219F11DC85BEEBBB9FB85360F5080A9E849D6251DB308A84DF21
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: e0051a6ffd701ccdb0d8792e8e576e7049d2213f790995b51572fdc369250294
                          • Instruction ID: dfa12a2a89c6d37102d49b105bc21cd143ea9de57d89c873192da0f136634068
                          • Opcode Fuzzy Hash: e0051a6ffd701ccdb0d8792e8e576e7049d2213f790995b51572fdc369250294
                          • Instruction Fuzzy Hash: 9FC14875A0024AAFCB14CFA9C894EAEB7B5FF48304F218598E505EF251D771EE81DB90
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: __alldvrm$_strrchr
                          • String ID:
                          • API String ID: 1036877536-0
                          • Opcode ID: 190bec492484a18a97fe5f025dcdb3e473ceac46589bc02d4dbe4f94f5be8f6e
                          • Instruction ID: 3d6c98627804c329d5ec1f2aed55f3a2956d35f265b81b4dec48013c2291fb28
                          • Opcode Fuzzy Hash: 190bec492484a18a97fe5f025dcdb3e473ceac46589bc02d4dbe4f94f5be8f6e
                          • Instruction Fuzzy Hash: C2A11772E003869FEB15DF28C8917FABBF9EF6A350F14426DE5959B283C2388941C750
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Variant$ClearInitInitializeUninitialize
                          • String ID:
                          • API String ID: 1998397398-0
                          • Opcode ID: 2eb5b93b5be3dc53679a8770480fd4be470ec536072e67bebdd4414821224e25
                          • Instruction ID: bdcabf6bbb7c368e807613c973552bbd64aac075157f06bda63c00c7e5fb02fe
                          • Opcode Fuzzy Hash: 2eb5b93b5be3dc53679a8770480fd4be470ec536072e67bebdd4414821224e25
                          • Instruction Fuzzy Hash: 6FA13F756043009FC714EF28C585A2EBBE9FF88714F148899F99A9B3A2DB31ED05CB51
                          APIs
                          • ProgIDFromCLSID.OLE32(?,00000000,?,00000000,00000800,00000000,?,00B1FC08,?), ref: 00AE05F0
                          • CoTaskMemFree.OLE32(00000000,00000000,?,00000000,00000800,00000000,?,00B1FC08,?), ref: 00AE0608
                          • CLSIDFromProgID.OLE32(?,?,00000000,00B1CC40,000000FF,?,00000000,00000800,00000000,?,00B1FC08,?), ref: 00AE062D
                          • _memcmp.LIBVCRUNTIME ref: 00AE064E
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FromProg$FreeTask_memcmp
                          • String ID:
                          • API String ID: 314563124-0
                          • Opcode ID: c110d143f78d168531444312f48d7a33d9c3653483257f419ed1632c68c9be90
                          • Instruction ID: 59a3fde26617507f2eeb5e8e5a027645a068ab680247ba57fe7d6e2b604dcbdc
                          • Opcode Fuzzy Hash: c110d143f78d168531444312f48d7a33d9c3653483257f419ed1632c68c9be90
                          • Instruction Fuzzy Hash: AE811B71A00109EFCB04DF95C984EEEB7B9FF89315F208598E516AB250DB71AE46CF60
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _free
                          • String ID:
                          • API String ID: 269201875-0
                          • Opcode ID: 3189e001a86a630f3f5a0c0df8f4c6591796c7368d0b36f894f8995dc50192db
                          • Instruction ID: 7a6cb4d290ab3c359244fecce8d3914ba924e65367c814c7b7814af62eb2cf05
                          • Opcode Fuzzy Hash: 3189e001a86a630f3f5a0c0df8f4c6591796c7368d0b36f894f8995dc50192db
                          • Instruction Fuzzy Hash: 26412B75B00500ABDB296BF98E45FFE3AA9EF43370F16462DF419D7293E73448415261
                          APIs
                          • GetWindowRect.USER32(?,?), ref: 00B162E2
                          • ScreenToClient.USER32(?,?), ref: 00B16315
                          • MoveWindow.USER32(?,?,?,?,000000FF,00000001,?,?,?,?,?), ref: 00B16382
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$ClientMoveRectScreen
                          • String ID:
                          • API String ID: 3880355969-0
                          • Opcode ID: 84f78ea3ed68394db6ce4601be8e84092659de1787d082b18d77b387e4e20329
                          • Instruction ID: 02d9bb15993257b216982d689c1f4f18d5fce2879ec0b66276d4357bd66456af
                          • Opcode Fuzzy Hash: 84f78ea3ed68394db6ce4601be8e84092659de1787d082b18d77b387e4e20329
                          • Instruction Fuzzy Hash: E4510A74A00209EFDB14DF68D980AEE7BF5EB45360F5085A9F8259B290DB70ED81CB90
                          APIs
                          • socket.WSOCK32(00000002,00000002,00000011), ref: 00B01AFD
                          • WSAGetLastError.WSOCK32 ref: 00B01B0B
                          • #21.WSOCK32(?,0000FFFF,00000020,00000002,00000004), ref: 00B01B8A
                          • WSAGetLastError.WSOCK32 ref: 00B01B94
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorLast$socket
                          • String ID:
                          • API String ID: 1881357543-0
                          • Opcode ID: f7c9238930ad61d36ead07b064793d5cde1c7fff05bab8acf3bd9ed667f8d9bd
                          • Instruction ID: 7ce4c115fbeeddc879471a7638306e1573c42455ed6bcee579dccb6d26265317
                          • Opcode Fuzzy Hash: f7c9238930ad61d36ead07b064793d5cde1c7fff05bab8acf3bd9ed667f8d9bd
                          • Instruction Fuzzy Hash: 8F41A034640200AFE724AF24C986F697BE5EB44718F54C498FA1A9F7D2D772DD418B90
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 1f034f40f7dc4ed038bd624d78a31cb885113cc0817b04253a5712e5b681e413
                          • Instruction ID: 03d99683938e3ae80aa54c49b9e01be04bffa54306d26d7d183028b0d9fd28dd
                          • Opcode Fuzzy Hash: 1f034f40f7dc4ed038bd624d78a31cb885113cc0817b04253a5712e5b681e413
                          • Instruction Fuzzy Hash: D441F771A10704AFD7249F78CD41BEABBEDEB89710F10862EF156DB283D7B1994187A0
                          APIs
                          • CreateHardLinkW.KERNEL32(00000002,?,00000000), ref: 00AF5783
                          • GetLastError.KERNEL32(?,00000000), ref: 00AF57A9
                          • DeleteFileW.KERNEL32(00000002,?,00000000), ref: 00AF57CE
                          • CreateHardLinkW.KERNEL32(00000002,?,00000000,?,00000000), ref: 00AF57FA
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CreateHardLink$DeleteErrorFileLast
                          • String ID:
                          • API String ID: 3321077145-0
                          • Opcode ID: 62055b8c2a6b1be29b1c3f52483061b644ca4990450da27e457380c3e7c93ce5
                          • Instruction ID: 0078210baf9718f1a0def4a1369c98950d4ce570610a233f0b35da1128776dc6
                          • Opcode Fuzzy Hash: 62055b8c2a6b1be29b1c3f52483061b644ca4990450da27e457380c3e7c93ce5
                          • Instruction Fuzzy Hash: AC412C35600610DFCB15EF55C544A5DBBE1AF49720B18C888E95A5B362CB30FD40CB91
                          APIs
                          • MultiByteToWideChar.KERNEL32(?,00000000,8BE85006,00AA6D71,00000000,00000000,00AA82D9,?,00AA82D9,?,00000001,00AA6D71,8BE85006,00000001,00AA82D9,00AA82D9), ref: 00ABD910
                          • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 00ABD999
                          • GetStringTypeW.KERNEL32(?,00000000,00000000,?), ref: 00ABD9AB
                          • __freea.LIBCMT ref: 00ABD9B4
                            • Part of subcall function 00AB3820: RtlAllocateHeap.NTDLL(00000000,?,00B51444,?,00A9FDF5,?,?,00A8A976,00000010,00B51440,00A813FC,?,00A813C6,?,00A81129), ref: 00AB3852
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ByteCharMultiWide$AllocateHeapStringType__freea
                          • String ID:
                          • API String ID: 2652629310-0
                          • Opcode ID: a6b8f3ed7c547935e78faf7eb58da2931c04f026c1305df016a9ca446ab76c4c
                          • Instruction ID: 848f9a95a4ee5198f7e16b12227cef35be603173b7e6d5f7dd8701b95e046ff2
                          • Opcode Fuzzy Hash: a6b8f3ed7c547935e78faf7eb58da2931c04f026c1305df016a9ca446ab76c4c
                          • Instruction Fuzzy Hash: 9431BC72A0020AABDF249F64DC41EEE7BA9EB41710F154268FC04D7292EB36CD50CBA0
                          APIs
                          • SendMessageW.USER32(?,00001024,00000000,?), ref: 00B15352
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B15375
                          • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00B15382
                          • InvalidateRect.USER32(?,00000000,00000001,?,?,?), ref: 00B153A8
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: LongWindow$InvalidateMessageRectSend
                          • String ID:
                          • API String ID: 3340791633-0
                          • Opcode ID: f638550ef3d39fe2c2482048902e994f99ccdd7937ce8c8e5a5f5ce4fd2b213a
                          • Instruction ID: 30447c887dbc950920c002c5c8517420af647d544b993bb995aa25595780482d
                          • Opcode Fuzzy Hash: f638550ef3d39fe2c2482048902e994f99ccdd7937ce8c8e5a5f5ce4fd2b213a
                          • Instruction Fuzzy Hash: 4231C634A55A0CEFEB349E14EC45BE837E5EB85390FD44182FA22971E1C7B09DC0AB49
                          APIs
                          • GetKeyboardState.USER32(?,75C0C0D0,?,00008000), ref: 00AEABF1
                          • SetKeyboardState.USER32(00000080,?,00008000), ref: 00AEAC0D
                          • PostMessageW.USER32(00000000,00000101,00000000), ref: 00AEAC74
                          • SendInput.USER32(00000001,?,0000001C,75C0C0D0,?,00008000), ref: 00AEACC6
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: KeyboardState$InputMessagePostSend
                          • String ID:
                          • API String ID: 432972143-0
                          • Opcode ID: 074fd6b7ecff42f864e17cb8d1103f05cac38f80aa425a1294c9049b23548b94
                          • Instruction ID: 431399e90c4e3fc0ba18830e5eed54065d647db6c11c810a0098c6bbef7faf5b
                          • Opcode Fuzzy Hash: 074fd6b7ecff42f864e17cb8d1103f05cac38f80aa425a1294c9049b23548b94
                          • Instruction Fuzzy Hash: 02310730A407986FEF35CBA68C057FE7BB5ABE9310F28831AE485931D1C375A9858753
                          APIs
                          • ClientToScreen.USER32(?,?), ref: 00B1769A
                          • GetWindowRect.USER32(?,?), ref: 00B17710
                          • PtInRect.USER32(?,?,00B18B89), ref: 00B17720
                          • MessageBeep.USER32(00000000), ref: 00B1778C
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Rect$BeepClientMessageScreenWindow
                          • String ID:
                          • API String ID: 1352109105-0
                          • Opcode ID: f4c277ba797cd8294015431adffaa5d04caf088dde41e56f9630dbf087cb9ef1
                          • Instruction ID: aa768605f9d3ace40fb2d1a48a6e977063e0f39faef666e6a8a9304286d65367
                          • Opcode Fuzzy Hash: f4c277ba797cd8294015431adffaa5d04caf088dde41e56f9630dbf087cb9ef1
                          • Instruction Fuzzy Hash: 00415C74645214DFCB12CF58C894FE9BBF5FB49315F9581E8E4249B2A1CB30AD82CB90
                          APIs
                          • GetForegroundWindow.USER32 ref: 00B116EB
                            • Part of subcall function 00AE3A3D: GetWindowThreadProcessId.USER32(?,00000000), ref: 00AE3A57
                            • Part of subcall function 00AE3A3D: GetCurrentThreadId.KERNEL32 ref: 00AE3A5E
                            • Part of subcall function 00AE3A3D: AttachThreadInput.USER32(00000000,?,00000000,00000000,?,00AE25B3), ref: 00AE3A65
                          • GetCaretPos.USER32(?), ref: 00B116FF
                          • ClientToScreen.USER32(00000000,?), ref: 00B1174C
                          • GetForegroundWindow.USER32 ref: 00B11752
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ThreadWindow$Foreground$AttachCaretClientCurrentInputProcessScreen
                          • String ID:
                          • API String ID: 2759813231-0
                          • Opcode ID: 22d285651f354046bb8acbee78ee73d68763d9f413df2702cf9bfd5f418500ee
                          • Instruction ID: fe2998b1408d215ccf8b39ec7f13314db4f6090f6b29ad75e9ec2570412a37b4
                          • Opcode Fuzzy Hash: 22d285651f354046bb8acbee78ee73d68763d9f413df2702cf9bfd5f418500ee
                          • Instruction Fuzzy Hash: 95314FB1D00249AFDB00EFA9C985CEEBBF9EF48304B5080A9E515E7251DB31DE45CBA1
                          APIs
                            • Part of subcall function 00A87620: _wcslen.LIBCMT ref: 00A87625
                          • _wcslen.LIBCMT ref: 00AEDFCB
                          • _wcslen.LIBCMT ref: 00AEDFE2
                          • _wcslen.LIBCMT ref: 00AEE00D
                          • GetTextExtentPoint32W.GDI32(?,00000000,00000000,?), ref: 00AEE018
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$ExtentPoint32Text
                          • String ID:
                          • API String ID: 3763101759-0
                          • Opcode ID: caa1c7e82452121b3cd06defdf08cfbff9756a705ade36604108f0d002aeed76
                          • Instruction ID: 1aa2b32dcfb2eb96864cf138d7928c7be2ba0669b1b2f5e431d9c60f125b631c
                          • Opcode Fuzzy Hash: caa1c7e82452121b3cd06defdf08cfbff9756a705ade36604108f0d002aeed76
                          • Instruction Fuzzy Hash: DC219571940214EFCB10EFA9DA81BAEB7F8EF8A750F144065F805BB285D7709E41CBA1
                          APIs
                          • CreateToolhelp32Snapshot.KERNEL32 ref: 00AED501
                          • Process32FirstW.KERNEL32(00000000,?), ref: 00AED50F
                          • Process32NextW.KERNEL32(00000000,?), ref: 00AED52F
                          • CloseHandle.KERNEL32(00000000), ref: 00AED5DC
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32
                          • String ID:
                          • API String ID: 420147892-0
                          • Opcode ID: 04286c35aee12d17553033f64fb6c3feaae8c29f7aa72a631696002ca8d9d7bd
                          • Instruction ID: debf30f4b40d667d9fcafc999303fabec5d79a929a5b28caddced2258c6a4f65
                          • Opcode Fuzzy Hash: 04286c35aee12d17553033f64fb6c3feaae8c29f7aa72a631696002ca8d9d7bd
                          • Instruction Fuzzy Hash: E131AB71108340AFD300EF64C985ABFBBF8EF99354F54092DF585971A1EB719A48CBA2
                          APIs
                            • Part of subcall function 00A99BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 00A99BB2
                          • GetCursorPos.USER32(?), ref: 00B19001
                          • TrackPopupMenuEx.USER32(?,00000000,?,?,?,00000000,?,00AD7711,?,?,?,?,?), ref: 00B19016
                          • GetCursorPos.USER32(?), ref: 00B1905E
                          • DefDlgProcW.USER32(?,0000007B,?,?,?,?,?,?,?,?,?,?,00AD7711,?,?,?), ref: 00B19094
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Cursor$LongMenuPopupProcTrackWindow
                          • String ID:
                          • API String ID: 2864067406-0
                          • Opcode ID: 1c71b671e93c4cef063449697ea06dc9a3c663114ca004df00f61f9d368b4790
                          • Instruction ID: 8257312b48e8a22c385b67a91147fa22e0e1ec8f93ae8f1f205b40177bbca1cd
                          • Opcode Fuzzy Hash: 1c71b671e93c4cef063449697ea06dc9a3c663114ca004df00f61f9d368b4790
                          • Instruction Fuzzy Hash: 5D219F35600158EFCB25CF98CC69FEA7BF9EB49361F9440A9F90547261C7319D90DB60
                          APIs
                          • GetFileAttributesW.KERNEL32(?,00B1CB68), ref: 00AED2FB
                          • GetLastError.KERNEL32 ref: 00AED30A
                          • CreateDirectoryW.KERNEL32(?,00000000), ref: 00AED319
                          • CreateDirectoryW.KERNEL32(?,00000000,00000000,000000FF,00B1CB68), ref: 00AED376
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CreateDirectory$AttributesErrorFileLast
                          • String ID:
                          • API String ID: 2267087916-0
                          • Opcode ID: a8e85f408d67f3f42803662d087c0a040f2c94f90ceba1a413b198f01a7f5cff
                          • Instruction ID: a286d5f5618841d99346c8e3eaea8ebcf66f8391cbca1c610bd319b7fd01a2b5
                          • Opcode Fuzzy Hash: a8e85f408d67f3f42803662d087c0a040f2c94f90ceba1a413b198f01a7f5cff
                          • Instruction Fuzzy Hash: 2321B2745083429F8710EF29C9818AFBBE4EE5A324F504A1DF499DB2E1DB30D945CB93
                          APIs
                            • Part of subcall function 00AE1014: GetTokenInformation.ADVAPI32(?,00000003(TokenIntegrityLevel),?,00000000,?), ref: 00AE102A
                            • Part of subcall function 00AE1014: GetLastError.KERNEL32(?,TokenIntegrityLevel,?,00000000,?), ref: 00AE1036
                            • Part of subcall function 00AE1014: GetProcessHeap.KERNEL32(00000008,?,?,TokenIntegrityLevel,?,00000000,?), ref: 00AE1045
                            • Part of subcall function 00AE1014: HeapAlloc.KERNEL32(00000000,?,TokenIntegrityLevel,?,00000000,?), ref: 00AE104C
                            • Part of subcall function 00AE1014: GetTokenInformation.ADVAPI32(?,00000003(TokenIntegrityLevel),00000000,?,?,?,TokenIntegrityLevel,?,00000000,?), ref: 00AE1062
                          • LookupPrivilegeValueW.ADVAPI32(00000000,?,?), ref: 00AE15BE
                          • _memcmp.LIBVCRUNTIME ref: 00AE15E1
                          • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00AE1617
                          • HeapFree.KERNEL32(00000000), ref: 00AE161E
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Heap$InformationProcessToken$AllocErrorFreeLastLookupPrivilegeValue_memcmp
                          • String ID:
                          • API String ID: 1592001646-0
                          • Opcode ID: e90cc562b945d52d2a1a2918d5caaf9c93c5eeaf7263fb0cf13c2d95be007bd5
                          • Instruction ID: b41f2110c9f47ef8485a03d9e48d6862dbb7cbffffe2ca4195aa633f5abc11f6
                          • Opcode Fuzzy Hash: e90cc562b945d52d2a1a2918d5caaf9c93c5eeaf7263fb0cf13c2d95be007bd5
                          • Instruction Fuzzy Hash: 27218E71E40219EFDF10DFA6C949BEEB7B8EF44354F188459E445AB241E731AE05CBA0
                          APIs
                          • GetWindowLongW.USER32(?,000000EC), ref: 00B1280A
                          • SetWindowLongW.USER32(?,000000EC,00000000), ref: 00B12824
                          • SetWindowLongW.USER32(?,000000EC,00000000), ref: 00B12832
                          • SetLayeredWindowAttributes.USER32(?,00000000,?,00000002), ref: 00B12840
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Long$AttributesLayered
                          • String ID:
                          • API String ID: 2169480361-0
                          • Opcode ID: 6dd1b5398585125dce17fe33f5732a68557a5a5360d2f53c64b3f527972406a2
                          • Instruction ID: e96ddc2b66a01df7f8c6ff5e9b9c1bee5d8285b886ab23315a6a812cd68f065d
                          • Opcode Fuzzy Hash: 6dd1b5398585125dce17fe33f5732a68557a5a5360d2f53c64b3f527972406a2
                          • Instruction Fuzzy Hash: CA21B031205511AFD7149B24D845FEA7B96EF86324F548198F826CB6E2CB71FC92CBD0
                          APIs
                            • Part of subcall function 00AE8D7D: lstrlenW.KERNEL32(?,00000002,000000FF,?,?,?,00AE790A,?,000000FF,?,00AE8754,00000000,?,0000001C,?,?), ref: 00AE8D8C
                            • Part of subcall function 00AE8D7D: lstrcpyW.KERNEL32(00000000,?,?,00AE790A,?,000000FF,?,00AE8754,00000000,?,0000001C,?,?,00000000), ref: 00AE8DB2
                            • Part of subcall function 00AE8D7D: lstrcmpiW.KERNEL32(00000000,?,00AE790A,?,000000FF,?,00AE8754,00000000,?,0000001C,?,?), ref: 00AE8DE3
                          • lstrlenW.KERNEL32(?,00000002,000000FF,?,000000FF,?,00AE8754,00000000,?,0000001C,?,?,00000000), ref: 00AE7923
                          • lstrcpyW.KERNEL32(00000000,?,?,00AE8754,00000000,?,0000001C,?,?,00000000), ref: 00AE7949
                          • lstrcmpiW.KERNEL32(00000002,cdecl,?,00AE8754,00000000,?,0000001C,?,?,00000000), ref: 00AE7984
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: lstrcmpilstrcpylstrlen
                          • String ID: cdecl
                          • API String ID: 4031866154-3896280584
                          • Opcode ID: 2475662a4a8eb7679978a5d19ea1db34ab53cdd543f0cf0b2c845b08872b0dda
                          • Instruction ID: 7aa42df7300fdfca5fdd56fbf71b466edbc2bf60f84d5fec1028422d81d58ff4
                          • Opcode Fuzzy Hash: 2475662a4a8eb7679978a5d19ea1db34ab53cdd543f0cf0b2c845b08872b0dda
                          • Instruction Fuzzy Hash: 8611D33A200382AFCB159F36DC45E7A77E9FF85750B50802AF946C72A5EF319811D7A1
                          APIs
                          • GetWindowLongW.USER32(?,000000F0), ref: 00B17D0B
                          • SetWindowLongW.USER32(00000000,000000F0,?), ref: 00B17D2A
                          • SetWindowLongW.USER32(00000000,000000EC,000000FF), ref: 00B17D42
                          • SetWindowPos.USER32(00000000,00000000,00000000,00000000,00000000,00000000,?,?,?,?,?,?,?,?,00AFB7AD,00000000), ref: 00B17D6B
                            • Part of subcall function 00A99BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 00A99BB2
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$Long
                          • String ID:
                          • API String ID: 847901565-0
                          • Opcode ID: 35124e5a348ab933d3758287120625fad6ef116b5deaef6c20757f4c862fee83
                          • Instruction ID: a2af15a61b500a88f66be275ba0ce47d3d8d5ee949e6583356e55ce1c3fd7829
                          • Opcode Fuzzy Hash: 35124e5a348ab933d3758287120625fad6ef116b5deaef6c20757f4c862fee83
                          • Instruction Fuzzy Hash: 7311AE71284618AFCB108F28DC04AE63BE5EF45364B5187A4F835C72E0DB3089A1CB80
                          APIs
                          • SendMessageW.USER32(?,00001060,?,00000004), ref: 00B156BB
                          • _wcslen.LIBCMT ref: 00B156CD
                          • _wcslen.LIBCMT ref: 00B156D8
                          • SendMessageW.USER32(?,00001002,00000000,?), ref: 00B15816
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend_wcslen
                          • String ID:
                          • API String ID: 455545452-0
                          • Opcode ID: b6b3440077730e70a61baa3fb3169d8ca1d964c2be5be6619249ab367649466a
                          • Instruction ID: ff6d657b61007254bb3865baeb91a2b5a2cc3c7ad277c5d632a060197f0b8959
                          • Opcode Fuzzy Hash: b6b3440077730e70a61baa3fb3169d8ca1d964c2be5be6619249ab367649466a
                          • Instruction Fuzzy Hash: 6D11E131600608DADB309F65CCC1AEE77ECEF95364B9040A6F915D7185EB708AC0CBA0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: bf90775317aa70d4b6ff21a1facef713cdce0bc5b4dae3608c8bf002c3204855
                          • Instruction ID: 09a7772be6a12e7c23c3f72df18619116cdbae3eb82430631556e523cb747f92
                          • Opcode Fuzzy Hash: bf90775317aa70d4b6ff21a1facef713cdce0bc5b4dae3608c8bf002c3204855
                          • Instruction Fuzzy Hash: 9701ADB220961A7EF62126786CD0FE76B6CDF817B8FB00326F525A21D3DB608C105160
                          APIs
                          • SendMessageW.USER32(?,000000B0,?,?), ref: 00AE1A47
                          • SendMessageW.USER32(?,000000C9,?,00000000), ref: 00AE1A59
                          • SendMessageW.USER32(?,000000C9,?,00000000), ref: 00AE1A6F
                          • SendMessageW.USER32(?,000000C9,?,00000000), ref: 00AE1A8A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend
                          • String ID:
                          • API String ID: 3850602802-0
                          • Opcode ID: 1b26749355b095b9e1af9a9f4e0fca13616586657272f000c5e0746286dc6c87
                          • Instruction ID: ce0c25d109c77da81e7175077db278790737dbf50564bd3a4dbcf329394a7dd3
                          • Opcode Fuzzy Hash: 1b26749355b095b9e1af9a9f4e0fca13616586657272f000c5e0746286dc6c87
                          • Instruction Fuzzy Hash: EB11093AD41229FFEB11DBA5CD85FADBB78EB08750F2000A1EA05B7290D6716E50DB94
                          APIs
                          • GetCurrentThreadId.KERNEL32 ref: 00AEE1FD
                          • MessageBoxW.USER32(?,?,?,?), ref: 00AEE230
                          • WaitForSingleObject.KERNEL32(00000000,000000FF,?,?,?,?), ref: 00AEE246
                          • CloseHandle.KERNEL32(00000000,?,?,?,?), ref: 00AEE24D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CloseCurrentHandleMessageObjectSingleThreadWait
                          • String ID:
                          • API String ID: 2880819207-0
                          • Opcode ID: 1ddf2ef8e9f63da237eed4d914bdad5294d7da642e0316b54c32619cf78c0d80
                          • Instruction ID: c1253d33ac23d696940bb0aa0c3c8d53a9d6b7b0b54f6a3d9d0ef77237cec715
                          • Opcode Fuzzy Hash: 1ddf2ef8e9f63da237eed4d914bdad5294d7da642e0316b54c32619cf78c0d80
                          • Instruction Fuzzy Hash: 6111C876904254BBCB01DFAD9C05BDE7FADEB45311F148655F925E3291DAB08D048BA0
                          APIs
                          • CreateThread.KERNEL32(00000000,?,00AACFF9,00000000,00000004,00000000), ref: 00AAD218
                          • GetLastError.KERNEL32 ref: 00AAD224
                          • __dosmaperr.LIBCMT ref: 00AAD22B
                          • ResumeThread.KERNEL32(00000000), ref: 00AAD249
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Thread$CreateErrorLastResume__dosmaperr
                          • String ID:
                          • API String ID: 173952441-0
                          • Opcode ID: 0af6841e362be37951f5f4d1ec708c05b82ba3d035dad04fa60538608a88eb50
                          • Instruction ID: 3a4623f1bddd6842abcb7fc45820452edfdafc96f4517f0514a0487463300b7f
                          • Opcode Fuzzy Hash: 0af6841e362be37951f5f4d1ec708c05b82ba3d035dad04fa60538608a88eb50
                          • Instruction Fuzzy Hash: 1701C076845204BBDB216BA5DC09BEE7E69EF83330F104229F926935D0DF708905C6A0
                          APIs
                            • Part of subcall function 00A99BA1: GetWindowLongW.USER32(00000000,000000EB), ref: 00A99BB2
                          • GetClientRect.USER32(?,?), ref: 00B19F31
                          • GetCursorPos.USER32(?), ref: 00B19F3B
                          • ScreenToClient.USER32(?,?), ref: 00B19F46
                          • DefDlgProcW.USER32(?,00000020,?,00000000,?,?,?), ref: 00B19F7A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Client$CursorLongProcRectScreenWindow
                          • String ID:
                          • API String ID: 4127811313-0
                          • Opcode ID: 879d0b406c0ca5eea2b0d55fefd3c30cab0250300cba4865a8bdf5592b6b65d4
                          • Instruction ID: 7762cc8d0b2d46326bc0ae461edc1d0160ea906a8a3f5af722259166ea4821e3
                          • Opcode Fuzzy Hash: 879d0b406c0ca5eea2b0d55fefd3c30cab0250300cba4865a8bdf5592b6b65d4
                          • Instruction Fuzzy Hash: 71115A3290025ABBDB10DF68C8999EE7BF9FB05311F904495F911E3140D730BAC2CBA1
                          APIs
                          • CreateWindowExW.USER32(?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 00A8604C
                          • GetStockObject.GDI32(00000011), ref: 00A86060
                          • SendMessageW.USER32(00000000,00000030,00000000), ref: 00A8606A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CreateMessageObjectSendStockWindow
                          • String ID:
                          • API String ID: 3970641297-0
                          • Opcode ID: 876f515731628bc48a96007c20cc38fc7a70436c2e40502da481693acb2a8cf8
                          • Instruction ID: ac67d790e2e12b8246c83db20d512fc323702d02894a086cfd661ed20879adbf
                          • Opcode Fuzzy Hash: 876f515731628bc48a96007c20cc38fc7a70436c2e40502da481693acb2a8cf8
                          • Instruction Fuzzy Hash: 2F116D72501508BFEF125FA49C54FEABF79EF083A5F048215FA1452150DB329C60DBA5
                          APIs
                          • ___BuildCatchObject.LIBVCRUNTIME ref: 00AA3B56
                            • Part of subcall function 00AA3AA3: BuildCatchObjectHelperInternal.LIBVCRUNTIME ref: 00AA3AD2
                            • Part of subcall function 00AA3AA3: ___AdjustPointer.LIBCMT ref: 00AA3AED
                          • _UnwindNestedFrames.LIBCMT ref: 00AA3B6B
                          • __FrameHandler3::FrameUnwindToState.LIBVCRUNTIME ref: 00AA3B7C
                          • CallCatchBlock.LIBVCRUNTIME ref: 00AA3BA4
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Catch$BuildFrameObjectUnwind$AdjustBlockCallFramesHandler3::HelperInternalNestedPointerState
                          • String ID:
                          • API String ID: 737400349-0
                          • Opcode ID: 12ea49abee573113f57dbd3ec3a577afcc9c348439d29e6cbe32e78011ac24d3
                          • Instruction ID: 5f1ebb6a4ea588ae01599e41dc7aec32c2d817bf2e2b74d4386c2a8ea009a06f
                          • Opcode Fuzzy Hash: 12ea49abee573113f57dbd3ec3a577afcc9c348439d29e6cbe32e78011ac24d3
                          • Instruction Fuzzy Hash: 5C011732100148BBDF126F95DD42EEB7B6AEF8A754F044018FE4857161C772E9619BA0
                          APIs
                          • LoadLibraryExW.KERNEL32(00000000,00000000,00000800,00A813C6,00000000,00000000,?,00AB301A,00A813C6,00000000,00000000,00000000,?,00AB328B,00000006,FlsSetValue), ref: 00AB30A5
                          • GetLastError.KERNEL32(?,00AB301A,00A813C6,00000000,00000000,00000000,?,00AB328B,00000006,FlsSetValue,00B22290,FlsSetValue,00000000,00000364,?,00AB2E46), ref: 00AB30B1
                          • LoadLibraryExW.KERNEL32(00000000,00000000,00000000,?,00AB301A,00A813C6,00000000,00000000,00000000,?,00AB328B,00000006,FlsSetValue,00B22290,FlsSetValue,00000000), ref: 00AB30BF
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: LibraryLoad$ErrorLast
                          • String ID:
                          • API String ID: 3177248105-0
                          • Opcode ID: 2870e7d44bba079c35e9cfe09bf5380bf00a93da77b916b0db196def42a5e3ba
                          • Instruction ID: e1c07bd83d07ac288309b3d3ef2456d27420a2131ca39aa4f69f4a4da7b1e125
                          • Opcode Fuzzy Hash: 2870e7d44bba079c35e9cfe09bf5380bf00a93da77b916b0db196def42a5e3ba
                          • Instruction Fuzzy Hash: 5B01D437745322ABCF315B78AC44AD77B9CAF05B61B604620F906E7141CB21D901C6E0
                          APIs
                          • GetModuleFileNameW.KERNEL32(?,?,00000104,00000000), ref: 00AE747F
                          • LoadTypeLibEx.OLEAUT32(?,00000002,?), ref: 00AE7497
                          • RegisterTypeLib.OLEAUT32(?,?,00000000), ref: 00AE74AC
                          • RegisterTypeLibForUser.OLEAUT32(?,?,00000000), ref: 00AE74CA
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Type$Register$FileLoadModuleNameUser
                          • String ID:
                          • API String ID: 1352324309-0
                          • Opcode ID: 764085c5ec43042e0e8ea2dd415e7ecd11bf52d30f63d934a536000a6dbaed4e
                          • Instruction ID: 39cbc3574eef8e176509798ee2b37470017d370202f64fca66082844cb399140
                          • Opcode Fuzzy Hash: 764085c5ec43042e0e8ea2dd415e7ecd11bf52d30f63d934a536000a6dbaed4e
                          • Instruction Fuzzy Hash: 2911C0B5249354AFE720CF19EC08F9A7FFCEB00B00F508569AA16DB191DBB0E904DB60
                          APIs
                          • QueryPerformanceCounter.KERNEL32(?,?,?,?,?,?,?,?,?,00AEACD3,?,00008000), ref: 00AEB0C4
                          • Sleep.KERNEL32(00000000,?,?,?,?,?,?,?,?,00AEACD3,?,00008000), ref: 00AEB0E9
                          • QueryPerformanceCounter.KERNEL32(?,?,?,?,?,?,?,?,?,00AEACD3,?,00008000), ref: 00AEB0F3
                          • Sleep.KERNEL32(00000000,?,?,?,?,?,?,?,?,00AEACD3,?,00008000), ref: 00AEB126
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CounterPerformanceQuerySleep
                          • String ID:
                          • API String ID: 2875609808-0
                          • Opcode ID: dec7312deb7b900406594f4e9b68e1d21c17dbdad4085167d556d7ebe8a70672
                          • Instruction ID: b7eccab7837ed9a258d33b4b84e0ed9e21c3b09144b269af3ff5823fdab6d9ae
                          • Opcode Fuzzy Hash: dec7312deb7b900406594f4e9b68e1d21c17dbdad4085167d556d7ebe8a70672
                          • Instruction Fuzzy Hash: F8113931D51668E7CF00AFEAE9986EFBF78FF09721F108186D941B3181CB3056509B61
                          APIs
                          • GetWindowRect.USER32(?,?), ref: 00B17E33
                          • ScreenToClient.USER32(?,?), ref: 00B17E4B
                          • ScreenToClient.USER32(?,?), ref: 00B17E6F
                          • InvalidateRect.USER32(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00B17E8A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClientRectScreen$InvalidateWindow
                          • String ID:
                          • API String ID: 357397906-0
                          • Opcode ID: e17b4ebabd5a93e2478db96bf53c98214831750bcb6a71a6bdeb3a00bdd731d9
                          • Instruction ID: cb7138445afde10a599c7e10b8bf7ce63e16626ca6aa0ae5705a5cd50520c748
                          • Opcode Fuzzy Hash: e17b4ebabd5a93e2478db96bf53c98214831750bcb6a71a6bdeb3a00bdd731d9
                          • Instruction Fuzzy Hash: 611143B9D4020AAFDB41CF98C8849EEBBF9FB09310F509056E915E3210D775AA54CF50
                          APIs
                          • SendMessageTimeoutW.USER32(?,00000000,00000000,00000000,00000002,00001388,?), ref: 00AE2DC5
                          • GetWindowThreadProcessId.USER32(?,00000000), ref: 00AE2DD6
                          • GetCurrentThreadId.KERNEL32 ref: 00AE2DDD
                          • AttachThreadInput.USER32(00000000,?,00000000,00000000), ref: 00AE2DE4
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Thread$AttachCurrentInputMessageProcessSendTimeoutWindow
                          • String ID:
                          • API String ID: 2710830443-0
                          • Opcode ID: 7d813e1b1cd9705c103bdaa2943cd108aed26b5ec49836f25be04420b9aa0e48
                          • Instruction ID: c810ce456f17117b126c3d3f2077dd9ff58eb24325f1a103051e0ed3cda53541
                          • Opcode Fuzzy Hash: 7d813e1b1cd9705c103bdaa2943cd108aed26b5ec49836f25be04420b9aa0e48
                          • Instruction Fuzzy Hash: 79E06D715812247AD7201B639C4DFEB3E6CEB42BA1F904115B205D3080DEA08840C6B0
                          APIs
                            • Part of subcall function 00A99639: ExtCreatePen.GDI32(?,?,00000000,00000000,00000000,?,00000000), ref: 00A99693
                            • Part of subcall function 00A99639: SelectObject.GDI32(?,00000000), ref: 00A996A2
                            • Part of subcall function 00A99639: BeginPath.GDI32(?), ref: 00A996B9
                            • Part of subcall function 00A99639: SelectObject.GDI32(?,00000000), ref: 00A996E2
                          • MoveToEx.GDI32(?,00000000,00000000,00000000), ref: 00B18887
                          • LineTo.GDI32(?,?,?), ref: 00B18894
                          • EndPath.GDI32(?), ref: 00B188A4
                          • StrokePath.GDI32(?), ref: 00B188B2
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Path$ObjectSelect$BeginCreateLineMoveStroke
                          • String ID:
                          • API String ID: 1539411459-0
                          • Opcode ID: 3fa39ffe5406faa88db0a33f53207ac172973346409060cf7b0d4b83c4addfec
                          • Instruction ID: e666af22e73f205a2754a5af1f31cf0930c2c3581d8065468559784afcfcb517
                          • Opcode Fuzzy Hash: 3fa39ffe5406faa88db0a33f53207ac172973346409060cf7b0d4b83c4addfec
                          • Instruction Fuzzy Hash: A0F05E36081258FADB125F98AC0EFCE3F99AF0A311F848040FA11660E2CB755562CFE9
                          APIs
                          • GetSysColor.USER32(00000008), ref: 00A998CC
                          • SetTextColor.GDI32(?,?), ref: 00A998D6
                          • SetBkMode.GDI32(?,00000001), ref: 00A998E9
                          • GetStockObject.GDI32(00000005), ref: 00A998F1
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Color$ModeObjectStockText
                          • String ID:
                          • API String ID: 4037423528-0
                          • Opcode ID: 23c1f9a1639bd2078d4ec6702b1577dce1b964eca1d479f570554133c909358f
                          • Instruction ID: 2cb40900c98affeaa04e82d4951786373fe716d6727e6d553ec8b5b3589f9c45
                          • Opcode Fuzzy Hash: 23c1f9a1639bd2078d4ec6702b1577dce1b964eca1d479f570554133c909358f
                          • Instruction Fuzzy Hash: 0AE06D312C4280BADB215B78BC09BED3F61AB12336F14C21AF6FA690E1CB7146509B11
                          APIs
                          • GetCurrentThread.KERNEL32 ref: 00AE1634
                          • OpenThreadToken.ADVAPI32(00000000,?,?,?,00AE11D9), ref: 00AE163B
                          • GetCurrentProcess.KERNEL32(00000028,?,?,?,?,00AE11D9), ref: 00AE1648
                          • OpenProcessToken.ADVAPI32(00000000,?,?,?,00AE11D9), ref: 00AE164F
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CurrentOpenProcessThreadToken
                          • String ID:
                          • API String ID: 3974789173-0
                          • Opcode ID: a12d81bebd1b4533a93e0126f7ace81b63c1ccab4a4a1abd9b28f497464ead59
                          • Instruction ID: 62e9f2d609b2f771d30f631269f79544377d852cace0ea481e514b0908593791
                          • Opcode Fuzzy Hash: a12d81bebd1b4533a93e0126f7ace81b63c1ccab4a4a1abd9b28f497464ead59
                          • Instruction Fuzzy Hash: F8E08631641221DBD7202FA1AD0DBC63F7CBF45795F14C808F245CB080DA344540C754
                          APIs
                          • GetDesktopWindow.USER32 ref: 00ADD858
                          • GetDC.USER32(00000000), ref: 00ADD862
                          • GetDeviceCaps.GDI32(00000000,0000000C), ref: 00ADD882
                          • ReleaseDC.USER32(?), ref: 00ADD8A3
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CapsDesktopDeviceReleaseWindow
                          • String ID:
                          • API String ID: 2889604237-0
                          • Opcode ID: 63b70cb8b337c1237aaab46e39640a08b40c29c9fa3ada48e7f3376cc19abcba
                          • Instruction ID: 47df62f2fdd0fc0fa3c44e057940a52211bcfb766e1bf829168e6c43f43702fe
                          • Opcode Fuzzy Hash: 63b70cb8b337c1237aaab46e39640a08b40c29c9fa3ada48e7f3376cc19abcba
                          • Instruction Fuzzy Hash: 4AE012B4840204EFCF41AFA0D90CAADBFB2FB08310F60D009E80AE7250CB388A41EF50
                          APIs
                          • GetDesktopWindow.USER32 ref: 00ADD86C
                          • GetDC.USER32(00000000), ref: 00ADD876
                          • GetDeviceCaps.GDI32(00000000,0000000C), ref: 00ADD882
                          • ReleaseDC.USER32(?), ref: 00ADD8A3
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CapsDesktopDeviceReleaseWindow
                          • String ID:
                          • API String ID: 2889604237-0
                          • Opcode ID: 980bcc27c3d7f91dee28e973223a1226f8abce5e6d2295ab376f30973c1b3388
                          • Instruction ID: 3a59e6db21bd869b58a5e74a9f9b015398c77a5b155c3dc9ab3265aa2c149902
                          • Opcode Fuzzy Hash: 980bcc27c3d7f91dee28e973223a1226f8abce5e6d2295ab376f30973c1b3388
                          • Instruction Fuzzy Hash: 48E092B5D40204EFCF51AFA0D94C6ADBFB5BB08311B549449E94AE7250CB385A41EF50
                          APIs
                            • Part of subcall function 00A87620: _wcslen.LIBCMT ref: 00A87625
                          • WNetUseConnectionW.MPR(00000000,?,0000002A,00000000,?,?,0000002A,?), ref: 00AF4ED4
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Connection_wcslen
                          • String ID: *$LPT
                          • API String ID: 1725874428-3443410124
                          • Opcode ID: 34e6e928b35acf3ce639b59595eac1bafbed3e86038a6f2c5a93bd06bf21a229
                          • Instruction ID: 4cedac2c7433002cade8e7407ab77220909dbb08c861549711edc20359a055ba
                          • Opcode Fuzzy Hash: 34e6e928b35acf3ce639b59595eac1bafbed3e86038a6f2c5a93bd06bf21a229
                          • Instruction Fuzzy Hash: 72916D75A002089FCB14DF98C584EAABBF1BF48704F188099F94A9F362D731ED85CB90
                          APIs
                          • __startOneArgErrorHandling.LIBCMT ref: 00AAE30D
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ErrorHandling__start
                          • String ID: pow
                          • API String ID: 3213639722-2276729525
                          • Opcode ID: 6b08328f2cbd3a768d6c35b419a72a8f644e1ae095e136f41b4dafc66f9caefd
                          • Instruction ID: ff8a8bf960050d990880c8c5d85093c2e86a83ff9d01bc8f0c718ee9acc2b030
                          • Opcode Fuzzy Hash: 6b08328f2cbd3a768d6c35b419a72a8f644e1ae095e136f41b4dafc66f9caefd
                          • Instruction Fuzzy Hash: E9512B71A0C20296CF15F718CA417FD3BACAF81780F344D98E096872EAEF758C959A56
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID:
                          • String ID: #
                          • API String ID: 0-1885708031
                          • Opcode ID: 4f9745b836c850abcc94e22845c01d4737a728ad17069356660ec6b3f878ff09
                          • Instruction ID: b9e308044d0e92b5feb3af82c1b4279b8d7009aa6e2a02031fa4b38d8e70b333
                          • Opcode Fuzzy Hash: 4f9745b836c850abcc94e22845c01d4737a728ad17069356660ec6b3f878ff09
                          • Instruction Fuzzy Hash: 1F51F175A04246DFDF15EF68C481AFA7BB8EF65310F24405AE8929F3D1DA349D42CBA0
                          APIs
                          • Sleep.KERNEL32(00000000), ref: 00A9F2A2
                          • GlobalMemoryStatusEx.KERNEL32(?), ref: 00A9F2BB
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: GlobalMemorySleepStatus
                          • String ID: @
                          • API String ID: 2783356886-2766056989
                          • Opcode ID: 3e04200a84c0a28bc5db054fd99e746fbb6adfdf79b0a62dd6f78b0f8fd1214f
                          • Instruction ID: b56842a9a52dac5e9755d844b4559579e16eca8998d5634edfffa322aca9e7b0
                          • Opcode Fuzzy Hash: 3e04200a84c0a28bc5db054fd99e746fbb6adfdf79b0a62dd6f78b0f8fd1214f
                          • Instruction Fuzzy Hash: 375158714087449BE320AF14ED86BAFBBF8FF84314F91884DF2D951195EB308929CB66
                          APIs
                          • CharUpperBuffW.USER32(?,?,?,00000003,?,?), ref: 00B057E0
                          • _wcslen.LIBCMT ref: 00B057EC
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: BuffCharUpper_wcslen
                          • String ID: CALLARGARRAY
                          • API String ID: 157775604-1150593374
                          • Opcode ID: 76a5718a0d22e0ebc4449139dbe7400db0f6e9906f3b00dbecd8ca877dc8dbe3
                          • Instruction ID: 306db88396470623a79a457c240fdfcac46863aa616754723ca019f59d92bb4e
                          • Opcode Fuzzy Hash: 76a5718a0d22e0ebc4449139dbe7400db0f6e9906f3b00dbecd8ca877dc8dbe3
                          • Instruction Fuzzy Hash: 34418F31A006099FCB14DFA9C9859BEBBF9EF59350F1480A9E905A7291EB70DD81CF90
                          APIs
                          • _wcslen.LIBCMT ref: 00AFD130
                          • InternetCrackUrlW.WININET(?,00000000,00000000,0000007C), ref: 00AFD13A
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CrackInternet_wcslen
                          • String ID: |
                          • API String ID: 596671847-2343686810
                          • Opcode ID: 29eacb24e421cec4f35ef6264e2d5d3ef65d0b94b61ee2501ef735229efe15fb
                          • Instruction ID: 7cd27ef544fda1af982c9116655a919ef2b8c6432e83e7ba100c2b0c80fcc86f
                          • Opcode Fuzzy Hash: 29eacb24e421cec4f35ef6264e2d5d3ef65d0b94b61ee2501ef735229efe15fb
                          • Instruction Fuzzy Hash: 81313E71D00209ABDF15EFE4CD85AEEBFBAFF05300F000119F915A6165E731AA56DB64
                          APIs
                          • DestroyWindow.USER32(?,?,?,?), ref: 00B13621
                          • MoveWindow.USER32(?,?,?,?,?,00000001,?,?,?), ref: 00B1365C
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$DestroyMove
                          • String ID: static
                          • API String ID: 2139405536-2160076837
                          • Opcode ID: 378a46b8fc39d3c6c171654afb77e20a65cc998d7373d4af5f0492fa85b724ac
                          • Instruction ID: 7a381924f0126c8c612731a38aef9ad43b7ed771e93fa57426dfd0e8b16c20fd
                          • Opcode Fuzzy Hash: 378a46b8fc39d3c6c171654afb77e20a65cc998d7373d4af5f0492fa85b724ac
                          • Instruction Fuzzy Hash: AA319E71100204AEEB109F28DC80FFB73E9FF98B64F508619F9A597290DA30AD91C760
                          APIs
                          • SendMessageW.USER32(00000027,00001132,00000000,?), ref: 00B1461F
                          • SendMessageW.USER32(?,00001105,00000000,00000000), ref: 00B14634
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend
                          • String ID: '
                          • API String ID: 3850602802-1997036262
                          • Opcode ID: dedc2322882a607ec1043d0423c9e9d56c1926f0d93f4b0f4b0389d4a95a6203
                          • Instruction ID: 4d92ea4e928e208d882ca1c8ab252e6f621da106a7ab9440e3127c16216985e5
                          • Opcode Fuzzy Hash: dedc2322882a607ec1043d0423c9e9d56c1926f0d93f4b0f4b0389d4a95a6203
                          • Instruction Fuzzy Hash: 03311674A0020A9FDF14CFA9C980BDA7BF6FB19304F5444AAE904AB341D770A981CF90
                          APIs
                          • SendMessageW.USER32(00000000,00000143,00000000,?), ref: 00B1327C
                          • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 00B13287
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: MessageSend
                          • String ID: Combobox
                          • API String ID: 3850602802-2096851135
                          • Opcode ID: 56b7fa2e1c6ad39d52cac01c21ad6195df610035f758ce4d743d9f4dc7bd7d08
                          • Instruction ID: 53882d87cff31623f933b09403412f7b4ecc0595fa98c607630864633cbebaa2
                          • Opcode Fuzzy Hash: 56b7fa2e1c6ad39d52cac01c21ad6195df610035f758ce4d743d9f4dc7bd7d08
                          • Instruction Fuzzy Hash: B511B2713002087FFF21AE54DC80EFB3BEAEB98764F504164F918A7290E6319D9187A0
                          APIs
                            • Part of subcall function 00A8600E: CreateWindowExW.USER32(?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 00A8604C
                            • Part of subcall function 00A8600E: GetStockObject.GDI32(00000011), ref: 00A86060
                            • Part of subcall function 00A8600E: SendMessageW.USER32(00000000,00000030,00000000), ref: 00A8606A
                          • GetWindowRect.USER32(00000000,?), ref: 00B1377A
                          • GetSysColor.USER32(00000012), ref: 00B13794
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Window$ColorCreateMessageObjectRectSendStock
                          • String ID: static
                          • API String ID: 1983116058-2160076837
                          • Opcode ID: b8b4084e399041024a838f210547763b09e644b6152bd47ef55744c236e474f7
                          • Instruction ID: 2b02397816be642be00fd4dbd5c6ae68816a7c1c597e3e76db34dba2bcba12bb
                          • Opcode Fuzzy Hash: b8b4084e399041024a838f210547763b09e644b6152bd47ef55744c236e474f7
                          • Instruction Fuzzy Hash: 461137B2610209AFDF01DFA8CC46EEA7BF8FB08714F404954F955E3250EB35E8619B60
                          APIs
                          • InternetOpenW.WININET(?,00000000,00000000,00000000,00000000), ref: 00AFCD7D
                          • InternetSetOptionW.WININET(00000000,00000032,?,00000008), ref: 00AFCDA6
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Internet$OpenOption
                          • String ID: <local>
                          • API String ID: 942729171-4266983199
                          • Opcode ID: bd163f0ef1fb2529d547fa116c432cf770f4eea48050162a826defa563346eb0
                          • Instruction ID: 8298fa73180333a4fbb2e0e5f0aa04c8b4b1d34335fe34029f73749cb323185b
                          • Opcode Fuzzy Hash: bd163f0ef1fb2529d547fa116c432cf770f4eea48050162a826defa563346eb0
                          • Instruction Fuzzy Hash: 4E11C27124563DBAD7384BA78C49EFBBEACEF127B4F40422AB20983080D7709941D6F0
                          APIs
                          • GetWindowTextLengthW.USER32(00000000), ref: 00B134AB
                          • SendMessageW.USER32(?,000000B1,00000000,00000000), ref: 00B134BA
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: LengthMessageSendTextWindow
                          • String ID: edit
                          • API String ID: 2978978980-2167791130
                          • Opcode ID: 698ac6083e2a317bacaae59bf48c6f52c202edadd96caca34e2cd2de59a08edf
                          • Instruction ID: 26cddfcb56284b7365fc855b9dafc8239dd521b9aaa4b728af2a57d25c399cb8
                          • Opcode Fuzzy Hash: 698ac6083e2a317bacaae59bf48c6f52c202edadd96caca34e2cd2de59a08edf
                          • Instruction Fuzzy Hash: 2811BF71100208AFEB228E64DC80AEB3BEAEB14B74F908364FA65932E0D731DCD19750
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                          • CharUpperBuffW.USER32(?,?,?), ref: 00AE6CB6
                          • _wcslen.LIBCMT ref: 00AE6CC2
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen$BuffCharUpper
                          • String ID: STOP
                          • API String ID: 1256254125-2411985666
                          • Opcode ID: 119a9923c767e30e8cbe9a0c501109e4e5afc65f942f010a4c07b2fef02cf569
                          • Instruction ID: 73397bbb514a74dc60eb0c35c2a0477fc45db645796b1aeabfa581dfc0dfbe4a
                          • Opcode Fuzzy Hash: 119a9923c767e30e8cbe9a0c501109e4e5afc65f942f010a4c07b2fef02cf569
                          • Instruction Fuzzy Hash: E90104326009668BCB20AFBECC908BF77B5FAB57907600D28E86293191EB31D900C750
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00AE3CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00AE3CCA
                          • SendMessageW.USER32(?,000001A2,000000FF,?), ref: 00AE1D4C
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClassMessageNameSend_wcslen
                          • String ID: ComboBox$ListBox
                          • API String ID: 624084870-1403004172
                          • Opcode ID: eaf1fd8aaccb4dfd4b630a988e19747808662b4ac6436ae9aad2398c06e71741
                          • Instruction ID: 665c46336464af906f79be9e7e0cfe5f1bcc292fa6ee1c6bec0dd93439e218de
                          • Opcode Fuzzy Hash: eaf1fd8aaccb4dfd4b630a988e19747808662b4ac6436ae9aad2398c06e71741
                          • Instruction Fuzzy Hash: 7101D471601228ABCF18FFA5CE95CFF77A8EB46350B540619F832672D2EA3199088761
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00AE3CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00AE3CCA
                          • SendMessageW.USER32(?,00000180,00000000,?), ref: 00AE1C46
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClassMessageNameSend_wcslen
                          • String ID: ComboBox$ListBox
                          • API String ID: 624084870-1403004172
                          • Opcode ID: 598064eba1f80a2f16d6df52d332ae60dbd165afbf0f9f41fc45d86bc05864c4
                          • Instruction ID: 219521cfae22db2279b7fef0fda3adbc69c3333d3cfd8ff37cd05422bdec20ef
                          • Opcode Fuzzy Hash: 598064eba1f80a2f16d6df52d332ae60dbd165afbf0f9f41fc45d86bc05864c4
                          • Instruction Fuzzy Hash: 1B01A7757811586BCF14FB91CA559FF77A89B51340F240019F416B7282EA319F1C97B2
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00AE3CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00AE3CCA
                          • SendMessageW.USER32(?,00000182,?,00000000), ref: 00AE1CC8
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClassMessageNameSend_wcslen
                          • String ID: ComboBox$ListBox
                          • API String ID: 624084870-1403004172
                          • Opcode ID: f9bf0c6750e43ec6285a55d51edcb798858120b8439cad826b36c913a8f2bd3b
                          • Instruction ID: ca1a386c1dc668e9590e563cdfbccb3132252fc6197b4994ff35c2c98e45c49f
                          • Opcode Fuzzy Hash: f9bf0c6750e43ec6285a55d51edcb798858120b8439cad826b36c913a8f2bd3b
                          • Instruction Fuzzy Hash: DB01D6B16811686BCF14FBA2CB05AFF77E89B51340F240415B802B3282EA319F18D772
                          APIs
                            • Part of subcall function 00A89CB3: _wcslen.LIBCMT ref: 00A89CBD
                            • Part of subcall function 00AE3CA7: GetClassNameW.USER32(?,?,000000FF), ref: 00AE3CCA
                          • SendMessageW.USER32(?,0000018B,00000000,00000000), ref: 00AE1DD3
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ClassMessageNameSend_wcslen
                          • String ID: ComboBox$ListBox
                          • API String ID: 624084870-1403004172
                          • Opcode ID: 0c2157a63edde5619c2b3b39d67c49d48f6d6705c54b0436aa6e0007e351a88b
                          • Instruction ID: 489ad511cf2ce2fb7fe2fd73e059bd35f7da742797b1cbfa90c87b61eca47014
                          • Opcode Fuzzy Hash: 0c2157a63edde5619c2b3b39d67c49d48f6d6705c54b0436aa6e0007e351a88b
                          • Instruction Fuzzy Hash: E5F0A971A416296BDB14F7A5CD95AFF77B8AB01350F580915F422632C1EA715A088361
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: _wcslen
                          • String ID: 3, 3, 16, 1
                          • API String ID: 176396367-3042988571
                          • Opcode ID: e49a2f2a9c59cc032bcc90ec9b0c28ec3425cdaff8527021fe5f461c41f1d59b
                          • Instruction ID: 745ef6143674f96a0bf42f71bb34a4b558e4dab131f13032db4a5466ad9372dd
                          • Opcode Fuzzy Hash: e49a2f2a9c59cc032bcc90ec9b0c28ec3425cdaff8527021fe5f461c41f1d59b
                          • Instruction Fuzzy Hash: A7E02B02A5426010D23116799DC197FDBCDCFCA790710186BF981C33E6EFD49DA293A0
                          APIs
                          • MessageBoxW.USER32(00000000,Error allocating memory.,AutoIt,00000010), ref: 00AE0B23
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Message
                          • String ID: AutoIt$Error allocating memory.
                          • API String ID: 2030045667-4017498283
                          • Opcode ID: e40a522fe6ab8a1c4acfd41fb7d56ce624e981b7381c188a8e9791a76ed79b57
                          • Instruction ID: d8fb56594544b2b1fded4cc428a578748b20f5e7c5c64156763abb95710a9a38
                          • Opcode Fuzzy Hash: e40a522fe6ab8a1c4acfd41fb7d56ce624e981b7381c188a8e9791a76ed79b57
                          • Instruction Fuzzy Hash: D3E0D8323843082BD62037547D03FC97EC58F06F50F10046AF748954D38BD1299006E9
                          APIs
                            • Part of subcall function 00A9F7C9: InitializeCriticalSectionAndSpinCount.KERNEL32(?,00000000,?,00AA0D71,?,?,?,00A8100A), ref: 00A9F7CE
                          • IsDebuggerPresent.KERNEL32(?,?,?,00A8100A), ref: 00AA0D75
                          • OutputDebugStringW.KERNEL32(ERROR : Unable to initialize critical section in CAtlBaseModule,?,?,?,00A8100A), ref: 00AA0D84
                          Strings
                          • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00AA0D7F
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: CountCriticalDebugDebuggerInitializeOutputPresentSectionSpinString
                          • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
                          • API String ID: 55579361-631824599
                          • Opcode ID: 27ac9a6d10525efad39fd3a1c923147eaf3fa8b29a605ac1398f9841a3ac4c9a
                          • Instruction ID: 8d8519b1d8ecbda90ec3b10d69f21ca8bd2507eca54254e0fff6f67d2f72f5d3
                          • Opcode Fuzzy Hash: 27ac9a6d10525efad39fd3a1c923147eaf3fa8b29a605ac1398f9841a3ac4c9a
                          • Instruction Fuzzy Hash: C9E06D752007018BD360AFBCD508B927BE0AB01740F40896DE486C76A1EBB5E488CB91
                          APIs
                          • GetTempPathW.KERNEL32(00000104,?,00000001), ref: 00AF302F
                          • GetTempFileNameW.KERNEL32(?,aut,00000000,?), ref: 00AF3044
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: Temp$FileNamePath
                          • String ID: aut
                          • API String ID: 3285503233-3010740371
                          • Opcode ID: ad50417d46135138b446c25fe3e4587a781bdfdfd676af17e440be1b22442af5
                          • Instruction ID: 86746fb37b56eb8fefe5b2c17effc3894ee379a6ecefb47183f40609f7894a66
                          • Opcode Fuzzy Hash: ad50417d46135138b446c25fe3e4587a781bdfdfd676af17e440be1b22442af5
                          • Instruction Fuzzy Hash: EBD05EB254032867DA20A7A4AC0EFCB3F6CDB05750F4002A1B655E30A1DEF09A84CAD0
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: LocalTime
                          • String ID: %.3d$X64
                          • API String ID: 481472006-1077770165
                          • Opcode ID: 7f4fac8a890df5a8ebe4aa9759a77435b8a1733c5a31bfad8bd6b1052e71c719
                          • Instruction ID: b1c19c2a58f15eefcadee1f373d5d5bcf97f02691a01ebd19a08c6b7c94d982d
                          • Opcode Fuzzy Hash: 7f4fac8a890df5a8ebe4aa9759a77435b8a1733c5a31bfad8bd6b1052e71c719
                          • Instruction Fuzzy Hash: 69D012B1948108EACF509AD0CC458F9B7BCEB18341F508453F807D2140DA34C649A761
                          APIs
                          • FindWindowW.USER32(Shell_TrayWnd,00000000), ref: 00B1232C
                          • PostMessageW.USER32(00000000,00000111,00000197,00000000), ref: 00B1233F
                            • Part of subcall function 00AEE97B: Sleep.KERNEL32 ref: 00AEE9F3
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FindMessagePostSleepWindow
                          • String ID: Shell_TrayWnd
                          • API String ID: 529655941-2988720461
                          • Opcode ID: 365d9ab950a8d9884e1585f13e1b41ff7df4ee727b2e52f10f5b07376c800ace
                          • Instruction ID: e3963a4e3850132c5d4840c69aae7d489397bc6ac85026c279900e0dcb4ec2ec
                          • Opcode Fuzzy Hash: 365d9ab950a8d9884e1585f13e1b41ff7df4ee727b2e52f10f5b07376c800ace
                          • Instruction Fuzzy Hash: FDD0C9363D4350BAE664A771DC0FFC6AA55AB10B10F4089167645AB1E5D9A0A841CA54
                          APIs
                          • FindWindowW.USER32(Shell_TrayWnd,00000000), ref: 00B1236C
                          • PostMessageW.USER32(00000000), ref: 00B12373
                            • Part of subcall function 00AEE97B: Sleep.KERNEL32 ref: 00AEE9F3
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: FindMessagePostSleepWindow
                          • String ID: Shell_TrayWnd
                          • API String ID: 529655941-2988720461
                          • Opcode ID: 11a4a1d4c6d0d75e840cd0ddec41532591853267d833888d8dda7e8f1ddfabb0
                          • Instruction ID: 495225f42807eea0a4879174ba6ca9f06c53ad80cde0763d134e232db5fb695d
                          • Opcode Fuzzy Hash: 11a4a1d4c6d0d75e840cd0ddec41532591853267d833888d8dda7e8f1ddfabb0
                          • Instruction Fuzzy Hash: 2AD0C9323C13507AE664A771DC0FFC6AA55AB15B10F4089167645AB1E5D9A0A841CA54
                          APIs
                          • MultiByteToWideChar.KERNEL32(?,00000009,?,00000000,00000000,?,?,?,00000000,?,?,?,?,?,00000000,?), ref: 00ABBE93
                          • GetLastError.KERNEL32 ref: 00ABBEA1
                          • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 00ABBEFC
                          Memory Dump Source
                          • Source File: 00000000.00000002.2984586360.0000000000A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00A80000, based on PE: true
                          • Associated: 00000000.00000002.2984565959.0000000000A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B1C000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984646237.0000000000B42000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984695001.0000000000B4C000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2984717342.0000000000B54000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a80000_file.jbxd
                          Similarity
                          • API ID: ByteCharMultiWide$ErrorLast
                          • String ID:
                          • API String ID: 1717984340-0
                          • Opcode ID: cc0a370344734d7aa52872d76794b1a93c6ac4341fbc7a1cac0489ce2b410d7d
                          • Instruction ID: f15a88f4a4c485231cbe407fd02426fcad01551f52f3516e4e38ce680390d154
                          • Opcode Fuzzy Hash: cc0a370344734d7aa52872d76794b1a93c6ac4341fbc7a1cac0489ce2b410d7d
                          • Instruction Fuzzy Hash: 1441C334610206AFCF258FB5CD44AFA7BADAF42310F244169F9599B1A2DBB0CD01DB70